PRIVACY · TRANSPARENCY
What we do with your data — and what we don't.
This page explains every data flow on ruetech.com under GDPR: what we process, why, where your data goes and how long we retain it. Concrete throughout – no wall-of-text, no escape hatches.
PRIVACY AT A GLANCE
The short version – before you dive into the detail
WHAT WE DO
- ✓TLS encryption on every connection (HTTPS, HSTS preload)
- ✓EU-based email delivery (Resend, eu-west-1)
- ✓Data Processing Agreements (DPAs) with every subprocessor
- ✓We delete data on request – without exceptions
WHAT WE DON'T DO
- ✗Sell data to third parties
- ✗Advertising tracking (no Facebook Pixel, no Google Ads tracking)
- ✗Build profiles based on your behaviour
- ✗Automated decisions with legal effect
Direct data-protection contact
Privacy questions are answered by Faissal Bibelghach personally – [email protected]. Response within one business day.
§ 1 · ART. 4 (7) GDPR
Data Controller
Responsible for processing your personal data on this website:
Ruetech GmbH
Kaiser-Joseph-Str. 254
79098 Freiburg im Breisgau
Deutschland
Managing Director: Faissal Bibelghach
Phone: +49 170 3058441
Email: [email protected]
Data Protection Officer: We are currently not obliged to appoint a Data Protection Officer under Art. 37 GDPR. Privacy requests are answered personally by the Managing Director.
§ 2 · WHAT WE PROCESS
Every data flow, individually and honestly
Rather than one long list, we explain each data flow separately: what happens, why, on what legal basis, how long we keep the data and who sees it.
2.1 Server logs (technically required)
When you access our website, your browser automatically transmits technical data to our server: IP address, date and time, requested URL, referer, user agent, transferred data volume, HTTP status code. This data is stored in a log file for a maximum of 14 days.
- Legal basis
- Art. 6 (1) f GDPR
- Retention
- 14 days
- Recipients
- Hosting provider (DE)
- Third country
- no
2.2 Cookies
We use exclusively technically required cookies – specifically: a NEXT_LOCALE cookie to remember your language choice (1 year) and possibly session cookies during active use. We use no tracking or marketing cookies. The legal basis is § 25 (2) Nr. 2 TDDDG (German Digital Services Privacy Act, successor to TTDSG) – no consent is required for these cookies.
2.3 Calendly (scheduling, third-country tool)
When you book a meeting via calendly.com/ruetech/30min, the booking runs through Calendly LLC (271 17th Street NW, Suite 1000, Atlanta, GA 30363, USA). This requires transmitting your name, email address and preferred time to Calendly. The transmission only takes place when you actively open the Calendly link or submit a form. We do not load Calendly automatically in the background.
- Legal basis
- Art. 6 (1) b GDPR
- Provider location
- USA
- Third country
- yes (USA)
- Safeguards
- SCC · DPF
2.4 Resend (email delivery, EU)
Transactional email delivery (contact-form confirmations, newsletter, booking confirmations) runs through Resend (provider: Resend, Inc., 2261 Market Street #4667, San Francisco, CA 94114, USA). Our delivery infrastructure runs in the EU region eu-west-1 (Ireland); the ruetech.com domain is verified with SPF and DKIM. The data transmitted is what is required for delivery: recipient email, email content, delivery status.
- Legal basis
- Art. 6 (1) b/f GDPR
- Processing region
- EU (eu-west-1)
- Third country
- HQ USA
- Safeguards
- AVV · SCC
2.5 Contact form and email enquiries
When you use our contact form or write us an email, we process the data submitted (name, email address, phone number if provided, content of the enquiry) to handle your request and for any follow-up. We do not pass it to third parties – except our processors (email delivery via Resend). We retain your enquiry for at most three years, unless a contractual or statutory retention obligation overrides this.
- Legal basis
- Art. 6 (1) b/f GDPR
- Retention
- max. 3 years
- Recipients
- Resend
- Third country
- no
2.6 Newsletter
If you subscribe to our newsletter, we process your email address for sending the newsletter on the basis of your consent (double opt-in). The email address is stored in a SQLite database that resides exclusively on our German servers. You can unsubscribe any time via the link in every email or by writing to [email protected].
- Legal basis
- Art. 6 (1) a GDPR
- Retention
- until withdrawn
- Recipients
- Resend (EU)
- Third country
- no
2.7 Voice messages (transcription)
In the contact form you can record your request as a voice message instead of typing it. Recording starts only when you click “Record” and your browser allows access to the microphone. The sole purpose is converting your voice message into text: the audio file is sent to our processor Mistral AI SAS (Paris, France). From the text, Mistral AI also reads details such as company size or current system so we can suggest them in the form for you to check. We store the audio file neither on our server nor in our database; it is deleted after transcription. Only the text you submit with the form – edited or not – is stored. You can withdraw your consent at any time with effect for the future.
- Legal basis
- Art. 6 (1) a GDPR
- Retention
- Audio: not stored by us
- Recipients
- Mistral AI (EU)
- Third country
- no
2.8 WhatsApp
On the contact page and in the mobile contact bar we link to WhatsApp, a messenger operated by WhatsApp Ireland Limited (Dublin, Ireland), a Meta group company. WhatsApp is not embedded: no data is sent to WhatsApp or Meta when you visit our pages. Only when you click the link does WhatsApp open with a prefilled message that you can change before sending. WhatsApp's privacy policy applies to your use of WhatsApp; a transfer of data to the USA cannot be ruled out. We process messages you send us via WhatsApp to handle your request.
- Legal basis
- Art. 6 (1) b/f GDPR
- Embedding
- none, link only
- Provider
- WhatsApp Ireland (Meta)
- Third country
- possible (USA)
§ 3 · ART. 28 GDPR
Subprocessors at a glance
A Data Processing Agreement (DPA) under Art. 28 GDPR is in place with every one of these providers. We share data only when strictly necessary for the respective function.
| Provider | Purpose | Region | Third country |
|---|---|---|---|
| Resend, Inc. | Email delivery | EU (eu-west-1) | HQ USA · DPA/SCC |
| Mistral AI SAS | Voice message transcription | EU (France) | no |
| Calendly LLC | Scheduling | USA | yes · SCC/DPF |
| Hosting partner | Server operations | Germany | no |
We provide the complete subprocessor list on request – just write to [email protected].
§ 4 · ART. 15–22 GDPR
Your rights – and how to exercise them
You have the following rights against us as the controller of your personal data:
Right to information
Art. 15 GDPR
You can find out at any time which data we process about you.
Right to rectification
Art. 16 GDPR
We will correct any inaccurate or incomplete data on your request.
Right to erasure
Art. 17 GDPR
"Right to be forgotten" – we delete unless statutory retention applies.
Right to restriction
Art. 18 GDPR
You can block processing during clarification.
Right to data portability
Art. 20 GDPR
We provide your data in a machine-readable format to you or another controller.
Right to object
Art. 21 GDPR
You can object to processing based on legitimate interests at any time.
Withdraw consent
Art. 7 (3) GDPR
Consents (e.g. newsletter) can be withdrawn for the future at any time.
Complain to supervisory authority
Art. 77 GDPR
You can lodge a complaint with the LfDI Baden-Württemberg any time.
HOW TO EXERCISE YOUR RIGHTS
Send an informal email to [email protected]. We respond within one month of receipt under Art. 12 (3) GDPR – usually significantly faster. No fees apply.
Competent Supervisory Authority
As Ruetech GmbH is headquartered in Freiburg im Breisgau (Baden-Württemberg), the following authority is competent:
State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI)
Postfach 10 29 32
70025 Stuttgart
Phone: +49 711 615541-0
Email: [email protected]
LfDI note: Before lodging a complaint you should first exercise your rights directly with us. The complaint path is meaningful only if we ignore or insufficiently address your request.
Changes to this privacy policy
We update this privacy policy when legal requirements, subprocessors, or processing purposes change. The current revision date is shown at the top of this page.
Last substantive update: 30 April 2026
STILL HAVE QUESTIONS?
Privacy is not a hurdle – it is a trust signal.
If you have questions about this policy, our subprocessors, or how your data is handled in a specific project – write to us.