Privacy Policy — selbstauskunft.de


Privacy policy

As of May 2026

§ 1 Data Controller

NLTS Global Analytics s.r.o.
Malá 43/6, 301 00 Pilsen, Czech Republic
Managing Director: Frank Drescher, MBA
Email: [email protected]
Company Number: 09262024 | Commercial Register: C 39473/KSPL Pilsen | VAT ID: CZ09262024

A data protection officer is not required based on the size of the company, in accordance with Article 37 of the GDPR. For data protection-related inquiries, please contact: [email protected]

§ 2 General Information on Data Processing

We generally process our users’ personal data only to the extent necessary to provide a fully functional website and to deliver our content and services. Processing is typically carried out only with the user’s consent. An exception applies if prior consent is not possible for practical reasons and the processing is permitted by law.

Since this offer is specifically aimed at users in Germany (principle of market location), we comply not only with the GDPR but also with the provisions of the TDDDG, in particular § 25 TDDDG.

The provision of personal data is required in certain areas in order to enter into a contract with us (Section 10). Outside of a contractual relationship, the provision of such data is voluntary. No automated decision-making, including profiling, as defined in Article 22 of the GDPR, takes place that produces legal effects concerning you or similarly significantly affects you.

This website uses SSL/TLS encryption (HTTPS).

§ 3 Server Log Files and Hosting Infrastructure

Technically necessary

Hosting & CDN
Infrastructure, Security, DDoS Protection


Provider
Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA
Data Collected
IP address, date/time, referrer URL, browser, HTTP status code, data volume. IP addresses are anonymized after 24 hours, and logs are deleted after 72 hours.
Purpose
Uninterrupted operation, protection against attacks (DDoS, bots)
Legal basis
Art. 6(1)(f) of the GDPR (legitimate interest)
third country
USA — EU-U.S. Data Privacy Framework (Cloudflare is DPF-certified)

§ 4 Cookies and Consent Management

Our website uses cookies. When you first visit the site, a consent banner will appear, allowing you to accept or decline the use of various categories of cookies. Technically necessary cookies are set without your consent (Section 25(2)(2) of the German Telemedia Act). Analytics and marketing cookies are activated only after you have given your explicit consent.

Technically necessary

Consent Management Platform
Consent Management, Cookie Banner


Provider
Usercentrics A/S (Cookiebot), Havnegade 39, 1058 Copenhagen, Denmark
Data Collected
Date and content of your consent, IP address (anonymized), user agent
Purpose
Legally compliant documentation and management of your consents in accordance with Section 25 of the TDDDG and Article 7 of the GDPR
Legal basis
Art. 6(1)(c) of the GDPR (legal obligation)
third country
Technical CDN resources are delivered via U.S. servers — based on the EU-U.S. DPF
Storage duration
Record of consent: 3 years (legal requirement to retain records)

§ 5 Tag Management and Google Consent Mode v2

We use a tag management system to centrally manage third-party scripts and activate them only after you have given your consent. Before you give your consent, all four Google signals (analytics_storage, ad_storage, ad_user_data, ad_personalization) is set to "denied" by default (Google Consent Mode v2). In this state, Google receives only anonymized signals that do not contain any personally identifiable information.

Technically necessary

Tag Management System
Consent-based script management (no proprietary tracking)


Provider
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Data Collected
No tracking data of its own; additional scripts are loaded only after you give your consent
Purpose
Centralized, consent-based management of analytics and marketing scripts
Legal basis
Art. 6(1)(f) of the GDPR (legitimate interest in centralized tag management)
third country
USA — EU-U.S. DPF (Google is DPF-certified)

§ 6 Web Analytics (only with consent)

Analysis

Web Analytics
Usage statistics — only with consent


Provider
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Product
Google Analytics 4 (GA4)
Data Collected
Page views, time spent on the site, click paths, approximate location (city level), device and browser type, referrer. IP addresses are anonymized before transmission.
Purpose
Analysis of website usage to improve our services
Legal basis
Art. 6(1)(a) of the GDPR in conjunction with § 25(1) of the TDDDG (Consent)
third country
USA — EU-U.S. DPF
Storage duration
User data is automatically deleted after 14 months
Cancellation
At any time via "Cookie Settings" in the footer
Analysis

Session Analysis / Heatmaps
User interactions — only with consent


Provider
Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Product
Microsoft Clarity
Data Collected
Mouse movements, clicks, scroll depth, and anonymized session replay data. Personal information (form fields, passwords) is automatically masked and not recorded.
Purpose
User Experience Analysis to Improve Website Usability
Legal basis
Art. 6(1)(a) of the GDPR in conjunction with § 25(1) of the TDDDG (Consent)
third country
USA — EU-U.S. DPF (Microsoft is DPF-certified)
Storage duration
30 days

§ 7 Remarketing and Conversion Tracking (only with consent)

Marketing

Search Engine Advertising / Remarketing
Google Ads Conversion Tracking — Only with Consent


Provider
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Product
Google Ads / Google DoubleClick
Data Collected
Click ID (gclid), conversion events, pseudonymized device IDs
Purpose
Measuring the effectiveness of ads, remarketing
Legal basis
Art. 6(1)(a) of the GDPR in conjunction with § 25(1) of the TDDDG (Consent)
third country
USA — EU-U.S. DPF
Marketing

Bing Search Engine Advertising
Microsoft Ads Conversion Tracking — Only with Consent


Provider
Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Product
Microsoft Advertising Universal Event Tracking (UET)
Data Collected
Click ID (msclkid), page views, conversion events, pseudonymized user ID (cookie duration: 13 months)
Purpose
Measuring the Effectiveness of Search Engine Advertising on Bing
Legal basis
Art. 6(1)(a) of the GDPR in conjunction with § 25(1) of the TDDDG (Consent)
third country
USA — EU-U.S. DPF

§ 8 Anonymous Audience Measurement

In addition to consent-based web analytics, we use an analytics service to measure reach anonymously. This service does not collect any personal data, does not store IP addresses, and does not perform browser fingerprinting. Only aggregated, non-personally identifiable access data is collected.

Legal basis: Article 6(1)(f) of the GDPR (legitimate interest in anonymous audience measurement); Section 25(2)(2) of the TDDDG.

§ 9 Fonts

Functional

Web fonts
Consistent typographic presentation


Provider
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Product
Google Fonts
Data Collected
IP address, font resource accessed (fonts.googleapis.com)
Purpose
Consistent typographic design of the website
Legal basis
Art. 6(1)(f) of the GDPR (legitimate interest)
third country
USA — EU-U.S. DPF

§ 10 Live Chat and Customer Support

Functional

Live Chat & Support
Direct customer contact via a chat widget


Provider
Help Scout PBC, 177 Huntington Ave, Suite 1703, Boston, MA 02115, USA
Data Collected
Chat message, name and email address (if provided), IP address, browser type, time of the request
Purpose
Efficient customer communication and support handling
Legal basis
Art. 6(1)(f) of the GDPR (legitimate interest) or Art. 6(1)(a) of the GDPR in conjunction with § 25(1) of the TDDDG (consent)
third country
United States — EU Standard Contractual Clauses (SCCs) pursuant to Article 46(2)(c) of the GDPR

§ 11 Automatic Website Translation

Functional

Automatic translation
Multilingual version of the website (EU)


Provider
Weglot SAS, 138 rue Pierre Joigneaux, 92270 Bois-Colombes, France
Data Collected
URL accessed, IP address, browser type, language preference, time of access; language selection cookie
Purpose
Multilingual version of the website
Legal basis
Art. 6(1)(f) of the GDPR; § 25(2)(2) of the TDDDG (language selection cookie is technically necessary)
third country
None — Processing within the EU (France)

§ 12 Data Processing in Connection with the Application

When you use our application form to request a SCHUFA self-disclosure report, the following personal data is collected:

  • Title, first name, and last name
  • Mailing address (street, house number, ZIP code, city)
  • Date of Birth
  • Email address (required)
  • Phone number (optional)
  • Handwritten signature (digital signature)

This data is used exclusively for the purpose of preparing and submitting the request for information in accordance with Article 15 of the GDPR to SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden, as well as for invoicing and sending status notifications.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract)
Retention period: Application data: 30 days after completion of processing. Invoice data: 10 years in accordance with § 147 AO.

12.1 Payment Processing and Billing

We charge a service fee of EUR 29.90 (including 19% VAT) for our services, payable upon receipt of an invoice after the service has been provided.

Billing

Invoice creation and delivery
Performance of the Contract — Processing Within the EU


Provider
Billogram AB, Tulegatan 11, 113 53 Stockholm, Sweden
Data transmitted
Name, email address, invoice amount, service description
Purpose
Invoicing, invoice mailing, accounts receivable
Legal basis
Art. 6(1)(b) of the GDPR (performance of a contract) in conjunction with Art. 6(1)(c) of the GDPR (legal obligation to retain data)
third country
None — Processing within the EU (Sweden)

12.2 Accounts Receivable Management in the Event of Late Payment

In the event of late payment, the data necessary to enforce the claim will be transferred to our collection agency. Data will be transferred only in the event of late payment and only to the extent necessary.

Debt collection (only in the event of default)

Accounts Receivable Management
Out-of-court and in-court debt collection — only in cases of late payment


Provider
ClarioCase GmbH, 49 Pfaffenstraße, 74078 Heilbronn, Germany
Data transmitted
Name, address, email address, amount due, service description, invoice date
Purpose
Out-of-court and in-court collection of outstanding debts
Legal basis
Art. 6(1)(f) of the GDPR (legitimate interest in enforcing legitimate claims); Art. 6(1)(b) of the GDPR (performance of a contract)
third country
None — Processing within the EU (Germany)

§ 13 Email Communication

13.1 Transactional emails (service emails)

As part of the contract processing, we send emails containing confirmations, status updates, and notifications regarding your application. We use an external email service provider based in the United States to send these emails (legal basis: EU-U.S. DPA).

Legal basis: Article 6(1)(b) of the GDPR (performance of a contract)

13.2 Marketing Emails (with Consent)

If you have consented to email communication on the application form, you will occasionally receive information about our services. You can withdraw this consent at any time, for example, by clicking the unsubscribe link in each email. We use a service provider based in the European Union (France) to send our newsletter—no data is transferred to third countries.

Legal basis: Article 6(1)(a) of the GDPR (Consent)

13.3 Communication with Existing Customers

If we have obtained your email address as part of an existing customer relationship, we reserve the right to send you information about similar services via email. You may object to this use at any time without providing a reason.

Legal basis: Section 7(3) of the German Unfair Competition Act (UWG) in conjunction with Article 6(1)(f) of the General Data Protection Regulation (GDPR)

§ 14 Contact Form and Email Contact

When you use our contact form or contact us by email, we collect your name, email address, and the content of your message. This information is used solely to process your inquiry.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures / performance of a contract) or Art. 6(1)(f) GDPR
Retention period: 90 days after final processing

§ 15 Categories of Recipients

We only disclose personal data if it is necessary for the performance of a contract, if there is a legal obligation to do so, or if consent has been obtained. We have contracts in place with all data processors in accordance with Article 28 of the GDPR.

Category Purpose Seat Third-country basis
Hosting & CDN Infrastructure, Security United States EU-U.S. DPF
Tag Management Consent-based script management IE / USA EU-U.S. DPF
Web Analytics Usage Analysis (with consent) IE / USA EU-U.S. DPF
Session Analysis Heat maps, usability (with consent) IE / USA EU-U.S. DPF
Advertising platform (Search) Conversion tracking, remarketing IE / USA EU-U.S. DPF
Advertising platform (Search) Bing Conversion Tracking IE / USA EU-U.S. DPF
Consent Management Consent Management DK (EU)
Translation Service Multilingual display FR (EU)
Customer Support / Chat Live Chat, Ticket System United States SCCs
Email delivery (transactional) Service emails United States EU-U.S. DPF
Email Marketing Newsletter FR (EU)
Web fonts Typographic presentation IE / USA EU-U.S. DPF
Billing Invoicing, Billing and Collection SE (EU)
Debt Collection Debt Collection in the Event of Late Payment DE (EU)
Credit bureau Submission of the application form DE (EU)

§ 16 Transfers to Third Countries

To the extent that we use services from providers based in the United States, data transfers are made on the basis of the EU-U.S. Data Privacy Framework (DPF), provided that the respective provider is DPF-certified. For providers without DPF certification, we use EU Standard Contractual Clauses (SCCs) in accordance with Article 46(2)(c) of the GDPR as the basis for the transfer.

§ 17 Rights of the Data Subject

You have the following rights with respect to your personal data:

  • Right of access (Art. 15 GDPR): You may request information about the data we have stored about you.
  • Right to rectification (Art. 16 GDPR): You may request the rectification of inaccurate data.
  • Right to erasure (Art. 17 GDPR): You may request the erasure of your data, provided there is no legal basis for retaining it.
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR): You may object at any time to processing based on Art. 6(1)(e) or (f) of the GDPR. In the case of direct marketing, you may object without providing a reason.
  • Right to withdraw consent (Art. 7(3) GDPR): You may withdraw your consent at any time with future effect. Any processing carried out prior to the withdrawal remains lawful.

To exercise your rights, please contact: [email protected]

§ 18 Right to File a Complaint with a Supervisory Authority

You have the right to file a complaint with the competent data protection supervisory authority. As a company based in the Czech Republic, our competent supervisory authority is:

Office for Personal Data Protection (ÚOOÚ)
Pplk. Sochora 27
170 00 Prague 7
Czech Republic

In addition, pursuant to Article 77 of the GDPR, you may also contact the supervisory authority in the jurisdiction where you usually reside or work.

§ 19 Current Status of This Privacy Policy

This Privacy Policy is current as of May 2026 and is always available at https://selbstauskunft.de/datenschutz. In the event of significant changes, we will notify you via a prominent notice on our website.