Privacy Policy

1. Introduction

Below, we'll tell you about how we process personal data when you use

  • our website https://upreach.com

  • our social media profiles.

Personal data is any information that can be linked to a specific natural person, like their name or IP address.

1.1. Contact Details

The controller, as per Art. 4 para. 7 of the EU General Data Protection Regulation (GDPR), is UpReach GmbH, Keithstraße 2-4, 10787 Berlin, Germany, Email: mail@upreach.com. We are legally represented by Danny Fandrich.

Our data protection officer is heyData GmbH, Kantstr. 99, 10627 Berlin, www.heydata.eu, Email: datenschutz@heydata.eu.

1.2. Scope of Data Processing,
Purposes of Processing, and
Legal Bases

We'll explain the scope of data processing, its purposes, and legal bases in detail below. Generally, the following can be considered as legal bases for data processing:

  • Art. 6 para. 1 sentence 1 lit. a GDPR serves as our legal basis for processing operations for which we obtain consent.

  • Art. 6 para. 1 sentence 1 lit. b GDPR is the legal basis when processing personal data is necessary for fulfilling a contract, e.g., when a website visitor buys a product from us or we perform a service for them. This legal basis also applies to processing needed for pre-contractual measures, such as inquiries about our products or services.

  • Art. 6 para. 1 sentence 1 lit. c GDPR applies when we process personal data to fulfill a legal obligation, as may be the case in tax law, for example.

  • Art. 6 para. 1 sentence 1 lit. f GDPR serves as a legal basis when we can rely on legitimate interests for processing personal data, e.g., for cookies that are necessary for the technical operation of our website.

1.3. Data Processing Outside
the EEA

When we share your data with service providers or other third parties outside the EEA, we make sure it's safe. This is usually covered by EU Commission adequacy decisions (Art. 45 Para. 3 GDPR) if they exist for that country (like the UK, Canada, and Israel).

If there's no adequacy decision (like for the USA), we typically rely on standard contractual clauses for data transfers, unless we tell you otherwise. These are rules approved by the EU Commission and are part of our agreement with that third party. They help keep your data safe during transfers, as per Art. 46 Para. 2 lit. b GDPR. Many providers even offer extra contractual guarantees beyond these standard clauses to protect your data even more. This could include things like data encryption or a promise from the third party to tell you if law enforcement wants to access your data.

1.4. How long we keep your data

Unless we say otherwise in this privacy policy, we delete the data we store as soon as it's no longer needed for its original purpose and there are no legal reasons to keep it. If we can't delete data because we need it for other legally allowed reasons, we'll restrict its processing. This means the data will be blocked and not used for anything else. For example, this applies to data we have to keep for business or tax reasons.

1.5. Your Rights

You have the following rights regarding your personal data with us:

  • The right to know what data we have,

  • The right to correct or delete your data,

  • The right to limit how we process your data,

  • The right to object to us processing your data,

  • The right to data portability (to get your data in a usable format),

  • The right to withdraw any consent you've given at any time.

You also have the right to complain to a data protection supervisory authority about how we process your personal data. You can find the contact details for these authorities at https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html.

1.6. When you need to provide
data

Customers, interested parties, or other third parties only need to give us the personal data that's essential for starting, managing, and ending a business or other relationship, or if we're legally required to collect it. If we don't have this data, we usually won't be able to enter into a contract, provide a service, or continue an existing agreement or relationship.

Required information is clearly marked.

1.7. No automatic
decisions made
about you

When we start or manage a business or other relationship, we generally don't use fully automated decision-making as per Article 22 GDPR. If we ever do use these methods in specific cases, we'll let you know separately, especially if the law requires it.

1.8. Contacting Us

When you get in touch with us, like by email or phone, we'll store the info you give us (such as your name and email address) to answer your questions. We do this based on our legitimate interest (Art. 6 Para. 1 S. 1 lit. f GDPR) to respond to your inquiries. We'll delete this data once we no longer need to keep it, or we'll restrict its processing if there are legal reasons to hold onto it.

1.9. Customer Surveys

Every now and then, we run customer surveys to get a better understanding of you and what you're looking for. We collect the data asked for in each survey. It's in our legitimate interest to learn more about our customers and their needs, so the legal basis for processing this data is Art. 6 Para. 1 S. 1 lit f GDPR. We delete the data once we've analyzed the survey results.

2. Newsletter

We might occasionally send emails or other electronic messages about our offers to customers who have already used our services or bought something from us, as long as they haven't said no to it. The legal reason for this data processing is Art. 6 Para. 1 S. 1 lit. f GDPR. Our legitimate interest here is direct marketing (Recital 47 GDPR). You can object to us using your email for advertising at any time, for free, by clicking the link at the bottom of any email or by sending an email to our address mentioned above.

If you're interested, you can sign up for our free newsletter. We only use the data you provide when signing up to send you the newsletter. You can sign up by selecting the right box on our website, ticking a box on a paper form, or by another clear action that shows you agree to us processing your data. This means the legal basis is Art. 6 Para. 1 S. 1 lit. a GDPR. You can withdraw your consent at any time, for example, by clicking the unsubscribe link in the newsletter or by letting us know at the email address above. Even if you withdraw your consent, any data processing that happened before that point is still considered lawful.

With your consent (Art. 6 para. 1 sentence 1 lit. a GDPR), we also track the open and click rates of our newsletters. This helps us figure out what content is most interesting to you.

We use HubSpot, a tool from HubSpot, Inc., 25 1st Street Cambridge, MA 0214, USA, to send our newsletters (you can find their Privacy Policy here: https://legal.hubspot.com/de/privacy-policy). HubSpot handles content, usage, meta/communication, and contact data within the EU.

3. How We Handle Data on
Our Website

3.1. Just Browsing Our Website

When you're just browsing our website and not actively sending us any info, we collect personal data that your browser sends to our server. This helps us keep our website stable and secure. It's in our legitimate interest to do so, which means the legal basis for this is Art. 6 para. 1 sentence 1 lit. f GDPR.

Here's what we collect:

  • IP address

  • Date and time of the request

  • Time zone difference to Greenwich Mean Time (GMT)

  • Content of the request (specific page)

  • Access status/HTTP status code

  • The amount of data transferred each time

  • The website you came from

  • Browser

  • Your operating system and its interface

  • The language and version of your browser software.

We also save this data in log files. We'll delete it once it's no longer needed, and definitely within 14 days.

3.2. Web Hosting and
How We Provide the Website

Our website is hosted by Webflow, Inc., 398 11th St., Floor 2, San Francisco, CA 94103, USA. They handle personal data sent through the website, like content, usage, meta/communication data, or contact details, in the USA. You can check out their privacy policy for more info here: https://webflow.com/legal/eu-privacy-policy.

It's in our legitimate interest to offer you a website, so the legal basis for how we process data here is Art. 6 para. 1 sentence 1 lit. f GDPR.

We use standard contractual clauses as the legal basis for sending data to countries outside the EEA. The safety of your data when it goes to a third country (meaning outside the EEA) is protected by standard data protection clauses. These clauses were put in place following the review process under Art. 93 para. 2 GDPR (Art. 46 para. 2 lit. c GDPR), and we've agreed to them with our provider.

3.3. Contact Form

If you reach out to us using the contact form on our website, we'll save the info you provide and the content of your message.
We process this data because we have a legitimate interest in responding to your questions. So, the legal basis for this processing is Art. 6 para. 1 sentence 1 lit. f GDPR.
We'll delete this data once we don't need to store it anymore, or we'll limit its processing if legal retention periods apply.

3.4. Job Openings

We list job openings for our company on our website, on linked pages, or on other third-party sites.
We process the data you provide when you apply to help us with the application process. If this info is needed for us to decide about hiring you, the legal basis is Art. 88 para. 1 GDPR in combination with § 26 para. 1 BDSG. We've marked or pointed out the data that's essential for your application. If you don't provide this data, we won't be able to process your application.
Any other data you provide is optional and not required for applying. If you choose to share more info, it's based on your consent (Art. 6 para. 1 sentence 1 lit. a GDPR).

We kindly ask applicants to avoid including political opinions, religious views, or similar sensitive data in their CVs and cover letters. These aren't needed for your application. If you still choose to provide such information, we can't stop it from being processed as part of your CV or cover letter. In that case, its processing is based on your consent (Art. 9 Para. 2 lit. a GDPR).

Also, we process applicant data for other application processes if they've given us their consent to do so. In this situation, the legal basis is Art. 6 Para. 1 S. 1 lit. a GDPR.

We share applicant data with the relevant HR staff, our processors for recruiting, and other employees involved in the application process.

If we hire an applicant after the application process, we only delete their data once their employment ends. Otherwise, we delete the data within six months of an applicant being rejected.

If applicants have given us their consent to use their data for other application processes, we'll delete their data one year after receiving their application.

3.5. Offering Goods and

Services

We offer goods and services through our website. When you place an order, we process the following data:

  • Company

  • Phone

  • Email address

We process this data to fulfill the contract made with each website visitor (Art. 6 Para. 1 S. 1 lit. b GDPR).

We share the mentioned data with messenger Transport + Logistik GmbH, Martin-Luther-Str. 7, 10777 Berlin, as far as it's needed for your order.

The legal basis for processing is Art. 6 Para. 1 S. 1 lit. b GDPR, as it's necessary to fulfill the contract.

3.6. Payment Service Providers

To handle payments, we use Stripe Payments Europe, Ltd., Ireland, who are themselves data controllers as per Art. 4 No. 7 GDPR. When they receive data and payment info entered by us during the order process, we're fulfilling the contract we have with our customers (Art. 6 Para. 1 S. 1 lit. b GDPR).

3.7. Third-Party Providers

3.7.1. HubSpot

We use HubSpot for managing customer relationships. The provider is HubSpot, Inc., 25 1st Street Cambridge, MA 0214, USA. They process usage data (like visited web pages, content interest, access times), content data (like entries in online forms), and meta/communication data (like device info, IP addresses) within the EU.

The legal basis for processing is Art. 6 Para. 1 S. 1 lit. f GDPR. We have a legitimate interest in managing data in a simple and cost-effective way.

Data is deleted when the reason for its collection is gone and there are no retention obligations. You can find more info in the provider's privacy policy here.

3.7.2. Webflow

We use Webflow to create websites. The provider is Webflow, Inc., 398 11th St., Floor 2, San Francisco, CA 94103, USA. They process usage data (like visited web pages, content interest, access times) and meta/communication data (like device info, IP addresses) in the USA.

The legal basis for processing is Art. 6 Para. 1 S. 1 lit. f GDPR. We have a legitimate interest in setting up and maintaining a website to present ourselves to the public.

We use standard contractual clauses as the legal basis for sending data to countries outside the EEA. The safety of your data when it goes to a third country (meaning outside the EEA) is protected by standard data protection clauses. These clauses were put in place following the review process under Art. 93 para. 2 GDPR (Art. 46 para. 2 lit. c GDPR), and we've agreed to them with our provider.

We delete data when the reason for its collection is gone. You can find more info in the provider's privacy policy here.

3.7.3. Google Analytics

We use Google Analytics for analysis. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Dublin, Ireland. They process usage data (like pages you've visited, content you're interested in, and access times) and meta/communication data (like device info and IP addresses) in the USA.

The legal basis for this processing is Art. 6 para. 1 sentence 1 lit. a GDPR. We process this data based on your consent. You can withdraw your consent at any time, for example, by contacting us using the details in our privacy policy. Withdrawing your consent doesn't affect the legality of any processing done before you withdrew it.

We use standard contractual clauses as the legal basis for sending data to countries outside the EEA. The safety of your data when it goes to a third country (meaning outside the EEA) is protected by standard data protection clauses. These clauses were put in place following the review process under Art. 93 para. 2 GDPR (Art. 46 para. 2 lit. c GDPR), and we've agreed to them with our provider.

Your data will be deleted once the reason for collecting it is no longer valid and there are no retention obligations. You can find more info in the provider's privacy policy here.

3.7.4. Microsoft Clarity‍

We use Microsoft Clarity to identify business potential and for analysis. This service is provided by Microsoft Ireland Operations, Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland. It processes user data like pages visited, areas of interest, access times, and meta/communication data such as device info and IP addresses within the EU.

This data processing is based on Art. 6 para. 1 sentence 1 lit. a GDPR and happens with your consent. You can withdraw this consent at any time, for example, by contacting us using the methods listed in our privacy policy. Withdrawing your consent doesn't affect the legality of any processing done before you withdrew it.

Your data will be deleted as soon as the purpose for collecting it is no longer valid and there are no legal retention periods preventing it. You can find more info in the provider's privacy policy here.

3.7.5. ​Weglot

To give our users a multilingual experience on our website, we've integrated the Weglot translation service. This service is provided by Weglot SAS, located at 138, rue Pierre Joigneaux, Bois-Colombes 92270, France. When you visit our website, Weglot activates, letting you adjust language settings using the language selection icon in our header. This creates a direct connection between your browser and the Weglot server. As a result, Weglot receives information like your IP address, which is needed to provide the translation service.

Weglot's data storage and analysis are based on Art. 6 para. 1 sentence 1 lit. f GDPR. We have a legitimate interest in providing our users with a user-friendly multilingual website. Plus, personal data is processed based on your consent, as per Art. 6 para. 1 sentence 1 lit. a GDPR, which we get through our website's cookie and privacy settings. You can withdraw this consent at any time via the privacy settings on any subpage of our website.

Your data is processed according to GDPR provisions and deleted as soon as the purpose for collecting it is no longer valid and there are no legal retention obligations. You can find more info in the provider's privacy policy here.


3.7.6. Tawk.to

On our website, we use Tawk.to, a live chat service provided by SMS SIA, located at Tirgonu iela 6, Riga, LV1050, Latvia. This service becomes active through a script integrated into our website's source code. While you're using the chat, we collect information like the chat history, your IP address at the time of the chat, and your country. This info is used only for security purposes and internal statistical analysis and isn't shared with third parties.

Tawk.to's processing of this data is based on Art. 6 para. 1 sentence 1 lit. f GDPR, justified by our interest in efficient and effective communication with our customers. Data storage is limited to the duration of the chat, after which it's immediately deleted. By actively using the live chat on our website, you're giving your consent to data processing, which you can withdraw at any time by contacting us using the methods listed in our privacy policy.

It's possible that Tawk.to transfers data to the USA. To keep your data safe, we've signed a data processing agreement with Tawk.to. This ensures they process our visitors' personal data only as we instruct and in line with the GDPR. The transfer of data to the USA relies on the Standard Contractual Clauses provided by the EU Commission. You can find more info in the provider's privacy policy here.

4. Data Processing on
Social Media Platforms

We're on social media networks to showcase our company and services there. The operators of these networks regularly process their users' data for advertising. Among other things, they create user profiles from your online behavior, which are then used, for example, to show ads on the network pages and elsewhere on the internet that match your interests. For this, the network operators store information about your usage behavior in cookies on your computer. It's also possible that the operators combine this information with other data. You can find more information and tips on how to object to processing by the site operators in the privacy policies of the respective operators listed below. It's also possible that the operators or their servers are located in non-EU countries, meaning they process data there. This could create risks for users, for example, because enforcing their rights might be harder or government agencies could access the data.

When network users contact us through our profiles, we process the data they provide to answer their inquiries. This is our legitimate interest, so the legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR.

4.1. Facebook

We have a profile on Facebook. The operator is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. You can find their privacy policy here: https://www.facebook.com/policy.php. You can object to data processing via ad settings: https://www.facebook.com/settings?tab=ads.
Based on an agreement, we are jointly responsible with Facebook, as per Art. 26 GDPR, for processing the data of our profile's visitors. Facebook explains exactly what data is processed at https://www.facebook.com/legal/terms/information_about_page_insights_data. Those affected can exercise their rights with both us and Facebook. However, according to our agreement with Facebook, we are obliged to forward inquiries to Facebook. So, those affected will get a quicker response if they contact Facebook directly.

4.2. Instagram

We have a profile on Instagram. The operator is Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. You can find their privacy policy here: https://help.instagram.com/519522125107875.

4.3. Twitter

We have a profile on Twitter. The operator is Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. You can find their privacy policy here: https://twitter.com/de/privacy. You can object to data processing via ad settings: https://twitter.com/personalization.

4.4. LinkedIn

We have a profile on LinkedIn. It's operated by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. You can find their privacy policy here: https://https://www.linkedin.com/legal/privacy-policy?_l=de_DE. If you want to object to data processing, you can do so through your ad settings here: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

4.5. Xing

We also have a profile on Xing. It's operated by New Work SE, Dammtorstraße 29-32, 20354 Hamburg. You can check out their privacy policy here: https://privacy.xing.com/de/datenschutzerklaerung.

5. Changes to This Privacy Policy

We reserve the right to change this privacy policy in the future. You'll always find the latest version available here.

6. Questions and Comments

If you have any questions or comments about this privacy policy, feel free to reach out to us using the contact details provided above.

Privacy Policy

1. Introduction

This Privacy Policy explains how UpReach, a brand of UpReach GmbH, collects and uses the information we gather when you visit https://www.upreach.com/. It also outlines your privacy rights and how data protection laws keep you safe.

By using our service, you agree to us collecting and using your data according to this Privacy Policy. Please don't access or use our service if you're not okay with your data being collected and used as explained here.

This Privacy Policy was created with the help of the CookieScript Privacy Policy Generator.

UpReach GmbH can update this Privacy Policy at any time, and they might do so without prior notice.

UpReach GmbH will post the updated Privacy Policy on their website, https://www.upreach.com/.

Collecting and Using Your Personal Data

What Kind of Data We Collect

When you use our service, we'll ask you to share some personal data so we can contact or identify you.

https://www.upreach.com/ collects the following information:

  • Usage Data

  • Name

  • Email

  • Mobile Phone

Usage data includes the following:

  • Internet Protocol (IP) address of the computers accessing the website

  • Website requests

  • Referring websites

  • Browser used to access the website

  • Time and date of access

How we collect data

https://www.upreach.com/
sammelt und erhält Daten von Ihnen auf folgende Weise:

  • When you fill out a registration form or otherwise submit your personal data.

Your data is stored for up to 30 days after your account is canceled. Your data might be kept for longer periods to create reports or records, as allowed by applicable laws. Data that doesn't personally identify you can be stored indefinitely.

What we use your data for

https://www.upreach.com/
kann Ihre Daten für die folgenden Zwecke verwenden:

  • Providing and maintaining our service, and monitoring how our service is used.

  • To get in touch with you.
    UpReach GmbH might contact you via email, phone, SMS, or other electronic communication regarding features, products, services, or security updates when necessary or appropriate.

How we use your data

UpReach GmbH might share your data in these situations:

  • With your consent.
    UpReach GmbH will only share your data for any purpose with your explicit permission.

Third-party sharing

Your data might be shared for other reasons,
such as:

  • Complying with applicable laws, regulations, or court orders.

  • Responding to claims that your use of our service violates the rights of third parties.

  • Enforcing agreements you've made with us, including this Privacy Policy.

Cookies

Cookies are small text files stored on your computer by websites you visit. Websites use cookies to help users navigate efficiently and perform certain functions. Cookies essential for the website to work properly can be set without your consent. All other cookies need your approval before they can be set in your browser.

  • Strictly Necessary Cookies. Strictly necessary cookies enable essential core website functions like user login and account management. Without these cookies, the website can't be used properly.

  • Performance Cookies. Performance cookies collect information about how visitors use a website, like analytics cookies. These cookies can't be used to directly identify a specific visitor.

  • Targeting Cookies. Targeting cookies are used to identify visitors across different websites, such as content partners or banner networks. Companies might use these cookies to build a profile of visitor interests or show relevant ads on other websites.

You can change your cookie consent below.

Security

The security of your data is important to us. https://www.upreach.com/ uses various security measures to prevent misuse, loss, or alteration of the data you provide. However, since we can't guarantee the security of the data you provide, accessing our service is at your own risk.

UpReach GmbH isn't responsible for the performance of websites operated by third parties or for your interactions with them. If you leave this website, we recommend checking the privacy practices of other websites you interact with and determining if those practices are appropriate.

Contact

If you have any questions, please contact us using one of the following channels:

Name: UpReach GmbH

Address: Keithstraße 2-4, 10787 Berlin

Email: mail@upreach.com

Website: https://www.upreach.com/

Phone: +4930994048401

If you have any questions or concerns about how your data is handled, feel free to contact our data protection officer at HeyData GmbH, datenschutz@heydata.eu anytime.