Skip to main content

PRIVACY · TRANSPARENCY

What we do with your data — and what we don't.

This page explains every data flow on ruetech.com under GDPR: what we process, why, where your data goes and how long we retain it. Concrete throughout – no wall-of-text, no escape hatches.

★Hosted in Germany
★No ad networks, no cross-site tracking
★We do not sell data
★Last updated: 30 April 2026

PRIVACY AT A GLANCE

The short version – before you dive into the detail

WHAT WE DO

  • ✓TLS encryption on every connection (HTTPS, HSTS preload)
  • ✓EU-based email delivery (Resend, eu-west-1)
  • ✓Data Processing Agreements (DPAs) with every subprocessor
  • ✓We delete data on request – without exceptions

WHAT WE DON'T DO

  • ✗Sell data to third parties
  • ✗Advertising tracking (no Facebook Pixel, no Google Ads tracking)
  • ✗Build profiles based on your behaviour
  • ✗Automated decisions with legal effect

Direct data-protection contact

Privacy questions are answered by Faissal Bibelghach personally – [email protected]. Response within one business day.

§ 1 · ART. 4 (7) GDPR

Data Controller

Responsible for processing your personal data on this website:

Ruetech GmbH

Kaiser-Joseph-Str. 254
79098 Freiburg im Breisgau
Deutschland

Managing Director: Faissal Bibelghach
Phone: +49 170 3058441
Email: [email protected]

Data Protection Officer: We are currently not obliged to appoint a Data Protection Officer under Art. 37 GDPR. Privacy requests are answered personally by the Managing Director.

§ 2 · WHAT WE PROCESS

Every data flow, individually and honestly

Rather than one long list, we explain each data flow separately: what happens, why, on what legal basis, how long we keep the data and who sees it.

2.1 Server logs (technically required)

When you access our website, your browser automatically transmits technical data to our server: IP address, date and time, requested URL, referer, user agent, transferred data volume, HTTP status code. This data is stored in a log file for a maximum of 14 days.

Legal basis
Art. 6 (1) f GDPR
Retention
14 days
Recipients
Hosting provider (DE)
Third country
no

2.2 Cookies

We use exclusively technically required cookies – specifically: a NEXT_LOCALE cookie to remember your language choice (1 year) and possibly session cookies during active use. We use no tracking or marketing cookies. The legal basis is § 25 (2) Nr. 2 TDDDG (German Digital Services Privacy Act, successor to TTDSG) – no consent is required for these cookies.

2.3 Calendly (scheduling, third-country tool)

When you book a meeting via calendly.com/ruetech/30min, the booking runs through Calendly LLC (271 17th Street NW, Suite 1000, Atlanta, GA 30363, USA). This requires transmitting your name, email address and preferred time to Calendly. The transmission only takes place when you actively open the Calendly link or submit a form. We do not load Calendly automatically in the background.

Legal basis
Art. 6 (1) b GDPR
Provider location
USA
Third country
yes (USA)
Safeguards
SCC · DPF

Calendly privacy policy →

2.4 Resend (email delivery, EU)

Transactional email delivery (contact-form confirmations, newsletter, booking confirmations) runs through Resend (provider: Resend, Inc., 2261 Market Street #4667, San Francisco, CA 94114, USA). Our delivery infrastructure runs in the EU region eu-west-1 (Ireland); the ruetech.com domain is verified with SPF and DKIM. The data transmitted is what is required for delivery: recipient email, email content, delivery status.

Legal basis
Art. 6 (1) b/f GDPR
Processing region
EU (eu-west-1)
Third country
HQ USA
Safeguards
AVV · SCC

2.5 Contact form and email enquiries

When you use our contact form or write us an email, we process the data submitted (name, email address, phone number if provided, content of the enquiry) to handle your request and for any follow-up. We do not pass it to third parties – except our processors (email delivery via Resend). We retain your enquiry for at most three years, unless a contractual or statutory retention obligation overrides this.

Legal basis
Art. 6 (1) b/f GDPR
Retention
max. 3 years
Recipients
Resend
Third country
no

2.6 Newsletter

If you subscribe to our newsletter, we process your email address for sending the newsletter on the basis of your consent (double opt-in). The email address is stored in a SQLite database that resides exclusively on our German servers. You can unsubscribe any time via the link in every email or by writing to [email protected].

Legal basis
Art. 6 (1) a GDPR
Retention
until withdrawn
Recipients
Resend (EU)
Third country
no

2.7 Voice messages (transcription)

In the contact form you can record your request as a voice message instead of typing it. Recording starts only when you click “Record” and your browser allows access to the microphone. The sole purpose is converting your voice message into text: the audio file is sent to our processor Mistral AI SAS (Paris, France). From the text, Mistral AI also reads details such as company size or current system so we can suggest them in the form for you to check. We store the audio file neither on our server nor in our database; it is deleted after transcription. Only the text you submit with the form – edited or not – is stored. You can withdraw your consent at any time with effect for the future.

Legal basis
Art. 6 (1) a GDPR
Retention
Audio: not stored by us
Recipients
Mistral AI (EU)
Third country
no

2.8 WhatsApp

On the contact page and in the mobile contact bar we link to WhatsApp, a messenger operated by WhatsApp Ireland Limited (Dublin, Ireland), a Meta group company. WhatsApp is not embedded: no data is sent to WhatsApp or Meta when you visit our pages. Only when you click the link does WhatsApp open with a prefilled message that you can change before sending. WhatsApp's privacy policy applies to your use of WhatsApp; a transfer of data to the USA cannot be ruled out. We process messages you send us via WhatsApp to handle your request.

Legal basis
Art. 6 (1) b/f GDPR
Embedding
none, link only
Provider
WhatsApp Ireland (Meta)
Third country
possible (USA)

§ 3 · ART. 28 GDPR

Subprocessors at a glance

A Data Processing Agreement (DPA) under Art. 28 GDPR is in place with every one of these providers. We share data only when strictly necessary for the respective function.

ProviderPurposeRegionThird country
Resend, Inc.Email deliveryEU (eu-west-1)HQ USA · DPA/SCC
Mistral AI SASVoice message transcriptionEU (France)no
Calendly LLCSchedulingUSAyes · SCC/DPF
Hosting partnerServer operationsGermanyno

We provide the complete subprocessor list on request – just write to [email protected].

§ 4 · ART. 15–22 GDPR

Your rights – and how to exercise them

You have the following rights against us as the controller of your personal data:

Right to information

Art. 15 GDPR

You can find out at any time which data we process about you.

Right to rectification

Art. 16 GDPR

We will correct any inaccurate or incomplete data on your request.

Right to erasure

Art. 17 GDPR

"Right to be forgotten" – we delete unless statutory retention applies.

Right to restriction

Art. 18 GDPR

You can block processing during clarification.

Right to data portability

Art. 20 GDPR

We provide your data in a machine-readable format to you or another controller.

Right to object

Art. 21 GDPR

You can object to processing based on legitimate interests at any time.

Withdraw consent

Art. 7 (3) GDPR

Consents (e.g. newsletter) can be withdrawn for the future at any time.

Complain to supervisory authority

Art. 77 GDPR

You can lodge a complaint with the LfDI Baden-Württemberg any time.

HOW TO EXERCISE YOUR RIGHTS

Send an informal email to [email protected]. We respond within one month of receipt under Art. 12 (3) GDPR – usually significantly faster. No fees apply.

Competent Supervisory Authority

As Ruetech GmbH is headquartered in Freiburg im Breisgau (Baden-Württemberg), the following authority is competent:

State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI)

Postfach 10 29 32
70025 Stuttgart
Phone: +49 711 615541-0
Email: [email protected]

LfDI note: Before lodging a complaint you should first exercise your rights directly with us. The complaint path is meaningful only if we ignore or insufficiently address your request.

Changes to this privacy policy

We update this privacy policy when legal requirements, subprocessors, or processing purposes change. The current revision date is shown at the top of this page.

Last substantive update: 30 April 2026

STILL HAVE QUESTIONS?

Privacy is not a hurdle – it is a trust signal.

If you have questions about this policy, our subprocessors, or how your data is handled in a specific project – write to us.