Privacy Policy
Preamble and Legal Foundation
WHEREAS, the Operator (as defined in Article II herein) operates a sophisticated, multi-layered digital ecosystem that includes, inter alia, a comprehensive bookmark management and social discovery platform (Bookmer Core), a centralized identity and authentication infrastructure (Bookmer ID / LoginSign) employing OAuth 2.0 and OpenID Connect protocols, and associated Developer tools, browser extensions, mobile applications, and APIs (collectively, the "Services");
WHEREAS, the Operator processes Personal Data (as defined in Article 4(1) of the General Data Protection Regulation - GDPR) of natural persons who interact with the Services, including but not limited to registered Users, visitors, End-Users of Developer Applications, and individuals referenced in User Content;
WHEREAS, the Operator is fully committed to the protection of the fundamental rights and freedoms of natural persons, and in particular their right to the protection of Personal Data, as enshrined in Article 8 of the Charter of Fundamental Rights of the European Union and the constitutional guarantees of the Federal Republic of Germany;
WHEREAS, this Privacy Policy is promulgated to fulfill the transparency obligations mandated by Articles 13 and 14 of the GDPR, to comply with the applicable provisions of the German Federal Data Protection Act (Bundesdatenschutzgesetz - BDSG), the German Telemedia Act (Telemediengesetz - TMG), the German Telecommunications-Telemedia Data Protection Act (Telekommunikation-Telemedien-Datenschutz-Gesetz - TTDSG), the ePrivacy Directive (2002/58/EC), the European Digital Services Act (Regulation 2022/2065 - DSA), the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (CCPA/CPRA), and the United States Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §§ 6501-6506);
WHEREAS, this Privacy Policy is intended to provide all Data Subjects with clear, transparent, comprehensive, and easily accessible information regarding: (a) the categories of Personal Data collected and processed; (b) the purposes and legal bases for processing; (c) the recipients and categories of recipients of Personal Data; (d) the retention periods and criteria for data erasure; (e) the international transfer mechanisms and safeguards; (f) the technical and organizational measures employed to secure Personal Data; and (g) the specific rights of Data Subjects and the procedures for exercising such rights;
NOW, THEREFORE, the Operator presents this Privacy Policy as the definitive, legally binding declaration of its data processing practices, which shall govern the relationship between the Operator and each Data Subject from the moment of first interaction with the Services.
Introductory Provisions and Scope
Material Scope of Application
This Privacy Policy (hereinafter "this Policy" or "this Privacy Declaration") constitutes the comprehensive, overarching information disclosure regarding the collection, processing, storage, transmission, transfer, and erasure of Personal Data by the Operator in connection with all components of the Bookmer ecosystem. This Policy applies to all processing activities, whether automated or non-automated, and whether carried out within the European Economic Area (EEA), the United Kingdom, Switzerland, the United States, or any other jurisdiction in which the Services are accessible.
Territorial Scope and Jurisdictional Applicability
The Operator operates a globally accessible platform. Consequently, this Policy is designed to comply with the strictest international data protection standards, including but not limited to:
The General Data Protection Regulation (GDPR) (EU) 2016/679, applicable to all Data Subjects habitually resident in the EEA, the UK, and Switzerland;
The German Federal Data Protection Act (BDSG) , which supplements the GDPR with specific national provisions;
The German Telemedia Act (TMG) and the Telecommunications-Telemedia Data Protection Act (TTDSG) , governing the use of cookies and storage access on terminal equipment;
The ePrivacy Directive (2002/58/EC) , concerning the processing of Personal Data and the protection of privacy in the electronic communications sector;
The Digital Services Act (DSA) (Regulation 2022/2065) , regarding content moderation and transparency obligations;
The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (CCPA/CPRA) , applicable to California residents;
The Children's Online Privacy Protection Act (COPPA) , 15 U.S.C. §§ 6501-6506, applicable to children under the age of thirteen (13) in the United States.
Exclusions and Third-Party Responsibility
This Policy applies exclusively to the processing activities carried out by the Operator. It does not apply to, and the Operator expressly disclaims any responsibility for, the data processing practices of:
Developer Applications: When you authenticate using Bookmer ID on a third-party Developer Application, the Developer acts as an independent Data Controller for the Personal Data they subsequently collect. This Policy governs only the data transmitted from Bookmer ID to the Developer; it does not govern the Developer's subsequent storage, processing, or sharing of that data. You are strongly urged to review the Developer's separate privacy policy prior to authorizing the OAuth flow.
External Websites: When you add a bookmark to a website or link, the Operator processes metadata for preview purposes, but the underlying external website is controlled by a third party. The Operator is not responsible for the privacy practices, content, security, or data processing activities of such external sites.
Payment Processors: Financial transactions are processed by independent third-party payment providers (e.g., Stripe, Inc., PayPal (Europe) S.à r.l. et Cie, S.C.A., Apple Inc., Google LLC). Their respective privacy policies, terms of service, and data processing agreements govern the handling of full payment card details (PAN), CVV/CVC codes, and bank account information. The Operator only receives tokenized references and confirmation of payment status.
Relationship with Other Legal Documents
This Privacy Policy is a standalone legal document, independent of and separate from the Terms of Service, the GDPR Notice, and the CPRA Notice. It is intended to complement those documents and to provide a comprehensive, unified privacy framework. In the event of an irreconcilable conflict between this Policy and a more specific notice (e.g., the GDPR Notice for EEA residents), the more specific notice shall prevail solely to the extent required by applicable law.
Controller, Data Protection Officer, and Contact Details (embedded)
Identity of the Data Controller
For the purposes of all applicable data protection and privacy laws, including but not limited to Art. 4(7) of the GDPR and Section 3(8) of the BDSG, the entity responsible for determining the purposes, conditions, and means of the processing of Personal Data described herein (the "Controller" or "Operator") is:
Gabriel Sgroi
Charlottenstr. 47,
73230 Kirchheim unter Teck,
Germany.
Designated Privacy Contact and Communication Channel
All formal communications, inquiries regarding data protection, requests to exercise data subject rights (including but not limited to access, rectification, deletion, restriction, portability, and objection), and any correspondence concerning the interpretation or application of this Policy shall be directed exclusively and in writing to the following dedicated contact point, which is permanently staffed by the Operator's internal privacy compliance team:
Email: support@mail.bookmer.com
Postal Address: Gabriel Sgroi, Charlottenstr. 47, 73230 Kirchheim unter Teck, Germany.
The Operator expressly acknowledges and fulfills its statutory obligation to acknowledge receipt of any data subject request within a maximum of one (1) month from the date of receipt, as mandated by Art. 12(3) GDPR and Section 34 BDSG, and shall provide a substantive, reasoned response within the same statutory timeframe, subject to the legally permissible extensions of an additional two (2) months for complex or multiple requests, as provided for in Art. 12(4) GDPR.
Data Protection Officer (DPO) Status and Designation
In accordance with Art. 37 of the GDPR and Section 38 of the BDSG, the Operator has carefully assessed the necessity of appointing a mandatory Data Protection Officer (DPO). Based on a comprehensive evaluation of its processing activities, the Operator has concluded that the core activities of the Services do not involve: (a) the large-scale, systematic monitoring of data subjects; nor (b) the large-scale processing of special categories of data (Art. 9 GDPR) or data relating to criminal convictions (Art. 10 GDPR). Consequently, the mandatory appointment of a DPO is not legally required. Nonetheless, the Operator has designated an internal privacy lead with specific responsibility for ensuring compliance with this Policy, maintaining the Record of Processing Activities (Art. 30 GDPR), and serving as the primary point of contact for the competent supervisory authority. All data protection matters can be directed to the privacy lead via the email address specified in Section 2.2 above.
Supervisory Authority with Jurisdiction
The competent supervisory authority for the Operator, located in the Federal Republic of Germany, is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Baden-Württemberg
Königstraße 10a,
70173 Stuttgart,
Germany.
Website: https://www.baden-wuerttemberg.datenschutz.de/
Data Subjects who are habitually resident in another Member State of the European Union have the right to lodge a complaint with the supervisory authority in their Member State of habitual residence, place of work, or place of the alleged infringement.
Definitions and Interpretation
Statutory Definitions
For the purposes of this Policy, the following capitalized terms, whether used in the singular or plural, shall have the meanings ascribed to them below, unless the context explicitly requires otherwise:
"Personal Data" shall mean any information relating to an identified or identifiable natural person (the "Data Subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person, as defined in Art. 4(1) of the GDPR and Cal. Civ. Code § 1798.140(v).
"Processing" shall mean any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction, as defined in Art. 4(2) of the GDPR.
"Controller" shall mean the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, as defined in Art. 4(7) of the GDPR.
"Processor" shall mean a natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Controller, as defined in Art. 4(8) of the GDPR.
"Data Subject" shall mean an identified or identifiable natural person whose Personal Data is processed by the Controller, as defined in Art. 4(1) of the GDPR.
"Sensitive Personal Data" shall mean the special categories of Personal Data referred to in Art
9(1) of the GDPR, including but not limited to data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation.
Interpretation and Construction
The headings and captions utilized within this Policy are inserted for convenience of reference only and shall not define, limit, extend, or construe the scope or intent of any provision herein. All references to the singular shall include the plural and vice versa, and references to the masculine gender shall be deemed to include the feminine and neuter genders, wherever appropriate. The use of the terms "including", "includes", "such as", or "e.g." shall be construed as illustrative and not as a limitation upon the scope of the general terms that precede or follow them.
Glossary of Key Terms
A comprehensive glossary of key terms and definitions is provided at the conclusion of this Policy for ease of reference.
Children's Privacy and Age Restrictions
Minimum Age Requirements (COPPA and GDPR)
The Services are not directed at, and are not intended to be used by, children under the age of sixteen (16) years within the European Economic Area, the United Kingdom, and Switzerland (in accordance with Art. 8 of the GDPR and Section 5 of the BDSG), or under the age of thirteen (13) years in all other jurisdictions, including the United States (in strict compliance with the Children's Online Privacy Protection Act - COPPA, 15 U.S.C. §§ 6501-6506). The Operator does not knowingly collect, process, or store Personal Data from any individual under the age of thirteen (13) without obtaining verifiable parental or legal guardian consent.
Verifiable Parental Consent Mechanisms
Where the Operator is required to obtain verifiable parental consent before collecting Personal Data from a child under the age of thirteen (13), the Operator shall implement a commercially reasonable consent mechanism, which may include: (a) requiring the parent to provide a valid credit card or other payment method for a nominal charge to confirm identity; (b) requiring the parent to sign and return a consent form by postal mail, fax, or electronic scan; (c) requiring the parent to provide a valid government-issued identification; or (d) other methods that are reasonably calculated to ensure that the person providing consent is indeed the child's parent or legal guardian.
Procedures for Inadvertent Collection of Minor Data
If the Operator becomes aware, through the exercise of reasonable diligence or through a notification from a parent, that Personal Data of a child under the age of thirteen (13) (or under sixteen (16) for EEA residents) has been inadvertently collected without the requisite verifiable parental consent, the Operator shall immediately: (a) cease all processing of such data; (b) permanently delete the data from its active databases, backups, and archival systems within a commercially reasonable timeframe, not to exceed thirty (30) days from the date of discovery; (c) where applicable, notify the relevant supervisory authority or law enforcement agency in accordance with legal obligations; and (d) take reasonable steps to prevent the recurrence of such unauthorized collection.
Parental and Guardian Rights
Parents and legal guardians who believe that their child has provided Personal Data to the Operator without their consent, or who wish to review, delete, or prevent further collection of their child's Personal Data, may contact the Operator via the contact details provided in Article II of this Policy. The Operator will require verification of the parent's or guardian's identity and relationship to the child before responding to any such request.
Exhaustive Categories of Personal Data Processed
Granular Inventory of Data Elements
The Operator processes the following exhaustive categories of Personal Data, each of which is collected, stored, and utilized in strict adherence to the principles of data minimization (Art. 5(1)(c) GDPR), purpose limitation (Art. 5(1)(b) GDPR), and storage limitation (Art. 5(1)(e) GDPR). The specific data elements collected depend on the Data Subject's interaction with the Services:
Statutory Category Specific Data Elements Collected?
A. Account and Profile Data Full legal name (where voluntarily provided), chosen username, display alias, primary email address (mandatory), secondary/recovery email address, profile picture (where uploaded), biographical description or tagline, account creation timestamp, account status (active, suspended, deleted), language preference, time zone, and user-defined security settings (including two-factor authentication status, passkey configuration, and recovery code storage). YES
B. Authentication and Credential Data Hashed and salted passwords (using industry-standard cryptographic algorithms such as bcrypt or Argon2), passkey metadata (public key credentials, relying party identifiers, credential IDs, and attestation statements from FIDO2-compliant authenticators), OAuth provider identifiers (e.g., Google, Apple, GitHub unique user IDs), session tokens and their hashes, refresh token hashes, login history (timestamps, IP addresses, device fingerprints, user-agent strings), and authentication event logs (including successful and failed login attempts, multi-factor authentication verifications, and password reset events). YES
C. Bookmer Content and Metadata All user-created and user-uploaded content, including but not limited to: hyperlinks (URLs) saved as bookmarks; hierarchical folder structures and sub-folder organizations; user-defined tagging taxonomies and labels; notes and annotations appended to individual bookmarks; comments on shared collections and public pages; customizable style preferences (CSS variables, background wallpaper selections, accent color choices, typography preferences, and layout configurations); imported data from third-party bookmark services and browsers; and automatically scraped Open Graph metadata (titles, descriptions, images, and favicons) from linked external websites. YES
D. Public Page and Sharing Data Information explicitly designated by the User as "Public," "Unlisted," or "Published," including: public profile page content (username, display name, avatar, description); public collection titles and descriptions; shared URL landing pages and custom domain configurations; public comment threads; public thumbnails and icons; and associated engagement metrics (view counts, external share counts, click-through rates, and interaction analytics generated by other Users or visitors). YES
E. Technical, Telemetry, and Log Data IP addresses (both IPv4 and IPv6), browser type and version, operating system type and version, device type and model, screen resolution, preferred language, HTTP referrer headers, requested URL endpoints, timestamp of requests, response times, latency metrics, crash logs, error reports (generated exclusively for diagnostic and debugging purposes), CDN (Content Delivery Network) access logs, and API call endpoints and frequencies. YES
F. Payment and Transaction Data Billing address (street, city, postal code, country), invoice recipient name, invoice numbers, transaction IDs from payment processors, subscription tier, billing cycle, payment status (active, expired, cancelled), the last four (4) digits of credit/debit cards (truncated in compliance with PCI-DSS standards), and the expiration date of the card (month/year). Full Primary Account Numbers (PAN), CVV/CVC codes, and full expiration dates are never processed, stored, or transmitted by the Operator. YES
G. Communication and Correspondence Data Full content of emails, support tickets, contact form submissions, live chat transcripts, and social media direct messages, including attachments, screenshots, and any metadata associated with such correspondence (sender/receiver addresses, timestamps, subject lines, and message IDs). YES
H. Developer and API Integration Data For registered Developers utilizing the Bookmer ID API ecosystem, this includes: Developer Application name, legal entity name (where applicable), contact details of technical representatives (email addresses, phone numbers), application description and category, redirect URIs (universal resource identifiers), hashed client ID and client secret, API usage analytics (request volumes, error rates, endpoint usage patterns, and response times), OAuth consent screen configurations, and Developer Console activity logs. YES
I. Consent and Preference Records Records of consents granted, modified, or withdrawn by the Data Subject, including: the specific consent text (verbatim), the date and time of each consent action, the version of the consent form, the cookie consent level (strictly necessary, functional, analytics, marketing), the marketing communication preference (opt-in/opt-out status), and the withdrawal status of any previously granted consent. YES
J. Abuse Prevention and Security Logs System-generated logs and records related to: rate-limiting violations, spam filtering and quarantine decisions, credential-stuffing detection, brute-force attack detection, IP blacklisting, email deliverability monitoring (bounce rates, spam complaints, trap hits), automated security incident response triggers (including session invalidation and temporary account lockouts), and forensic investigation records. YES
K. Sensitive Personal Data (Art. 9 GDPR) The Operator does not intentionally collect, process, or store any special categories of data as defined in Art. 9(1) of the GDPR, including but not limited to: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation. The Services are not designed to collect or process such data, and Users are expressly prohibited from submitting Sensitive Personal Data through the Services. NO
Sensitive Personal Data (Art
9 GDPR). As stated in Section 5.1.K above, the Operator does not intentionally collect any Sensitive Personal Data. Users are expressly prohibited from uploading, sharing, or otherwise making available Sensitive Personal Data through the Services. If the Operator becomes aware that Sensitive Personal Data has been inadvertently uploaded, the Operator shall take immediate steps to delete such data and, where applicable, notify the Data Subject.
Data Relating to Criminal Convictions (Art
10 GDPR). The Operator does not process data relating to criminal convictions or offenses, as defined in Art. 10 of the GDPR. Users are prohibited from submitting such data through the Services.
Sources and Origins of Personal Data
Direct Provision by the Data Subject
The predominant source of Personal Data is the Data Subject themselves, who voluntarily and actively provides information: (a) during the registration process (e.g., email address, username, password); (b) during account configuration (e.g., profile picture, display name, biographical description); (c) through the creation and management of User Content (e.g., bookmarks, folders, notes, comments); (d) through the submission of support inquiries, contact forms, or feedback; and (e) through the voluntary participation in surveys, promotional activities, or interactive features.
Automated Generation through System Operation
The Operator's IT infrastructure inherently generates and logs technical data, telemetry data, session data, and security logs as an automatic byproduct of the Data Subject's interaction with the Services. This includes: (a) server access logs recording IP addresses, requested URLs, timestamps, and response codes; (b) browser-generated telemetry such as operating system type, browser type, and language preferences; (c) session data required to maintain authenticated state; (d) error reports and crash logs generated by the client-side applications; and (e) security logs documenting authentication attempts, rate-limiting violations, and suspicious activity flags.
Third-Party Federated Authentication Providers
Where a Data Subject opts to register or log in through an external identity provider (e.g., Google LLC, Apple Inc., GitHub, Inc., or Microsoft Corporation), the Operator may receive specific profile attributes from that external provider, strictly limited to the scopes explicitly authorized by the Data Subject during the federated authentication flow. Typically, this includes: (a) the Data Subject's email address; (b) the Data Subject's display name; (c) a link to the Data Subject's public profile picture (URL); and (d) a unique identifier from the provider (e.g., Google User ID, Apple ID). The Operator does not request or receive any data beyond these minimal scopes.
Metadata Scraping from External Websites
To generate link previews and enable visual bookmark recognition, the Operator's backend systems send automated HTTP/S GET requests to the target URLs submitted by the Data Subject. These requests retrieve only the standard Open Graph metadata (e.g., <meta property="og:title">, <meta property="og:description">, <meta property="og:image">, and the page's <title> element). The Operator does not index, store, or process the full HTML content of external pages, nor does it intentionally collect Personal Data from these external sources. The scraping process may reveal to the target website's infrastructure provider (e.g., their web server or analytics provider) that a request originated from the Operator's IP addresses.
Payment Processors and Financial Institutions
The Operator receives a confirmation of payment, invoice data, and a client-side tokenized reference (e.g., Stripe PaymentIntent ID, PayPal transaction ID) from third-party payment processors (such as Stripe, Inc., PayPal (Europe) S.à r.l. et Cie, S.C.A., Apple Inc., and Google LLC). This data is used exclusively for: (a) billing reconciliation; (b) subscription status verification; (c) invoice generation; and (d) tax compliance. The Operator does not receive full credit card numbers, CVV/CVC codes, or bank account details.
Connected Applications and OAuth Flows
When an End-User authenticates to a Developer Application using Bookmer ID, the Operator's OAuth server transmits the specific Personal Data elements corresponding to the scopes authorized by the End-User (e.g., email address, display name, profile picture URL) to the Developer Application. The Developer acts as an independent Data Controller for the data received.
Purposes of Processing and Specific Legal Bases
Contractual Performance (Art
6(1)(b) GDPR). The Operator processes Personal Data to perform the contract with the Data Subject and to take steps at the Data Subject's request prior to entering into a contract. This includes, but is not limited to:
Creating and managing User accounts and profiles;
Enabling synchronization of bookmarks, folders, and settings across multiple devices;
Facilitating public sharing, private storage, and publishing features;
Processing subscriptions, payments, cancellations, and refunds;
Providing customer support for account-specific technical issues;
Authenticating Users via Bookmer ID and enabling OAuth flows for Developer Applications;
Sending transactional and service-related communications, including verification emails, password reset links, and account security notifications.
Legitimate Interests Pursued by the Controller (Art
6(1)(f) GDPR). The Operator processes Personal Data based on its legitimate interests, which are not overridden by the fundamental rights and freedoms of the Data Subject. The specific legitimate interests pursued by the Controller are:
Platform Security and Integrity: Detecting, preventing, and responding to fraudulent activities, phishing, credential-stuffing, brute-force attacks, denial-of-service attacks, and other malicious activities to ensure a secure and trustworthy environment for all Users (Recital 47 GDPR).
Service Reliability and Troubleshooting: Maintaining network and information security, including monitoring technical logs to diagnose errors, fix bugs, optimize system performance, and prevent service disruptions.
Product Improvement and Innovation: Analyzing aggregated, pseudonymized usage patterns to enhance user interface ergonomics, improve algorithmic discovery recommendation engines, prioritize feature development, and conduct internal research into User behavior for product optimization.
Direct Marketing (Business-to-Business): Sending transactional and service-related communications and, where applicable, promoting similar Bookmer products or features to existing business or enterprise Users, subject to the User's explicit right to object at any time without incurring any cost.
Legal Defense and Enforcement: Establishing, exercising, and defending legal claims, including the enforcement of the Terms of Service, the detection and prosecution of breaches, and the response to lawful requests from judicial or administrative authorities.
Legal Obligations (Art
6(1)(c) GDPR). The Operator processes data to comply with statutory retention and disclosure obligations imposed by German, European, and international laws, including but not limited to:
Tax and commercial law retention periods under §§ 147 of the German Fiscal Code (Abgabenordnung - AO) and § 257 of the German Commercial Code (Handelsgesetzbuch - HGB), mandating the retention of financial and transactional records for up to ten (10) years.
Obligations under the German Telemedia Act (TMG) and the Digital Services Act (DSA) to retain specific traffic data and to provide information to law enforcement and regulatory authorities upon lawful request.
Obligations under anti-money laundering laws (Geldwäschegesetz - GwG) to verify the identity of Users in certain circumstances.
Obligations under consumer protection laws (e.g., the German Civil Code - BGB) regarding the provision of withdrawal rights and warranty information.
Consent (Art
6(1)(a) GDPR). For processing activities that are neither contractually necessary nor based on a legitimate interest, including the placement of non-essential tracking cookies, the sending of promotional newsletters to consumers (B2C), and specific advanced profiling activities, the Operator obtains the Data Subject's explicit, freely given, specific, informed, and unambiguous consent (opt-in) prior to processing. This consent is documented and may be withdrawn at any time by the Data Subject through the account settings, cookie preference center, or by clicking the unsubscribe link in marketing emails.
Protection of Vital Interests (Art
6(1)(d) GDPR). In rare and exceptional circumstances, the Operator may process Personal Data to protect the vital interests of the Data Subject or of another natural person, including, but not limited to, situations involving a medical emergency or a threat to life.
Task Carried Out in the Public Interest (Art
6(1)(e) GDPR). The Operator does not typically process Personal Data for tasks carried out in the public interest or in the exercise of official authority vested in the Controller. This basis is not applicable to the Services.
Cookies, Tracking Technologies, and Local Storage
Definition and Classification of Cookies
The Operator uses cookies (small text files stored on the Data Subject's device), local storage, session storage, IndexedDB, and similar technologies to enhance the functionality, security, and usability of the Services. The Operator categorizes cookies into the following types, in compliance with the German TTDSG and the ePrivacy Directive:
Strictly Necessary Cookies: Essential for the operation of the Services
They enable core functionalities such as user authentication, session persistence, security, load balancing, and the prevention of fraudulent activity. They are set in response to actions taken by the Data Subject (e.g., logging in, submitting forms) and do not require consent.
Functional and Preference Cookies: Allow the Services to remember choices made by the Data Subject (e.g., language preferences, display settings, wallpaper selections, folder collapse states) to provide enhanced, personalized features. These cookies require the Data Subject's consent.
Analytics and Performance Cookies: Collect aggregated, pseudonymized information about how Data Subjects interact with the Services, including page visits, click-through rates, and error rates. The Operator uses this data to improve platform performance and user experience. These cookies require the Data Subject's consent.
Marketing and Targeting Cookies: Used to deliver advertisements relevant to the Data Subject's interests, to limit the number of times an advertisement is displayed, and to measure the effectiveness of advertising campaigns. The Operator does not deploy third-party marketing cookies on the Bookmer platform without explicit consent. These cookies require the Data Subject's consent.
Consent Management Platform (CMP)
The Operator operates a transparent, granular consent management platform (cookie banner) that is presented to the Data Subject upon their first visit to the website. The CMP allows the Data Subject to: (a) accept all cookies; (b) reject all non-essential cookies; or (c) customize their preferences on a granular, category-by-category basis. The Data Subject may modify their preferences at any time via the "Cookie Settings" link in the website footer or account dashboard. Consent records are retained in accordance with Art. 7(1) GDPR to demonstrate compliance.
Local Storage, IndexedDB, and Browser Extension Storage
The Services utilize the browser's local storage and IndexedDB to cache non-sensitive data, such as UI state preferences, offline synchronization metadata, and temporary data. Browser extensions store API tokens locally to facilitate quick-add functionality and contextual bookmarking. The Data Subject may clear all local storage, cache, and extension data at any time through their browser settings. The Operator does not have access to data stored exclusively in the Data Subject's local client environment.
Recipients, Processors, and Third-Party Disclosures
Internal Access and Confidentiality Obligations
Access to Personal Data is strictly limited to authorized personnel of the Operator, including software engineers, support staff, security analysts, and product managers, on a stringent "need-to-know" basis. All personnel are bound by legally enforceable confidentiality agreements (including clauses under § 53 BDSG) and undergo regular data protection training to ensure compliance with this Policy.
External Processors (Data Processing Agreements)
The Operator engages reputable third-party processors to perform specific technical operations. These processors are bound by Data Processing Agreements (DPAs) that comply with Art. 28 GDPR and include obligations to implement appropriate technical and organizational measures. The categories of processors include:
Category Processor(s) Purpose
Cloud Hosting and Infrastructure Amazon Web Services (AWS) (servers in EU and US) Server storage, compute resources, load balancing, networking
Database Hosting AWS Relational Database Service (RDS), AWS DynamoDB Structured and unstructured data storage
Email Delivery and Transactional Messaging Amazon SES, SendGrid (Twilio) Magic links, verification codes, system notifications
Payment Processors Stripe, Inc., PayPal (Europe) S.à r.l. et Cie, S.C.A., Apple Inc. (Apple Pay), Google LLC (Google Pay) Payment processing, subscription billing
Analytics and Performance Monitoring Sentry, Datadog, Plausible (anonymized) Error tracking, performance monitoring, debugging
Content Delivery Network (CDN) Cloudflare, Inc. Global asset distribution, DDoS protection, caching
Security and Abuse Prevention Various security monitoring tools Intrusion detection, fraud prevention, rate limiting
Public and Governmental Disclosures
The Operator may disclose Personal Data to public authorities, law enforcement agencies, or courts where such disclosure is: (a) required by law (e.g., a valid subpoena, search warrant, or court order); (b) necessary to comply with the Digital Services Act (DSA) regarding illegal content removal; (c) necessary to protect the vital interests of a Data Subject or to protect the rights, property, or safety of the Operator, its Users, or the public; or (d) otherwise necessary to establish, exercise, or defend legal claims.
No Sale of Personal Data
The Operator does not, and has not in the preceding twelve (12) months, "sold" Personal Data to third parties in exchange for monetary compensation, as that term is traditionally understood. The Operator does not engage in the trade, rental, or leasing of Personal Data to data brokers or advertising networks.
Disclosure to Developer Applications (OAuth Recipients)
When an End-User authenticates to a Developer Application via Bookmer ID, the Operator transmits the specific Personal Data elements corresponding to the scopes authorized by the End-User. The Developer acts as an independent Data Controller for the data received. The Operator does not control or supervise the Developer's subsequent data processing practices.
International Transfers and Cross-Border Data Flows
Global Infrastructure and Cross-Border Transfers
The Operator utilizes a global, multi-region cloud infrastructure to deliver the Services. This necessarily involves the transfer of Personal Data to servers, data centers, and processing facilities located outside the European Economic Area (EEA), including specifically to the United States of America and potentially other countries where the Operator's processors maintain operations.
Transfer Mechanisms and Safeguards (SCCs)
To ensure an adequate level of data protection for such international transfers, in full compliance with Chapter V of the GDPR and the ruling of the Court of Justice of the European Union in Case C-311/18 (Schrems II), the Operator relies upon the following legally valid transfer mechanisms:
EU Standard Contractual Clauses (SCCs): The Operator has implemented the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914 of 4 June 2021) for the transfer of Personal Data to third countries. Specifically, Module One (Controller to Controller) is used for transfers to independent Data Controllers, and Module Two (Controller to Processor) is used for transfers to third-party processors acting on the Operator's behalf.
Where applicable, the EU-US Data Privacy Framework (DPF): The Operator monitors the adequacy status of the EU-US Data Privacy Framework. Where the Operator or its processors are certified under the DPF, such certification serves as an additional lawful transfer mechanism.
Supplementary Technical Measures
In addition to the SCCs, the Operator implements robust supplementary technical measures, including: (a) end-to-end Transport Layer Security (TLS) 1.3 encryption for all data in transit; (b) Advanced Encryption Standard (AES-256-GCM) for data at rest; (c) pseudonymization and tokenization of identifiable data elements where feasible; and (d) strict access controls and network-level isolation.
Data Protection Impact Assessments (DPIAs)
Where required, the Operator conducts comprehensive DPIAs in accordance with Art. 35 GDPR to assess and mitigate the risks associated with international transfers, particularly where the data protection laws of the recipient country do not provide an adequate level of protection.
Data Retention, Storage Limitation, and Erasure Schedules
General Retention Principle (Art
5(1)(e) GDPR). The Operator retains Personal Data only for as long as is reasonably necessary to fulfill the purposes for which it was collected, in strict adherence to the principle of storage limitation. The specific retention periods vary depending on the type of data and the legal, contractual, or operational context. Once the retention period has expired, Personal Data is securely deleted or permanently anonymized.
Comprehensive Retention Schedule
The following table sets forth the specific retention periods and the legal bases for each category of Personal Data:
Category of Data Standard Retention Period Legal Basis (GDPR)
Account Data (Active Users) For the entire duration of the active account, plus a reasonable transition period of up to thirty (30) days after account closure to facilitate data export and ensure continuity. Contractual necessity (Art. 6(1)(b)).
User Content (Bookmarks, Folders, Notes) For the entire duration of the active account, until the User explicitly deletes the specific content, or for up to thirty (30) days after account termination. User instruction and contractual necessity (Art. 6(1)(b)).
Authentication Logs and Session Data For up to ninety (90) days for active accounts, and up to twelve (12) months in aggregated, fully anonymized form for security auditing purposes. Legitimate interest in security and fraud prevention (Art. 6(1)(f)).
Billing and Transaction Data For up to ten (10) years from the end of the calendar year in which the transaction occurred. Legal obligation under German tax law (§ 147 AO, § 257 HGB) (Art. 6(1)(c)).
Support Correspondence and Tickets For up to three (3) years from the final resolution of the support ticket. Legitimate interest in customer service consistency and legal defense (Art. 6(1)(f)).
Consent Records and Documentation For the duration of the active consent, plus up to three (3) years after consent is withdrawn to demonstrate compliance with Art. 7(1) GDPR. Legal obligation (Art. 6(1)(c)).
Security Logs and Abuse Records For up to twelve (12) months, after which logs are either permanently deleted or fully anonymized for statistical analysis. Legitimate interest in platform security (Art. 6(1)(f)).
Developer API Usage Logs For up to six (6) months, after which they are aggregated and anonymized. Operational necessity and service monitoring (Art. 6(1)(f)).
Cookies and Tracking Data For the duration of the User's session or as specified in the User's consent preferences, subject to the User's right to withdraw consent. Consent (Art. 6(1)(a)) or legitimate interest (Art. 6(1)(f)).
Extended Retention for Legal Holds
Where the Operator is subject to a legal hold, pending litigation, a valid investigative request from law enforcement, or a statutory retention requirement that exceeds the standard periods above, the Operator may extend the retention period of specific data. In such cases, the data will be segregated, encrypted, and will not be processed for any purpose other than fulfilling the specific legal obligation.
Data Erasure and Destruction Procedures
Upon the expiry of the applicable retention period, the Operator will securely delete or anonymize the Personal Data using industry-standard secure deletion methods (e.g., overwriting, cryptographic erasure, or physical destruction of storage media). Data stored in backup archives may be retained for a limited additional period (typically up to thirty (30) days) to ensure restoration capabilities in the event of a catastrophic failure, but such backup copies are not actively processed.
Technical and Organizational Measures (security)
Comprehensive Security Infrastructure (Art
32 GDPR). The Operator implements a multi-layered security architecture comprising both technical and organizational measures (TOMs) designed to protect Personal Data against accidental loss, unauthorized access, unlawful processing, alteration, disclosure, or destruction. These measures are continuously reviewed, updated, and improved in response to evolving threats and technological developments.
Encryption Standards
All data transmitted between the User's device and the Operator's servers is protected using end-to-end Transport Layer Security (TLS) 1.3 or higher, utilizing strong cipher suites (e.g., TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384). Data stored on the Operator's servers (including databases, file systems, and backups) is encrypted at rest using Advanced Encryption Standard (AES-256-GCM) or equivalent industry-standard encryption algorithms.
Access Controls and Authentication
The Operator enforces strict role-based access controls (RBAC) and the principle of least privilege (PoLP). Access to production databases, server logs, internal administrative panels, and code repositories is restricted to the minimum number of authorized personnel required for specific operational tasks. All personnel are required to use multi-factor authentication (MFA) and secure VPN connections to access internal systems.
Network Security and Monitoring
The Operator employs a comprehensive network security infrastructure, including: (a) next-generation firewalls with intrusion detection and prevention (IDS/IPS) capabilities; (b) continuous network traffic monitoring and analysis; (c) automated threat detection and alerting systems; (d) DDoS protection; and (e) regular vulnerability scanning and penetration testing.
Regular Security Testing and Audits
The Operator conducts periodic internal and external security audits, including: (a) quarterly vulnerability assessments; (b) annual penetration tests performed by independent third-party security firms; (c) regular code reviews and security testing of new features; and (d) continuous monitoring of the OWASP Top 10 and other common vulnerabilities.
Incident Response Plan and Breach Notification
A comprehensive data breach notification and incident response plan is in place, which enables the Operator to: (a) detect, contain, and remediate security incidents in a timely manner; (b) notify the competent supervisory authority within seventy-two (72) hours of becoming aware of a data breach, as required by Art. 33 GDPR; and (c) notify affected Data Subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Art. 34 GDPR).
User Responsibility for Own Security
While the Operator employs state-of-the-art security measures, no online service can guarantee absolute security against all threats. The Data Subject bears the primary responsibility for protecting their own devices, maintaining the confidentiality of their login credentials, and ensuring that their operating systems and browsers are up-to-date with the latest security patches. The Data Subject is strongly advised to enable two-factor authentication (2FA) / passkeys and to use strong, unique passwords.
Automated Decision-Making and Profiling
Absence of Significant Automated Decisions (Art
22 GDPR). The Operator does not engage in automated decision-making, including profiling, that produces legal effects concerning the Data Subject or similarly significantly affects the Data Subject, within the meaning of Art. 22(1) and (4) of the GDPR, without a separate legal basis or required safeguards. The Services do not utilize fully automated algorithms to make decisions regarding creditworthiness, employment, health, insurance, or similar matters.
Automated Security and Abuse Checks
The Services employ automated machine learning and rule-based algorithms exclusively for operational security screening, spam detection, phishing detection, rate-limiting, and abuse prevention. These automated checks are inherent to the provision of secure services and do not constitute "automated decision-making" as defined in Art. 22 GDPR, as they are strictly necessary for entering into and performing the contract (Art. 22(2)(a) GDPR) and are authorized by EU or Member State law (Art. 22(2)(b) GDPR). These checks do not produce legal effects concerning the Data Subject in the absence of human intervention; any significant action (e.g., account suspension) is subject to human review upon appeal.
Profiling for Service Improvement
The Operator may generate pseudonymized profiles reflecting user preferences (e.g., preferred categories of bookmarks, link types, usage frequency) to personalize recommendations and improve the discovery algorithm. However, these profiles are not used for targeted advertising outside the platform and are based on pseudonymized data that does not permit direct re-identification.
Data Subject Rights and How to Exercise Them
Exhaustive Enumeration of Rights
Depending on the applicable jurisdiction (EEA, UK, Switzerland, California, or other), the Data Subject is entitled to the following rights regarding their Personal Data. The Operator is obligated to facilitate and respond to these rights free of charge, subject to the statutory exceptions and verification processes.
Right of Access (Art
15 GDPR / Cal. Civ. Code § 1798.110). The Data Subject has the right to obtain from the Operator confirmation as to whether or not Personal Data concerning them is being processed, and, where that is the case, access to the Personal Data and the following information: (a) the purposes of the processing; (b) the categories of Personal Data concerned; (c) the recipients or categories of recipients to whom the Personal Data have been or will be disclosed; (d) the envisaged retention period; (e) the existence of the right to request rectification, erasure, or restriction; (f) the right to lodge a complaint with a supervisory authority; and (g) any available information as to the source of the data (where not collected from the Data Subject directly). The Operator shall provide a copy of the Personal Data undergoing processing, free of charge, and may charge a reasonable fee for any additional copies requested.
Right to Rectification (Art
16 GDPR / Cal. Civ. Code § 1798.106). The Data Subject has the right to obtain from the Operator the rectification of inaccurate Personal Data concerning them without undue delay, and the right to have incomplete Personal Data completed, including by means of providing a supplementary statement.
Right to Erasure (Right to be Forgotten) (Art
17 GDPR / Cal. Civ. Code § 1798.105). The Data Subject has the right to obtain from the Operator the erasure of Personal Data concerning them without undue delay where one of the following grounds applies: (a) the Personal Data is no longer necessary in relation to the purposes for which it was collected; (b) the Data Subject withdraws consent on which the processing is based (where applicable); (c) the Data Subject objects to processing pursuant to Art. 21(1); (d) the Personal Data has been unlawfully processed; or (e) the Personal Data has to be erased for compliance with a legal obligation. This right is subject to exceptions, including where processing is necessary for compliance with a legal obligation (e.g., tax retention) or for the establishment, exercise, or defense of legal claims.
Right to Restriction of Processing (Art
18 GDPR). The Data Subject has the right to obtain from the Operator restriction of processing where: (a) the Data Subject contests the accuracy of the Personal Data; (b) the processing is unlawful and the Data Subject opposes erasure; (c) the Operator no longer needs the Personal Data for processing but the Data Subject requires it for legal claims; or (d) the Data Subject has objected to processing pursuant to Art. 21(1) pending verification of whether the legitimate grounds of the Operator override the Data Subject's interests.
Right to Data Portability (Art
20 GDPR / Cal. Civ. Code § 1798.130). The Data Subject has the right to receive the Personal Data concerning them, which they have provided to the Operator, in a structured, commonly used, and machine-readable format (e.g., JSON, HTML), and the right to transmit that data to another controller without hindrance from the Operator, where: (a) processing is based on consent or a contract; and (b) processing is carried out by automated means. This right includes the right to have the Personal Data transmitted directly from the Operator to another controller, where technically feasible.
Right to Object (Art
21 GDPR). The Data Subject has the right to object, on grounds relating to their particular situation, at any time to processing of Personal Data concerning them which is based on legitimate interests (Art. 6(1)(f)). The Operator shall no longer process the Personal Data unless the Operator demonstrates compelling legitimate grounds for the processing which override the Data Subject's interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims. The Data Subject also has an absolute right to object to processing for direct marketing purposes.
Right to Withdraw Consent (Art
7(3) GDPR). Where processing is based on consent (Art. 6(1)(a)), the Data Subject has the right to withdraw their consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. Withdrawal can be effected through the account settings, cookie preference center, or by clicking the unsubscribe link in marketing emails.
Right to Lodge a Complaint (Art
77 GDPR). The Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement, if they consider that the processing of Personal Data concerning them infringes the GDPR.
California Consumer Rights (CCPA/CPRA)
California residents are entitled to the following additional rights under the CCPA/CPRA: (a) right to know the categories and specific pieces of Personal Information collected; (b) right to delete Personal Information; (c) right to correct inaccurate Personal Information; (d) right to opt-out of the sale or sharing of Personal Information for cross-context behavioral advertising; (e) right to limit the use of Sensitive Personal Information; and (f) right to non-discrimination for exercising rights.
Exercising Your Rights - Verification Process
To exercise any of these rights, the Data Subject must submit a verifiable consumer request to the Operator using the contact details provided in Article II of this Policy: support@mail.bookmer.com. The Operator may request specific information from the Data Subject to verify their identity (e.g., email address, account ID, recent transaction details) to ensure the security of the data and prevent fraudulent requests. The Operator will respond to all legitimate requests within the statutory timeframes (typically one (1) month, extendable by two (2) months for complex requests, or forty-five (45) days for California residents).
Bookmer ID - Authentication and Identity Layer
Purpose and Function of Bookmer ID
Bookmer ID constitutes a centralized, comprehensive identity and access management (IAM) system that issues a persistent, globally unique digital identifier to each registered User. This identity layer serves a dual purpose: (a) authenticating the User into the Bookmer Core ecosystem; and (b) enabling the User to leverage their Bookmer ID credentials as a trusted, third-party identity provider for external Developer Applications through the implementation of standardized OAuth 2.0 and OpenID Connect (OIDC) protocols.
Authentication Modalities
The Data Subject may authenticate their identity via a variety of modalities, including: (a) traditional password-based login (with hashed and salted passwords); (b) email-based "Magic Links"; (c) SMS or authenticator application-based one-time passwords (OTPs); and (d) FIDO2-compliant passkeys (biometric and device-based authentication).
OAuth 2.0 and OpenID Connect Flows. When authenticating to an external Developer Application, the Data Subject is presented with a transparent consent screen that enumerates the specific categories of data (scopes) requested by the Developer, including but not limited to: (a) the Data Subject's email address; (b) the Data Subject's display name; (c) the Data Subject's profile image URL; and (d) the Data Subject's Bookmer ID account identifier. The Data Subject bears the sole and exclusive responsibility for reviewing the content and scope of the consent screen and for authorizing or denying the requested permissions.
Granular Consent and Scope Management
The Operator's OAuth server respects the principle of minimal scope. The Data Subject may grant, review, and revoke scopes at any time through their Bookmer ID account settings. Revocation of access does not automatically compel the Developer Application to delete previously transferred data; the Data Subject must direct any deletion request directly to the Developer.
Developer Applications and Independent Controllers
Upon the successful completion of the OAuth consent flow, the Developer Application becomes an independent, separate Data Controller for the data received. The Operator assumes no control, oversight, or liability over the Developer's subsequent storage, processing, transfer, or misuse of the Data Subject's Personal Data. The Data Subject is strongly urged to review the Developer's separate privacy policy prior to authorizing a Bookmer ID login.
Bookmer Core - Bookmark Management and Discovery
Storage and Organization of Bookmarks
Bookmer Core provides the Data Subject with a powerful, multi-tenant, cloud-based repository for the persistent storage, granular classification, and dynamic manipulation of web bookmarks. This includes, but is not limited to: (a) the creation of infinite-depth hierarchical folder structures; (b) the application of user-defined tags; (c) full-text search within stored notes and titles; (d) advanced filtering algorithms; and (e) the ability to import data via Netscape HTML bookmarks file format, as well as to export such data in machine-readable JSON, CSV, or HTML structures.
Public Sharing and Social Discovery Features
The Services include a unique, proprietary social discovery engine designed to expose publicly shared collections, trending links, and popular content to the broader User community. This discovery feature is powered by automated, algorithmic recommendation systems that analyze aggregate interaction data, including click-through rates, public collection additions, and user engagement metrics, to surface relevant content. The Data Subject explicitly acknowledges that such algorithmic suggestions are generated on an objective, statistical basis and do not constitute an endorsement, guarantee, or warranty by the Operator regarding the quality, accuracy, safety, or legality of the recommended external websites.
Algorithmic Recommendations and Personalization
The Operator may process pseudonymized user preferences, bookmark categories, and interaction history to provide personalized recommendations. This processing is based on the legitimate interest in improving the user experience (Art. 6(1)(f) GDPR) and is conducted in a manner that does not permit direct re-identification of the Data Subject.
Browser Extensions and Local Data
In order to facilitate seamless link saving and management, the Operator provides browser extensions that interact with the User's local browser environment. These extensions possess permissions to read the User's current browser URL, page title, and metadata for the sole purpose of creating bookmarks. The extensions store local tokens and temporary data in the browser's extension storage. The Data Subject may uninstall the extension at any time, which will remove all extension-specific local data.
Developer Ecosystem and API Integrations
Developer Registration and App Review
Any User wishing to integrate Bookmer ID into their software ecosystem must register as a Developer via the dedicated Developer Console. This registration requires the submission of a verified corporate or individual identity, a valid support email address, a detailed description of the intended application, the exact redirect URIs, and a functioning privacy policy URL. The Operator operates a stringent, internal App Review process, during which the Developer Application is scrutinized for security posture, compliance with these Terms, and the proportionality of requested OAuth scopes.
API Usage and Data Transfers
Developers are granted a limited, non-exclusive, non-transferable license to access the Operator's APIs solely for the purpose of enabling authentication, authorization, and profile retrieval for End-Users who explicitly consent via the OAuth flow. The Operator logs API usage for monitoring, rate-limiting, and security purposes.
Developer Data Retention and Deletion Obligations
Developers must implement and enforce a data retention policy that provides for the deletion or anonymization of all Personal Data obtained via Bookmer ID within a commercially reasonable timeframe, not to exceed ninety (90) days following: (a) the End-User's revocation of access; or (b) the termination of the Developer's API credentials.
Audit Rights
The Operator reserves the right, upon fourteen (14) days' prior written notice, to conduct a technical or documentary audit of the Developer's data handling practices to verify compliance with this Policy. Should the Developer fail the audit, the Operator may summarily suspend or permanently revoke the Developer's API access.
Email, Alias Addresses, and Forwarding
Transactional and Service-Related Emails
The Operator sends transactional and service-related emails to the Data Subject's registered email address, including but not limited to: (a) account verification and confirmation emails; (b) password reset links; (c) security notifications (e.g., login from a new device); (d) subscription confirmations, invoices, and renewal reminders; and (e) support ticket responses. These emails are essential for the operation of the Services and are sent based on contractual necessity (Art. 6(1)(b) GDPR).
Email Alias and Forwarding Services
Bookmer ID may offer the Data Subject the ability to create unique, randomized, or user-defined email aliases that forward communications to the Data Subject's primary inbox. The Operator processes headers, delivery events, bounce events, and complaint events to provide forwarding services, prevent spam, and protect deliverability.
Email Tracking and Delivery Metrics
The Operator uses standard email delivery infrastructure (e.g., Amazon SES, SendGrid) that may automatically track: (a) delivery confirmations; (b) bounce events (hard and soft bounces); (c) complaint events (spam reports); and (d) open rates and click-through rates (where enabled and where such tracking is disclosed). This data is used exclusively to ensure reliable email delivery and to maintain the reputation of the Operator's email sending infrastructure.
Public Pages, Search Engines, and Social Previews
Public Content and Search Engine Indexing
If the Data Subject designates content as "Public," this information becomes accessible to the global public internet, including search engine crawlers (e.g., Googlebot, Bingbot, DuckDuckBot) and any visitor accessing the public URL. The Operator exercises reasonable efforts to honor no-index and no-archive metadata directives where configured by the Data Subject, but disclaims control over third-party caching, archiving, or indexing services.
Social Media Previews and Open Graph
When a public Bookmer page or collection is shared on social media platforms (e.g., Twitter/X, Facebook, LinkedIn), these platforms may automatically fetch Open Graph metadata (title, description, thumbnail) to generate a preview. This functionality is inherent to the public nature of the content and is not controlled by the Operator.
Third-Party Caching and Archival Services
Public content may be automatically cached, archived, or preserved by third-party services such as the Internet Archive's Wayback Machine, Google Cache, or other digital preservation services. The Operator cannot and does not control the retention or accessibility of content by these third-party archiving services.
Compliance with German and European Laws
Telemedia Act (TMG) Compliance
The Operator strictly adheres to the obligations set forth in the German Telemedia Act (TMG), including: (a) the provision of clear and transparent information regarding the identity of the Operator (imprint); (b) the obligation to provide contact details for rapid communication; and (c) the duty to disclose information on the use of cookies and other tracking technologies, where applicable.
Telecommunications-Telemedia Data Protection Act (TTDSG)
The Operator complies with the TTDSG, which implements the ePrivacy Directive in Germany, by: (a) obtaining legally compliant consent for the storage of non-essential cookies and local storage on terminal equipment; (b) providing clear and easily accessible consent management options; and (c) ensuring that essential cookies (technically necessary for the provision of the Services) are used without consent.
Digital Services Act (DSA) Compliance
In accordance with the European Digital Services Act (Regulation 2022/2065), the Operator: (a) provides a transparent notice-and-action mechanism for the reporting of illegal content; (b) publishes clear statements of reasons for any content moderation decisions that restrict content visibility or user access; (c) provides contact information of its legal representative for DSA purposes; and (d) complies with the transparency reporting obligations, where applicable.
Federal Data Protection Act (BDSG) Compliance
The Operator complies with the German Federal Data Protection Act (BDSG), which supplements the GDPR with specific national provisions, including: (a) the obligation to appoint a Data Protection Officer where required; (b) specific requirements for data processing in the employment context (not applicable); and (c) the right to lodge a complaint with the German supervisory authorities.
Updates and Modifications to This Policy
Right to Amend
The Operator reserves the right to modify, update, amend, or supplement this Privacy Policy at any time in response to: (a) changes in the Services (e.g., new features, new processing activities); (b) changes in the applicable legal framework (e.g., new laws, judicial rulings, or regulatory guidance); (c) changes in the Operator's security practices or organizational structure; or (d) changes in the practices of third-party processors or subprocessors.
Notification of Material Changes
In the event of a material modification to this Policy, the Operator shall provide the Data Subject with reasonable advance notice via: (a) an email to the registered address associated with the Data Subject's account; (b) a prominent notification displayed within the Data Subject's account dashboard or upon the next login attempt; or (c) a notification on the Bookmer website.
Effective Date and Continued Use
Any modifications shall become effective thirty (30) calendar days following the aforementioned notification date. The Data Subject's continued use of the Services after the effective modification date shall constitute the Data Subject's unequivocal, informed acceptance of the revised Policy. Should the Data Subject object to the modifications, the Data Subject's sole remedy is to terminate their account and cease using the Services.
Contact, Complaints, and Further Information
Primary Contact for Privacy Matters (Embedded)
For all privacy-related inquiries, including but not limited to data subject rights requests, questions regarding this Policy, reports of data breaches, or complaints, please contact the Operator's dedicated privacy compliance team using the following embedded details:
Email: support@mail.bookmer.com
Postal Address: Gabriel Sgroi, Charlottenstr. 47, 73230 Kirchheim unter Teck, Germany.
Supervisory Authority (Germany)
Without prejudice to any other administrative or judicial remedy, Data Subjects have the right to lodge a complaint with the competent supervisory authority, which for the Operator is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Baden-Württemberg
Königstraße 10a,
70173 Stuttgart,
Germany.
Website: https://www.baden-wuerttemberg.datenschutz.de/
International Complaints
For Data Subjects residing in California, complaints may be directed to the California Privacy Protection Agency (CPPA) or the Office of the Attorney General of California. For Data Subjects in the EEA, complaints may be directed to the supervisory authority in their Member State of habitual residence.
Response Timeframes
The Operator endeavors to respond to all privacy inquiries and data subject requests within the statutory timeframes set forth in the GDPR (one (1) month, extendable by two (2) months for complex requests) and the CCPA/CPRA (forty-five (45) days). The Operator will acknowledge receipt of any formal request within ten (10) business days.
Glossary of Key Terms
Bookmer Core: The primary bookmark management and publishing platform operated by the Operator, allowing Users to collect, organize, search, customize, synchronize, and publish links, folders, collections, and associated metadata.
Bookmer ID: The centralized authentication, identity, and account infrastructure operated by the Operator, providing login, passkey management, email verification, OAuth, and session management for Bookmer Core and connected Developer Applications.
CCPA/CPRA: The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (California Civil Code §§ 1798.100 et seq.), which grants specific privacy rights to California residents.
COPPA: The Children's Online Privacy Protection Act (15 U.S.C. §§ 6501-6506), a United States federal law governing the collection of Personal Data from children under the age of thirteen (13).
Data Controller: The natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of Personal Data (Art. 4(7) GDPR).
Data Processor: A natural or legal person which processes Personal Data on behalf of the Controller (Art. 4(8) GDPR).
Data Subject: An identified or identifiable natural person whose Personal Data is processed by the Controller (Art. 4(1) GDPR).
Developer Application: A software application, website, or platform developed by a third party that integrates Bookmer ID's OAuth/OpenID Connect capabilities to authenticate End-Users.
DSA: The Digital Services Act (Regulation 2022/2065), a European Union regulation concerning content moderation, transparency, and the obligations of digital service providers.
EEA: The European Economic Area, comprising the Member States of the European Union, Iceland, Liechtenstein, and Norway.
ePrivacy Directive: Directive 2002/58/EC of the European Parliament and of the Council concerning the processing of Personal Data and the protection of privacy in the electronic communications sector.
GDPR: The General Data Protection Regulation (Regulation (EU) 2016/679), the primary European Union regulation governing the processing of Personal Data.
OAuth 2.0: An open standard for access delegation, commonly used as a way for users to grant websites or applications access to their information on other websites without giving them the passwords.
OpenID Connect (OIDC): An identity layer on top of the OAuth 2.0 protocol, allowing clients to verify the identity of the end-user based on the authentication performed by an authorization server.
Passkey: A FIDO2-based, passwordless authentication credential that uses public-key cryptography and biometrics to enable secure, phishing-resistant authentication.
Sensitive Personal Data: Special categories of Personal Data referred to in Art. 9(1) GDPR, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification, health data, or sex life/sexual orientation.
Standard Contractual Clauses (SCCs): Model contractual clauses adopted by the European Commission to facilitate the lawful transfer of Personal Data from the EEA to third countries.
TTDSG: The German Telecommunications-Telemedia Data Protection Act (Telekommunikation-Telemedien-Datenschutz-Gesetz), implementing the ePrivacy Directive in Germany.
BY REGISTERING FOR, ACCESSING, OR USING THE BOOKMER SERVICES, THE DATA SUBJECT ACKNOWLEDGES, WITHOUT RESERVATION, THAT THEY HAVE READ, COMPREHENDED, AND UNEQUIVOCALLY CONSENT TO THE DATA PROCESSING PRACTICES DESCRIBED IN THIS PRIVACY POLICY.