Privacy Policy of M O E Z G m b H (Apostille-Germany.com)
Note on language and legal validity
This English version is provided for convenience only. In case of any discrepancies or contradictions, exclusively the German version of our Privacy Policy shall be legally binding. You can find the German version here: https://apostille-germany.com/ds/.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
M O E Z GmbH, Im Mediapark 5, 50670 Cologne, Germany
Phone: +49 (0) 221 123456
E-Mail: service
apostille-germany.com
For data protection enquiries, you can reach us at:
E-Mail: ds
apostil-germania.com
No data protection officer is appointed as required by law. The person responsible for all data protection matters is the management of M O E Z G m b H – D r. I n g a A r t a m o n o v a die Geschäftsführung der M O E Z G m b H.
2. General information on data processing
We process personal data insofar as this is necessary for the provision of our website and for the initiation, performance and handling of our contractual services.
“Personal data” means any information relating to an identified or identifiable natural person (e.g. name, contact details, ID number, IP address).
We process your data exclusively on the basis of the GDPR, the German Federal Data Protection Act (BDSG), the Telecommunications Digital Services Data Protection Act (TDDDG) and other applicable statutory provisions.
3. Categories of data processed
Depending on how you use our website and our services, we process in particular the following categories of data:
- Master data: name, address, contact details (e-mail, telephone number, if applicable messenger ID)
- Contract data: booked packages/services, contract content, invoicing data, payment status
- Payment data: bank details (IBAN, BIC, account holder) in case of bank transfers; when using payment service providers (e.g. Stripe, Klarna), further payment information is processed directly by them
- Communication data: correspondence by e-mail, telephone, post as well as via messenger services (e.g. WhatsApp, Telegram, Signal, where applicable video conferences)
- ID data and documents: in particular copies of passports, ID numbers, issuing country/date, civil status documents (e.g. birth certificates, marriage certificates, divorce decrees), insofar as required for fulfilling your order
- Website/technical data: IP address, date and time of access, pages visited, referrer URL, browser type/version, operating system, log files
- Data from online forms: information from contact forms (e.g. name, e-mail, telephone, message) as well as any uploaded files/documents
As a general rule, we receive all personal data directly from you (e.g. by filling in forms, sending documents or within the scope of our communication).
4. Purposes and legal bases of processing
We process your data for the following purposes and on the following legal bases:
Contract initiation and performance
- Responding to enquiries (via website, e-mail, telephone, messenger)
- Provision of the services you have booked (information and support services, document preparation, powers of attorney, submission and dispatch of documents)
Legal basis: Article 6(1)(b) GDPR
Compliance with legal obligations
- Tax and commercial law retention obligations (e.g. under HGB, AO)
- Where applicable, other statutory obligations (e.g. under the German Identity Card Act – Personalausweisgesetz)
Legal basis: Article 6(1)(c) GDPR
IT security and operation of the website
- Ensuring the technical operation of the website (hosting, log files)
- Defence against and tracing of misuse or attack scenarios
Legal basis: Article 6(1)(f) GDPR Our legitimate interest lies in the secure and stable provision of the website and our IT systems.
Payment processing
- Processing payments via banks, Stripe, Klarna
Legal bases: Article 6(1)(b) GDPR (performance of a contract), Article 6(1)(f) GDPR (legitimate interest in secure payment processing)
Communication with authorities and other bodies
- Forwarding of documents and applications to competent authorities, courts, notaries, consulates, translators/interpreters and comparable bodies, insofar as required for the fulfilment of your order
Legal basis: Article 6(1)(b) GDPR
Web analytics and statistics (e.g. Google Analytics, Yandex Metrica, Bing)
- Measuring reach and improving our website
Legal basis: Article 6(1)(a) GDPR (consent) These services are only activated if you have given your consent via the cookie/consent banner.
Processing of special categories of personal data
If the documents you submit contain special categories of personal data within the meaning of Article 9(1) GDPR (e.g. information on religious affiliation in civil status certificates or comparable information in documents), such data will only be processed to the extent necessary for the establishment, exercise or defence of legal claims in the context of the administrative or judicial procedures you have instructed us to handle.
The legal basis is Article 9(2)(f) GDPR in conjunction with Section 22(1) No. 1 BDSG.
You are not obliged to provide us with such data. However, if you do not provide such data, this may mean that we are unable to carry out the specific assignment (e.g. preparation of applications or obtaining certain certificates).
We do not carry out automated decision-making with legal effect within the meaning of Article 22 GDPR.
5. Hosting and server log files
Our website is hosted by a service provider established in the European Union (data centre in Amsterdam, Netherlands), for example:
Hetzner Online GmbH
When you visit our website, the hosting provider automatically processes information in so-called server log files that your browser transmits:
- IP address
- Date and time of the request
- Page/file accessed
- Referrer URL
- Browser type/version
- Operating system used
These log files are generally stored for up to 30 days to ensure the technical operation of the website and to defend against attacks, and are then deleted unless a longer retention period is required for evidentiary purposes (e.g. in the event of specific attack attempts).
Legal basis: Article 6(1)(f) GDPR (legitimate interest in a secure and stable website).
We have concluded a data processing agreement with our hosting provider in accordance with Article 28 GDPR.
6. Contact form, e-mail and upload functions
If you contact us via contact form, e-mail or upload function, the information you provide, including the contact details you enter and the files you upload, will be stored by us for the purpose of processing your enquiry and for any follow-up questions.
The data processed in particular includes:
- Name, e-mail address, telephone number, if applicable messenger ID
- Content of your message
- Any uploaded files (e.g. copies of ID documents, certificates, powers of attorney, forms)
Transmission via our website is generally encrypted (HTTPS). In addition, we provide you with a public PGP/GPG key so that you can encrypt e-mails end-to-end if necessary.
Legal basis: Article 6(1)(b) GDPR (contract initiation/performance).
7. Payment processing (bank transfer, Stripe, Klarna)
For payment processing, the following payment methods may be offered, among others:
- Bank transfer
- Stripe (e.g. credit card, further payment methods)
- Klarna (e.g. instant transfer, purchase on account), depending on availability
For payments via Stripe or Klarna, payment data (e.g. credit card data, account data, transaction data) is processed directly between you and the respective payment service provider. We generally only receive information as to whether a payment was successful (payment status) and, where applicable, a transaction ID.
Stripe: Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. Insofar as personal data is transmitted to Stripe group companies in the USA (e.g. Stripe, Inc.), such data transfer is based, inter alia, on the EU–US Data Privacy Framework and the adequacy decision of the European Commission dated 10 July 2023. We have also ensured that Stripe complies with the data protection principles of the Data Privacy Framework.
Klarna: Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden. A transfer of data to third countries (e.g. USA) cannot be excluded. In such cases, Klarna states that it relies on appropriate safeguards within the meaning of Articles 44 et seq. GDPR (e.g. EU Standard Contractual Clauses).
Legal basis: Article 6(1)(b) GDPR (performance of a contract), Article 6(1)(f) GDPR (legitimate interest in secure payment processing).
8. Disclosure of data to authorities and other recipients
For the performance of the contract concluded with you, it may be necessary to disclose personal data and documents to the following categories of recipients:
- Competent authorities, courts and registry offices (e.g. apostille authorities, registry offices, courts) in Germany, the EU or abroad
- Notaries, consulates and other public bodies
- Sworn translators/interpreters
- Postal and courier services (e.g. Deutsche Post, DHL, UPS, FedEx, DPD, Nova Poshta)
- Payment service providers (Stripe, Klarna, banks)
- Technical service providers in the context of hosting and IT support
Data is only disclosed to the extent necessary for the performance of the contract or where we are legally obliged to do so.
Legal bases: Article 6(1)(b) GDPR (performance of a contract), Article 6(1)(c) GDPR (legal obligations).
Where these service providers process personal data on our behalf (e.g. hosting), we have concluded data processing agreements with them in accordance with Article 28 GDPR.
9. Transfers to third countries
In the following cases, personal data may be transferred to third countries outside the EU/EEA:
- Use of certain payment service providers (e.g. Stripe, Klarna)
- Use of web analytics tools (e.g. Google Analytics, Yandex Metrica)
- Use of certain messenger services (e.g. WhatsApp, Telegram)
- Transfer of documents to authorities or bodies in third countries (e.g. consulates, foreign authorities)
If there is no adequacy decision of the European Commission for the respective third country, the transfer is based on appropriate safeguards (e.g. EU Standard Contractual Clauses) or on your explicit consent (Article 49(1)(a) GDPR).
10. Cookies and web analytics
10.1 Cookies
Our website uses cookies and similar technologies. We distinguish between:
- Technically necessary cookies: These are required for the technical functioning of the website (e.g. session cookies, security functions). Legal basis: Article 6(1)(f) GDPR (legitimate interest in a functional website) and Section 25(2) TDDDG.
- Optional cookies (e.g. for analytics/statistics): These are only set if you give your consent via the cookie/consent banner. Legal basis: Article 6(1)(a) GDPR, Section 25(1) TDDDG.
You can withdraw or adjust your consent at any time for the future via the cookie/consent banner.
10.2 Web analytics (e.g. Google Analytics, Yandex Metrica, Bing)
We may use web analytics tools to statistically evaluate usage behaviour on our website and to improve our offering. These services are only activated if you have expressly consented via the cookie/consent banner. The legal basis is your consent in accordance with Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future via the cookie/consent banner.
Google Analytics The service provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies and similar technologies to analyse the use of our website. The information collected may generally be transmitted to and stored on Google servers; processing in the USA cannot be excluded. Insofar as personal data is transferred to the USA in this context, such transfer is based on the EU–US Data Privacy Framework and the related adequacy decision of the European Commission dated 10 July 2023. We have also ensured that Google complies with the data protection principles of the Data Privacy Framework.
Yandex Metrica The service provider is Yandex LLC, 16 Lva Tolstogo St., Moscow, 119021, Russia. To comply with GDPR requirements, Yandex has an EU representative:
EU Digital Partners SRL
5 Chilia Veche Street, Building TD 17, 36
061741 Bucharest, Romania
E-mail: team@eudigitalpartners.com
Yandex Metrica may use cookies and process usage data (e.g. IP address, click behaviour) to create anonymous or pseudonymous statistics. Depending on the configuration, this may involve data transfers to third countries. Yandex Metrica is only used if you have expressly consented via the cookie/consent banner.
Other services (e.g. Bing tools/Microsoft) Insofar as we use analytics or marketing services from Microsoft (e.g. Bing webmaster or analytics tools), this is also based solely on your consent. These providers may transfer data to third countries (e.g. USA). If these providers participate in the EU–US Data Privacy Framework, data transfers are based on the relevant adequacy decision of the European Commission; in addition, EU Standard Contractual Clauses are generally used.
11. hCaptcha and fonts
11.1 hCaptcha
To protect our online forms against spam and automated attacks, we use the service hCaptcha.
Service provider: Intuition Machines, Inc. 350 Alabama St, #10 San Francisco, CA 94110 USA
hCaptcha analyses the behaviour of visitors on the website (e.g. IP address, mouse movements, time spent on the page, technical data) in order to distinguish between human users and automated bots. The information collected may be transmitted to hCaptcha’s servers, possibly including servers in the USA.
The use of hCaptcha is based on your consent pursuant to Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG, provided you activate this service in the cookie/consent banner. We use hCaptcha to protect our forms from misuse and automated spying (spam bots). You can withdraw your consent at any time with effect for the future via the cookie/consent banner.
11.2 Fonts (locally hosted)
For a consistent and appealing display of our website, we use fonts that are hosted locally on our server. Fonts are not loaded from third-party servers (e.g. Google). In this context, no personal data is transmitted to external font providers.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in a uniform and user-friendly presentation of the website).
12. Communication via e-mail and messenger services
Our primary and recommended means of communication for contractual matters is encrypted e-mail (where applicable using PGP/GPG) and the use of our secure upload functions on the website.
At the express request of the customer, communication for simple organisational arrangements may also take place via messenger services. In this context, the following is important to us:
Preferred messengers: We recommend privacy-friendly services with end-to-end encryption such as Signal or Threema. Where possible, we prefer to use these services for messenger communication.
Other messengers (e.g. WhatsApp, Telegram): Using services such as WhatsApp (Meta Platforms) or Telegram may involve data protection risks, in particular with respect to possible data transfers to third countries (e.g. USA) and data processing by the respective platform providers. We have no influence over the nature and scope of this data processing and refer to the privacy notices of the respective providers.
Technical measures: For messenger communication, we use separate devices or configurations in which, in particular, automatic synchronisation of private contacts is deactivated in order to avoid uncontrolled transmission of contact data.
We do not routinely use messenger services to request or send particularly sensitive documents (in particular copies of ID documents, civil status documents). For such documents, we explicitly ask you to use secure channels (encrypted e-mail, upload function). If you nevertheless send us sensitive documents via messenger on your own initiative, this is done at your own risk. We will, where possible, promptly transfer such documents to our internal systems and then delete them from the respective messenger.
The legal basis is Article 6(1)(b) GDPR (communication in the context of contract initiation and performance) and, where applicable, Article 6(1)(a) GDPR (consent to the use of a specific messenger service).
13. Storage periods and erasure
We store personal data only for as long as is necessary for the respective purposes or as we are legally required to do so.
- Contract and invoicing data: As a rule, for 10 years after the end of the calendar year in which the contract was terminated (tax and commercial law retention obligations).
- General correspondence (e-mails): As a rule, for up to 1 year after final completion of the matter, unless longer retention periods or interests in legal defence conflict with this.
- Passport copies and particularly sensitive documents: These documents are only required for the duration of the specific assignment. As the delivery of original documents (especially in the case of international shipping) may take different amounts of time and we wish to offer our customers the option of obtaining copies again in the event of delivery problems or enquiries, we generally store such documents for up to 90 days after final completion of the customer’s order and dispatch of all result documents to the customer. These documents are then permanently and irreversibly deleted from our systems. An exception applies only where a statutory retention obligation or an official order (e.g. in connection with suspected criminal offences) expressly requires longer storage.
- Log files (server logs): As a rule, for up to 30 days, unless longer storage is necessary for defending against or tracking attacks.
- Prospective customer data where no contract is concluded: As a rule, for up to 6 months after the last contact, unless other legal bases justify longer storage.
After expiry of the respective periods, the data will be deleted or anonymised, unless there are other legal reasons for further storage.
14. Rights of data subjects
Within the framework of the GDPR, you have the following rights:
- Right of access (Article 15 GDPR)
- Right to rectification (Article 16 GDPR)
- Right to erasure (Article 17 GDPR)
- Right to restriction of processing (Article 18 GDPR)
- Right to data portability (Article 20 GDPR)
- Right to object to certain processing (Article 21 GDPR)
- Right to withdraw consent (Article 7(3) GDPR) with effect for the future
To exercise your rights, you can contact us at any time:
E-mail: ds
apostil-germania.com
We endeavour to respond to your requests within the statutory deadline, usually one month.
15. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data. The competent supervisory authority for our registered office in North Rhine-Westphalia is, for example:
The State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen – LDI NRW)
Contact details can be found on the LDI NRW website.
16. Changes to this Privacy Policy
We reserve the right to amend this Privacy Policy if the legal situation, our data processing or the services we use change. The current version is available on our website at all times.