Data protection
Data protection declaration / Data protection provisions for TrustFair. De
Status: 27.08.2026
Part 1: Introduction
The protection of personal data is important to us. With this data protection declaration, we inform you which personal data we process on TrustFair.de, for which purposes this is done, on which legal basis the processing takes place, how long data is stored and what rights data subjects have.
TrustFair.de is an evaluation platform. Users can rate companies, services, products, shops, online offers or other business providers. Companies can claim company profiles, manage reviews, respond to reviews, report reviews, and use free or paid features depending on the offer.
This privacy policy applies to all visitors, registered users, rating persons, rating companies, company users, premium customers, contact persons, support requests and other persons whose personal data is processed in connection with TrustFair.de.
Personal data is any information relating to an identified or identifiable natural person. This includes, for example, name, e-mail address, IP address, telephone number, account data, payment data, evaluation content, communication data, proof, contract data or technical usage data.
We only process personal data if there is a legal basis for this. This may be the case in particular if the processing is necessary for the provision of the platform, for the performance of the contract, for the fulfilment of legal obligations, for the protection of legitimate interests or on the basis of consent.
The processing is subject in particular to the General Data Protection Regulation (EU) 2016/679 (GDPR), the Dutch Uitvoeringswet Algemene verordening gegevensbescherming (UAVG) as well as to cookies and comparable accesses to end devices Art. 11.7a of the Dutch Telecommunicatiewet. For electronic direct marketing, art. 11.7 of the Dutch Telecommunicatiewet.
Part 2: Responsible and contact
Responsible for data processing on this platform is:
Scriptfabrik B.V.
Pastoor Jacobsweg 27
6226 VV Maastricht
Netherlands
E-mail: welcome@trustfair.de
Website: https://www.trustfair.de
The controller is the natural or legal person who alone or together with others decides on the purposes and means of processing personal data.
Part 3: Data Protection Officer
A data protection officer is not currently appointed. We regularly check whether, in particular due to the nature, scope or purpose of the processing or due to extensive regular and systematic monitoring of user behavior, an obligation to be named by type. 37 GDPR is created.
Data protection requests can be addressed at any time to the following contact address:
Scriptfabrik B.V.
Pastoor Jacobsweg 27
6226 VV Maastricht
Netherlands
E-mail: welcome@trustfair.de
Part 4: Data protection at a glance
-
Who is affected?
Data processing may affect in particular the following persons:
a) visitors to the website,
b) registered users,
c) persons submitting reviews,
d) people who read or report reviews,
e) companies and their contact persons,
f) enterprise users with a free or paid account,
g) customers or business contacts of companies invited to submit a valuation,
h) persons making support or contact requests,
(i) persons identified in evidence, complaints or test procedures;
j) invoice recipients and payment participants,
k) Receivers of system messages or notifications.
-
What data do we process?
Depending on the use of the platform, in particular the following data can be processed:
a) name,
b) user name or display name,
c) e-mail address,
d) telephone number,
e) address,
f) company name,
g) role or position in the company,
h) account data,
i) login and registration data,
j) rating content,
k) star ratings or scores,
l) company responses,
m) grounds for notification and complaint,
n Evidence such as order numbers, invoices, support tickets or communication history,
o) contract and invoice data,
p) Payment status,
q) IP address,
r) browser and device data,
s) server logfiles,
t) technical safety and test features.
-
Why do we process data?
We process personal data in particular in order to:
a to technically provide TrustFair.de,
b to create and manage user accounts,
c to publish and display reviews,
d to provide company profiles,
e enable companies to manage their profiles,
f to check reviews for authenticity, abuse or infringement of rights,
g) to process reports and complaints,
h prevent fake reviews, spam, manipulation and abuse,
i to answer support requests,
j) to pay for services,
k to fulfill legal obligations,
l to assert our own rights or to defend us against claims,
m) to ensure the security and stability of the platform.
-
Are we passing on data?
Personal data will only be shared if this is necessary and legally permissible.
In particular, recipients may be:
a) hosting provider,
b) IT service providers,
c) e-mail service providers,
d) payment service providers,
e) tax advisors and accounting,
f) Lawyers,
g) authorities and courts,
h) affected users or companies in the context of evaluation, notification or complaint procedures,
i) other service providers, insofar as they are necessary for the operation of the platform.
-
How long do we store data?
We store personal data only as long as it is necessary for the respective purposes or statutory storage obligations exist.
Typical storage periods are:
a) Account data: for the duration of the user account,
b ratings: as long as they are published or there are legitimate reasons for further storage,
c Evidence of assessments: for the duration of the examination and thereafter only as long as it is necessary for documentation or legal defence,
(d) notifications and complaints: for the duration of processing and adequate documentation,
e) contract and invoice data: corresponding to legal storage obligations,
f Server log files: usually up to 30 days, unless longer storage is required to detect security incidents.
-
What rights do data subjects have?
In accordance with the statutory provisions, data subjects have in particular the following rights:
a) Right of access,
b) Right to rectification,
c) right of deletion,
d right to restriction of processing,
the right to data portability;
f) right to object,
g) right to withdraw consent,
h) Right to complain to a data protection supervisory authority.
Part 5: Legal bases of processing
We process personal data in particular on the basis of the following legal bases:
-
Article 6(3) 1 lit. a GDPR
This legal basis applies if consent has been given. This may be the case in particular for unnecessary cookies, analysis functions, marketing measures or newsletters.
-
Article 6(3) 1 lit. b GDPR
This legal basis applies if the processing is necessary for the performance of a contract or for the implementation of pre-contractual measures. This applies in particular to user accounts, corporate accounts, premium functions, support requests with contract reference, payment processing and platform services.
-
Article 6(3) 1 lit. c GDPR
This legal basis applies if we are legally obliged to process. This applies in particular to tax and commercial law storage obligations, legal proof obligations, official inquiries or legal reporting obligations.
-
Article 6(3) 1 lit. f GDPR
This legal basis applies if the processing is necessary to safeguard legitimate interests and does not conflict with overriding interests or fundamental rights of the data subject.
Legitimate interests may in particular be:
a) secure operation of the platform,
b protection against fake evaluations,
protection against manipulation, spam and abuse,
d) examination and moderation of assessments,
e) processing of legal complaints,
ensuring freedom of expression and transparency in the evaluation system,
protection of rated companies against illegal content,
h protection of evaluating persons from unauthorized interference,
i legal defense and enforcement of own claims,
j) Improvement of the platform,
k) IT security and error analysis.
-
Special categories of personal data and criminally relevant information
TrustFair.de does not require any special categories of personal data in the sense of Art. 9 par. 1 GDPR and no information on criminal convictions or offences within the meaning of art. 10 GDPR. Users should not transmit such information, in particular in reviews, reports, messages and evidence, unless this is absolutely necessary for the respective process.
If such data is nevertheless transmitted, we limit the processing to the necessary extent. Insofar as special categories of personal data are necessary for the assertion, exercise or defence of legal claims, the processing takes place on the basis of art. 9 par. 2 lit. f GDPR. For data within the meaning of art. 10 GDPR is only processed insofar as this is permitted under EU law or Dutch law. Unnecessary information shall be blackened or deleted.
Part 6: Processing when visiting the website
When TrustFair.de is called up, technical data is automatically processed. These may include, in particular:
a) IP address,
b) date and time of access,
c) called page or file,
d) referrer URL,
e) browser type and browser version,
f) operating system used,
g) instrument type,
h) amount of data transmitted,
i) HTTP status code,
j) requesting provider,
k) technical safety features.
This data is processed in order to technically deliver the website, to ensure system security, to analyze errors, to detect abuse and to operate the platform in a stable manner.
The legal basis is Art. 6 par. 1 lit. f GDPR.
Server log files are usually stored for up to 30 days and then deleted or anonymized. Longer storage can take place if this is necessary to clarify security incidents, abuses, attacks or legal violations.
Part 7: Hosting
TrustFair.de is operated on servers in Germany. The technical provision is made via eghosting.pro, an offer of Scriptfabrik B.V. Since TrustFair.de and eghosting.pro are operated by the same legal entity, there is no transmission to an independent hosting provider.
External infrastructure, data center, network and security service providers can be used to provide the server and data center infrastructure. These processes in particular IP addresses, server log files, connection data, database contents and backup copies, as far as this is necessary for operation, maintenance, data backup and IT security. Insofar as these service providers act as processors, contracts according to art. 28 GDPR completed.
Legal bases are kind. 6 par. 1 lit. b GDPR for the provision of contractual platform services and art. 6 par. 1 lit. f GDPR for the secure, stable and economical operation of the platform.
Further information: EGhosting.pro Data protection
Part 8: Cookies, Local Storage and similar technologies
TrustFair.de uses cookies, local storage, session storage and comparable storage or access technologies.
Technically necessary cookies and storage technologies serve in particular to:
a to provide the Website,
b to store the login status,
c to manage sessions,
d implement security settings,
e) to store language settings,
f to document cookie settings,
g to provide shopping cart or booking functions where available.
Access to the terminal device is by type. 11.7a par. 3 of the Dutch Telecommunicatiewet without consent, insofar as it serves exclusively for the transmission of a message or is absolutely necessary to provide a digital service expressly desired by the user. As far as personal data are processed, this is done on the basis of art. 6 par. 1 lit. b GDPR or art. 6 par. 1 lit. f GDPR.
Unnecessary cookies, analytics cookies, marketing cookies or external services are only used if consent has been given.
For non-necessary storage and access processes, prior consent in accordance with art. 11.7a para 1 of the Dutch Telecommunicatiewet. As far as personal data are processed, an additional legal basis is art. 6 par. 1 lit. a GDPR.
A given consent can be revoked at any time via the cookie settings.
Currently, in particular the following technically necessary storage technologies are used:
a ci_session the management of meetings;
b csrf_cookie to protect against cross-site request forgery attacks;
c) tf_cc and tf_cookie_consent_v2 to store the cookie selection,
d tf_anonymous_id to assign and document a cookie decision,
e _GRECAPTCHA or comparable reCAPTCHA storage for bot and abuse detection on protected forms.
The optional internal analysis system uses the identifier in particular upon consent tf_sid in local storage. Details are given in Part 24.
Part 9: Consent Management
TrustFair.de uses an internal consent management system to obtain, document and manage consents for cookies, internal analysis functions and external services.
In particular, the following data can be processed:
a) consent status,
b) date and time of consent,
c) selected categories,
d) technical browser data,
e) abbreviated or pseudonymised IP address,
f) Consent ID,
g) language used,
h) Version of the declaration of consent.
The processing takes place in order to technically implement the selection, to enable revocation and to prove the granting or rejection of consent. The selection is stored in the browser and additionally logged on the server side. The cookie selection can be changed at any time via the data protection or cookie settings.
The legal basis is Art. 6 par. 1 lit. c GDPR in connection with art. 5 para 2 and Art. 7 par. 1 GDPR, as far as the consent must be proven. In addition, the processing is based on art. 6 par. 1 lit. f GDPR; Our legitimate interest lies in the legally secure management of data protection decisions.
Part 10: Registration and user account
For certain functions, registration is required.
When registering and using a user account, the following data in particular can be processed:
a) name or user name,
b) e-mail address,
c) password secured by means of a cryptographic hash method,
d) Account ID,
e) registration date,
f) login times,
g) account settings,
h) roles and authorizations,
i) booked functions or packages,
j) technical safety data,
k) Confirmation status of the email address.
The processing takes place to create, manage and secure the user account as well as to provide the platform functions.
The legal basis is Art. 6 par. 1 lit. b GDPR.
If data is processed for the prevention of abuse, system security or to prevent unauthorized access, the legal basis is art. 6 par. 1 lit. f GDPR.
Part 11: Reviews and Public Content
When users post reviews on TrustFair.de, we process the data entered.
These may include, in particular:
a) rating content,
b) star rating or other score,
c) rated entity;
d) date and time of assessment,
e) user name or display name,
f) verification status,
g) response history,
h) processing course,
i) reporting and verification status,
j) technical test features for misuse detection.
Reviews can be publicly visible. Publicly visible content can be perceived, stored or further processed by other users, search engines or third parties.
Users should not publish personal data of third parties in reviews. This includes in particular names, telephone numbers, e-mail addresses, addresses, customer numbers, payment data, health data, private messages or other confidential information.
The processing takes place for the publication, management and display of reviews.
The legal basis is Art. 6 par. 1 lit. b GDPR, insofar as the evaluation is provided as a platform function.
In addition, art. 6 par. 1 lit. f GDPR relevant. Our legitimate interest lies in the operation of a transparent evaluation system, the presentation of real experiences, the prevention of abuse and the information of the public.
Part 12: Evaluators
When a person submits a review, we may process personal data to technically enable the review, prevent abuse and verify the authenticity of the review.
These may include, in particular:
a) e-mail address,
b) name or display name,
c) IP address,
d) time of assessment,
e the content of the assessment;
f) the rated entity;
g) technical test characteristics,
h) evidence for evaluation,
i) communication history for queries,
j) status of verification.
The processing is done to provide the evaluation function, to prevent fake reviews, to review complaints and to ensure the integrity of the platform.
Legal bases are kind. 6 par. 1 lit. b GDPR and Art. 6 par. 1 lit. f GDPR.
Part 13: Assessment invitations
Depending on the functional scope, companies can invite customers or business contacts to submit a review.
In particular, the following data can be processed:
a) Name of the invited customer,
b) e-mail address,
c) company arranging the invitation,
d) time of dispatch,
e) invitation status,
f) assessment status,
g) technical shipping data,
h) Order number, customer number or transaction number, if provided by the company.
If a company imports customer data into TrustFair.de or triggers a review invitation, the company is generally responsible for ensuring that there is a legal basis for this.
TrustFair.de processes such data, as far as an order processing is available, according to the instructions of the respective company and on the basis of a contract for order processing.
In this case, the inviting company remains responsible for fulfilling the information obligations towards the invited persons. In particular, it must transparently inform that the contact data is transmitted to TrustFair.de or used via TrustFair.de for an invitation to review. TrustFair.de provides the companies with the necessary information for order processing.
Insofar as TrustFair.de processes data for its own purposes, for example for security, abuse prevention, documentation or to fulfill legal obligations, the processing takes place as its own controller.
If personal data is not collected directly from the invited person and TrustFair.de processes this as its own controller, the information obligations will become art. 14 GDPR is generally fulfilled at the latest within one month, during the first communication or before the first disclosure, whichever comes first.
Legal bases can be art. 6 par. 1 lit. b GDPR, Art. 6 para. 1 lit. c GDPR or art. 6 par. 1 lit. f GDPR.
Part 14: Verification of evaluations
To check the authenticity or plausibility of an evaluation, we can request or process proof.
Possible evidence is in particular:
a) order number,
b) invoice,
c) booking confirmation,
d) contract number,
e) customer number,
f) Support ticket,
g) proof of payment with blackened sensitive data,
h) e-mail communication,
i) proof of delivery or performance,
j) other appropriate evidence.
Users and companies should blacken unnecessary data before uploading. This includes in particular payment data, private message content, health data, ID data, data of third parties or other sensitive information, insofar as this is not necessary for the examination.
Evidence shall not be publicly displayed. They shall be made available only to the persons involved in the examination and, to the extent necessary for a fair trial or legal defence, to the parties involved, legal advisers, courts or authorities. Unnecessary information is generally blacked out before disclosure.
The processing is carried out to check whether an evaluation is based on real experience, as well as for abuse prevention, moderation and legal defence.
The legal basis is Art. 6 par. 1 lit. f GDPR.
As far as the examination under a user contract is necessary, art. 6 par. 1 lit. b GDPR is relevant.
Part 15: Company profiles
Company profiles can be displayed on TrustFair.de.
In the case of company profiles, the following data may in particular be processed:
a) company name,
b) address,
c) Website,
d) sector,
e public contact information,
f) assessments,
g) company responses,
h) Profile description,
i) logo or images,
j) authorised representatives or contact persons,
k) publicly available company data.
As far as data relate exclusively to legal persons, it is not always personal data. However, personal data may be affected if data relating to sole proprietors, managers, contact persons, employees or other natural persons are processed.
The processing takes place for the provision and management of company profiles as well as for the presentation of evaluations.
The legal basis is Art. 6 par. 1 lit. f GDPR.
Our legitimate interest lies in providing a transparent rating portal, informing the public and assigning ratings to companies.
Company and contact information may come directly from the company concerned, users, company websites, imprint information, publicly accessible registers, business directories or other lawfully accessible public sources. In the case of data that has not been collected directly from the data subject, the information requirements apply by type. 14 GDPR. Insofar as individual information is not required by law or is only possible with disproportionate effort, the information is provided by this publicly accessible data protection declaration; the conditions for this are examined on a case-by-case basis.
Part 16: Claiming and managing company profiles
When a company claims or manages a profile, we process data to check eligibility and manage the company account.
These may include, in particular:
a) name of the applicant,
b) business e-mail address,
c) telephone number,
d position or role in the company,
e) company name,
f) company address,
g) proof of representation,
h) Business Registration Statement,
i) proof of business,
j) domain or website confirmation,
k) power of attorney,
l) Roles and permissions in the company account.
The processing is carried out to check whether the applicant is entitled to manage the company profile and to provide the account functions.
The legal basis is Art. 6 par. 1 lit. b GDPR, insofar as the processing is necessary for the use of the company account.
In addition, art. 6 par. 1 lit. f GDPR relevant. Our legitimate interest lies in the prevention of unauthorized profile assumptions and in the protection of the integrity of the platform.
Part 17: Company Responses
Companies can respond to reviews as far as this feature is enabled.
In particular, the following data can be processed:
a) name or display name of the enterprise user,
b) corporate account,
c) response text,
d) date and time of publication,
e) processing course,
f) reporting or verification status,
g) technical test characteristics.
Company responses may be publicly visible.
The processing takes place to provide the response function, to document company reactions and to moderate illegal or abusive content.
Legal bases are kind. 6 par. 1 lit. b GDPR and Art. 6 par. 1 lit. f GDPR.
Part 18: Reporting, review and deletion of assessments
Companies, users or third parties may report reviews if they believe they are false, unlawful, abusive or not experience-based.
In particular, the following data may be processed in the event of a notification:
a) reporting person,
b) affected assessment,
c) affected user or company,
d) reporting reason,
e) justification of the notification,
f) evidence,
g) communication history,
h) decision and reasons for the decision,
i) processing status,
j) internal audit reports,
k) technical safety data.
Where an entity requests the deletion or review of an assessment, appropriate evidence may be required to be submitted. These may include, in particular:
a) customer data reconciliation,
b) order or contract data,
c Proof that there was no business relationship,
d) communication history,
e) invoice,
f) cancellation,
g) proof of delivery or performance,
h evidence of confusion,
i. evidence of abuse or extortion,
j) legal letter,
k) judicial decision.
Unnecessary personal data must be blackened before the upload.
The processing is carried out for the purpose of examining the report, deciding on the removal, blocking or retention of the evaluation, documenting the operation and legal defence.
A review procedure may provide the evaluating person and the entity concerned with the information necessary to provide an appropriate opinion. Real names, contact details and full proofs are not automatically shared with the other party. A disclosure shall only be made to the extent that it is necessary and proportionate for the purposes of examination, performance of a legal obligation or for the purposes of asserting, exercising or defending legal claims.
The legal basis is Art. 6 par. 1 lit. f GDPR.
Our legitimate interest lies in the legally compliant moderation of content, the protection of affected persons and companies, the prevention of fake reviews and the legal defence.
As far as legal obligations exist, the processing takes place on the basis of art. 6 par. 1 lit. c GDPR.
Part 19: DSA notification and complaint procedures
Insofar as TrustFair.de is subject to legal obligations for online platforms, we provide reporting and complaint channels for unlawful content and moderation decisions.
In particular, the following data can be processed:
a) name or contact details of the reporter,
b) affected content,
c) URL or unique content identifier,
d) reporting reason,
e) legal or factual reasons,
f) evidence,
g) decision on the notification,
h) statement of grounds of appeal,
i) communication history,
j) internal audit reports.
The processing takes place to process statutory notification and complaint procedures as well as to document moderation decisions.
The legal basis is Art. 6 par. 1 lit. c GDPR, insofar as legal obligations exist.
In addition, art. 6 par. 1 lit. f GDPR be relevant. Our legitimate interest lies in proper platform moderation, abuse prevention and legal defence.
Part 20: Contact and Support
When users, companies or other persons contact us, we process the transmitted information.
These may include, in particular:
a) name,
b) e-mail address,
c) telephone number,
d) enterprises;
e) Subject,
f) message,
g) customer number or account ID,
h) Annexes,
i) communication history,
j) Processing status.
The processing takes place to process the request, to communicate with the requesting person and to document the process.
TrustFair.de also provides an internally operated live chat and a ticket system. When starting a chat or ticket, depending on use, in particular name, e-mail address, message content, attachments, time stamps, account reference, session identification and technical connection data are processed. Chat and ticket data are processed within the TrustFair.de infrastructure. The chat widget is activated according to the current cookie configuration only after sharing the associated optional category; the active transmission of a message takes place additionally at the request of the user.
The legal basis is Art. 6 par. 1 lit. b GDPR, if the request is related to a contract, account or pre-contractual measures.
In all other cases, the legal basis is Art. 6 par. 1 lit. f GDPR.
Our legitimate interest lies in the processing and documentation of inquiries.
Part 21: Premium accounts, contracts, payments and invoices
If paid functions, premium packages or additional services are booked, we process the necessary data.
These may include, in particular:
a) name or company,
b) contact person,
c) invoice address,
d) e-mail address,
e) booked package,
f) scope of power,
g) maturity,
h) Payment status,
i) invoice number,
j) control data,
k) method of payment,
l) transaction data,
m) Contract communication.
Payment processing can take place via external payment service providers.
Depending on the payment method, payment data is processed directly by the payment service provider. For this processing, the data protection notice of the respective payment service provider applies in addition.
The specific payment methods and payment service providers available are displayed in the order or checkout process.
When selecting an external payment service provider, the latter receives the data necessary for payment processing and processes certain data under its own data protection responsibility. This may include name, billing address, e-mail address, amount, currency, transaction identifier, payment status and payment method-specific information. Complete card or account access data are generally entered directly with the respective payment service provider and are not stored by TrustFair.de, unless they are exceptionally necessary for the selected payment method. The data protection notices of the selected payment service provider displayed in the checkout apply in addition.
The processing takes place for the execution of the contract, payment processing, invoicing, contract management and fulfillment of statutory storage obligations.
The legal basis is Art. 6 par. 1 lit. b GDPR.
Insofar as tax or commercial law storage obligations exist, the legal basis is Art. 6 par. 1 lit. c GDPR.
Part 22: Email and system messages
For the sending of system messages, own mail servers or external e-mail service providers can be used.
System messages can in particular be:
a) registration confirmation,
b) password reset email,
c) security notifications,
d) assessment notifications,
e) assessment invitations,
f) payment and billing information,
(g) notification and complaint decisions;
h) Notes on account changes.
In particular, the following data can be processed:
a) e-mail address,
b) Name,
c) account ID,
d) message type,
e) time of dispatch,
f) delivery status,
g) technical shipping data.
The legal basis is Art. 6 par. 1 lit. b GDPR, as far as the messages are necessary for contract or account processing.
For security-relevant notifications and proof of delivery is additionally art. 6 par. 1 lit. f GDPR relevant.
If an external e-mail service provider is used, it will be named in this data protection declaration or in the context of additional data protection information.
Part 23: Newsletter and promotional communication
If a newsletter is offered, it will only be sent if there is consent or legal permission.
In particular, the following data may be processed for the newsletter:
a) e-mail address,
b) Name, if indicated,
c) date of filing,
d) confirmation time,
e) IP address upon registration,
f) consent status,
g) Deregistration status.
The application can be made via a double opt-in method.
The legal basis for sending the newsletter is art. 6 par. 1 lit. a GDPR. For the use of electronic contact data, art. 11.7 of the Dutch Telecommunicatiewet.
The consent can be revoked at any time with effect for the future.
Existing customers can obtain information on their own similar services if the electronic contact data in connection with the sale of a service were collected and the legal requirements of the art. 11.7 para 4 of the Dutch Telecommunicatiewet are fulfilled. When collecting the contact details and in each advertising message, a clear, free and simple objection option is provided.
Legal basis for the processing of personal data may in this case art. 6 par. 1 lit. f GDPR. Our legitimate interest lies in direct advertising for our own similar services. An objection against direct advertising will be observed at any time and without giving reasons.
If no newsletter is offered, no newsletter-related processing takes place.
Part 24: Internal analysis, range and error measurement system
TrustFair.de uses an internally operated analysis system. It is only activated when the user has approved the category “Statistics & Analysis”. The analysis data is transmitted to endpoints on the domain trustfair.de; an external analysis provider such as Google Analytics or Matomo is currently not included for this internal measurement.
In particular, the following data can be processed:
a) called side path,
b) pseudonymous session identifier tf_sid,
c) page views and referrer URL,
d) device class such as mobile device, tablet or desktop,
e status as a guest or registered user,
f) active period of use and residence,
g) Scroll depth,
h) click events including position and technical identification of the clicked element,
i) expressly defined conversion events,
j) IP address, time and further connection data arising technically during the transmission,
k) JavaScript errors, affected URL, file name, row and column specifications, and technical error or stack information.
The processing serves to measure the range, improve the user guidance, error analysis, stability and further development of the platform. The session identifier is stored in the local storage and removed when the analysis consent is revoked. Users can revoke the consent at any time via the cookie settings.
The legal basis for accessing the terminal is art. 11.7a para 1 of the Dutch Telecommunicatiewet. The legal basis for the processing of personal data is art. 6 par. 1 lit. a GDPR.
Part 25: Google reCAPTCHA and bot protection
TrustFair.de uses Google reCAPTCHA v3 on the registration and on selected forms via the domain www.recaptcha.net. Provider in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. reCAPTCHA is used to detect automated access, spam, fake accounts, abusive reviews and attacks.
In particular, the following data may be transmitted to Google or processed by Google:
a) IP address,
b) browser and device information,
c) referrer and called page,
d) date and time,
e) mouse, keyboard and other interaction data,
f) the cookie or storage identifier _GRECAPTCHA,
g) security tokens, risk and audit values,
h) information from already existing Google cookies or a logged-in Google account, if Google technically assigns them.
Google indicates that reCAPTCHA has the necessary identifier _GRECAPTCHA for risk analysis. TrustFair.de uses the domain offered by Google recaptcha.netto reduce access to other Google cookies.
The processing serves the security of the platform and the prevention of spam, fraud and automated misuse. The legal basis for the processing of personal data is art. 6 par. 1 lit. f GDPR. Our legitimate interest lies in the protection of accounts, forms, reviews and IT systems. Access to the terminal device is provided in art. 11.7a par. 3 of the Dutch Telecommunicatiewet, insofar as it is absolutely necessary for the expressly used form and security function. Insofar as Google also performs non-necessary storage or access operations, activation may only take place after prior consent in accordance with art. 11.7a para 1 of the Telecommunicatiewet and Art. 6 para. 1 lit. a GDPR.
Google may also process data outside the European Economic Area, especially in the USA. For this purpose, the requirements of Part 32 apply.
Further information:
a Google data protection declaration
b Google reCAPTCHA – Frequent questions
Part 26: Abuse and Fraud Prevention
To prevent fake reviews, spam, manipulation, multiple accounts, security attacks and other misuse, we can use technical and organizational auditing measures.
In particular, the following can be processed:
a) IP address,
b) account data,
c) login data,
d) valuation patterns,
e) device and browser data,
f) times of action,
g) Frequency of certain actions,
h) technical safety features,
i) reporting and verification history,
j) conspicuous usage patterns,
k) Verification status.
The processing is done to secure the platform, the integrity of the rating system and to protect users and companies.
The legal basis is Art. 6 par. 1 lit. f GDPR.
Our legitimate interest lies in the prevention of fake reviews, manipulation, spam, fraud, automated attacks and other abuse.
Part 27: Automated tests
We can use automated systems to detect flashy activity, fake ratings, spam, manipulation patterns or security risks.
Such systems may provide guidance but do not necessarily lead to a final decision with legal effect alone.
In particular, the test systems used may take into account technical characteristics, time patterns, multiple use, unusual evaluation activities, verification status, reporting history and similarities between contents. The result may lead to risk labelling, manual checking, temporary retention of content or additional verification requirements.
If an automated review leads to restrictions, blocks or removal of content, affected users may submit a review or complaint to the extent provided by law or offered by us.
The legal basis is Art. 6 par. 1 lit. f GDPR.
An exclusively automated decision with legal effect or similar significant impairment does not take place. Final blocks, permanent deletions or similar measures may be reviewed by a person authorised to do so. Affected persons may state their point of view and request human review.
Part 28: External Content, Google Maps, Google Fonts and Links
TrustFair.de may contain links to external websites. When simply displaying a link, no data is transmitted to the linked website. When users click on an external link, they leave TrustFair.de; for the subsequent processing is the respective external provider responsible.
-
Google Maps
On the imprint page, a map of Google Maps can be integrated. The card is initially blocked and is loaded only after a corresponding release. The provider in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
When loading the card, in particular IP address, browser and device information, referrer, location or map data as well as date and time can be transmitted to Google. If the user is logged into Google, Google can assign the processing to the Google account.
The legal basis for accessing terminal information is art. 11.7a para 1 of the Dutch Telecommunicatiewet. The legal basis for the processing of personal data is art. 6 par. 1 lit. a GDPR. The consent can be revoked at any time via the cookie settings.
-
Google Fonts
TrustFair.de may load fonts from Google servers upon consent. Technically, the IP address together with browser, device, referrer and time information is transmitted to Google. The provider in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The legal basis for accessing terminal information is art. 11.7a para 1 of the Dutch Telecommunicatiewet. The legal basis for the processing of personal data is art. 6 par. 1 lit. a GDPR. Where possible, fonts should be provided locally so that no connection to Google is required.
-
Other external media
Videos, social media content or other external media are only loaded with the necessary consent. The respective provider, purpose, the processed data and a possible third country transmission are indicated in the cookie settings or immediately before activation.
Google may also process data outside the European Economic Area, especially in the USA. For this purpose, the requirements of Part 32 apply. Further information shall include: Google data protection declaration.
Part 29: Social media presences
We can operate our own presences in social networks.
When users visit our social media pages or communicate with us about them, personal data may be processed by us and the respective platform operator.
For the processing by the respective platform operator, its data protection information applies.
Our social media presences serve for external presentation, communication, information and user interaction.
The legal basis is Art. 6 par. 1 lit. f GDPR.
If no social media presences are currently operated, no corresponding processing takes place via our own social media presences.
Part 30: Recipients of personal data
Personal data may be transmitted to the following recipients to the extent necessary:
a) hosting provider,
b) IT service providers,
c) e-mail service providers,
d) payment service providers,
e) Support and CRM providers,
f) analytics and security service providers;
g) tax advisors and accounting,
h) Lawyers,
i) authorities and courts,
j) affected users or companies in the framework of notification and verification procedures,
k other service providers, insofar as they are necessary for operation, security or contract implementation.
Among the specific recipients used is Google Ireland Limited for reCAPTCHA as well as – upon consent – Google Maps and externally loaded Google Fonts. The internal analysis system and the live chat are operated via the TrustFair.de infrastructure and do not transmit data for these functions to an external analysis or chat provider. Further specific recipients are named in the checkout, in the cookie settings or immediately when using the respective function.
A transfer will only take place if there is a legal basis for this.
We conclude contracts with processors, where necessary, for order processing.
Part 31: Processing
Insofar as we process personal data on behalf of a company, we act as a processor in the sense of art. 28 GDPR.
This can be the case in particular if a company imports customer data, triggers review invitations or uses account-related evaluations.
In these cases, the processing takes place according to the instructions of the respective company and on the basis of a contract for order processing.
In other cases, we act as our own controller. This applies in particular to the operation of the platform, the publication and moderation of ratings, the examination of fake ratings, the processing of legal complaints, abuse prevention, own user accounts, own billing and the fulfillment of legal obligations.
Part 32: Transmission to third countries
A transfer of personal data to countries outside the European Union or the European Economic Area will only take place if the legal requirements are met.
This can be done in particular if:
a there is an adequacy decision of the EU Commission,
b the recipient is certified in the USA in accordance with the EU-US Data Privacy Framework and the certification covers the relevant processing,
c standard contractual clauses of the European Commission have been concluded,
if necessary, additional technical, organisational or contractual protective measures exist,
e) express consent in accordance with art. 49 para 1 lit. a GDPR,
f) the transmission exceptionally for the performance of the contract according to art. 49 GDPR is required,
g) there is another legal exception.
Third-country transfers may be relevant in particular for external services such as payment service providers, analytics tools, captcha services, cloud services or communication services.
Unless external third-country-related services are used, no corresponding third-country transmission by these services shall take place.
Data subjects may request further information on the specific basis for transmission and a copy or description of the appropriate guarantees at the contact address referred to in Part 39. For Google services, processing by Google LLC may take place in the USA. Where applicable, Google relies on the EU-US Data Privacy Framework and additional guarantees. Further information: Google – Data transmission framework.
Part 33: Storage time
We store personal data only as long as it is necessary for the respective purposes or statutory retention periods exist.
The following time limits are considered to be control values. earlier deletion takes place as soon as the data are no longer needed for the respective purpose; a longer storage takes place only if a specific legal obligation, an ongoing procedure or the assertion, exercise or defence of legal claims requires this.
Typical storage periods:
a) Account data: for the duration of the user account,
b reviews: as long as they are published or there are legitimate reasons for storage,
c Evidence of assessments: for the duration of the examination and in principle up to 6 months after final completion; in the case of a specific legal dispute or abuse until its final conclusion and the expiry of relevant limitation periods,
d) notifications and complaints procedures: for the duration of processing and in principle up to 3 years after completion; in the case of legal disputes, longer,
e contract data: for the duration of the contractual relationship and statutory storage obligations,
f) Payment and billing data: in accordance with statutory storage obligations,
g basic data of the Dutch business and tax administration, including debtor, creditor, purchase, sales and general ledger data: in principle 7 years,
h data on immovable property and data on turnover covered by the EU One-Stop-Shop or Import-One-Stop-Shop regulations: in principle 10 years, as far as the legal requirements are met,
i) server log files: usually up to 30 days, unless longer storage is required,
j security data: as long as this is necessary to investigate or prevent misuse,
k support chats and tickets: in principle up to 3 years after conclusion, as far as no contract, legal or security case requires longer storage,
l) proofs of consent and opposition: for the duration of the processing based thereon and thereafter for as long as the proof of compliance with accountability or legal proceedings
idation is required,
m) internal analysis data: generally a maximum of 14 months, unless it is anonymized beforehand or deleted due to revocation.
A longer storage can take place if this is necessary for asserting, exercising or defending legal claims, for information about abuse or for fulfilling legal obligations.
Part 34: Deletion of the user account
Users can request the deletion of their account.
After deletion of the account, personal data will be deleted or anonymized, as far as no statutory storage obligations, open inspection procedures, security reasons, suspicion of abuse or legitimate interests conflict.
Public reviews are not automatically removed in every case when an account is deleted. They can be separated from the account, anonymized or stored if there is an independent legal basis for this, in particular type. 6 par. 1 lit. f GDPR as well as the protection of freedom of expression and information. The interests of the evaluating person, the rated entity and the public are weighed on a case-by-case basis. If there is a cancellation claim according to art. 17 DSGVO, the evaluation is deleted or effectively anonymized.
If reviews remain anonymized, no direct personal reference is provided anymore.
Part 35: Data security
We take technical and organizational measures to protect personal data against loss, misuse, unauthorized access, alteration or disclosure.
These may include, in particular:
a) encrypted transmission via TLS/SSL,
b) access restrictions,
c) cryptographic password hash methods,
d) role-based permissions,
logging of security-relevant processes,
f. regular updates,
g) backups,
h) technical protection against attacks,
internal data protection and security processes,
j) Restricting access to required persons.
Despite all measures, complete safety cannot be guaranteed. Internet-based data transmissions may have security risks.
Part 36: Obligation to provide data
The provision of certain personal data is necessary to use the Platform.
Without certain data, individual functions cannot be provided.
In particular:
a) e-mail address for registration and login,
b account data for user accounts,
(c) evaluation data for the publication of evaluations;
d) company data for claimed company profiles,
e) payment data for paid packages,
f) Evidence when an assessment has to be verified or a claim has to be substantiated.
There is no legal obligation to use the platform.
Failure to provide necessary data may result in an account not being created, a review not being published or verified, a company profile not being claimed, a report not being finally verified or a paid service not being provided.
Part 37: Minors
The platform is not aimed at children. Registered users must in principle be at least 16 years old.
People under the age of 16 may not create their own account or post a review. Insofar as processing is exceptionally to be based on the consent of a person under the age of 16, Dutch law requires the demonstrable consent of the legal representatives.
We reserve the right to suspend or delete accounts if there is any doubt about the effective use by minors.
Part 38: Rights of data subjects
Data subjects have the following rights in accordance with statutory provisions:
-
Right of access
Data subjects can request information about whether and which personal data we process about them.
-
Right to rectification
Data subjects may request the correction of inaccurate personal data.
-
Right of cancellation
Affected persons may request the deletion of personal data insofar as no statutory storage obligations, legitimate interests, legal defence reasons or other statutory reasons conflict.
-
Right to restriction of processing
Data subjects may, under certain conditions, request that the processing of their personal data be restricted.
-
Right to data portability
Data subjects may request to receive personal data they have provided to us in a structured, common and machine-readable format, as far as the legal requirements are met.
-
Right of appeal
If personal data based on art. 6 par. 1 lit. f GDPR, data subjects may object to the processing for reasons arising from their particular situation.
If personal data are processed for direct marketing, there is a right to object at any time without giving reasons.
-
Right to withdraw consent
If a processing is based on consent, this consent can be revoked at any time with effect for the future.
The legality of the processing until the revocation remains unaffected.
-
Right to complain to a supervisory authority
Data subjects have the right to complain to a data protection supervisory authority.
-
Law relating to automated decisions
Affected persons have by type 22 GDPR the right not to be subject to an exclusively automated decision that has legal effect on them or similarly significantly affects them, unless there is a legal exception. TrustFair.de makes no such exclusively automated decisions. Details of automated test aids are given in Part 27.
Part 39: Exercise of data subject rights
For the exercise of rights, a notification shall be sufficient to:
Scriptfabrik B.V.
Pastoor Jacobsweg 27
6226 VV Maastricht
Netherlands
E-mail: welcome@trustfair.de
We may ask data subjects to prove their identity if this is necessary to clearly assign a request and to avoid unauthorized information.
In principle, we answer inquiries immediately and at the latest within one month of receipt. In the case of complex or numerous requests, the deadline may vary according to type. 12 para 3 GDPR can be extended by up to two further months. An extension and its reasons will be notified within the first month. The exercise of the rights of the data subject is, in principle, free of charge; Art. 12 para 5 GDPR remains unaffected.
Part 40: Right of complaint to a data protection supervisory authority
Affected persons have according to art. 77 GDPR the right to complain to a data protection supervisory authority if they consider that the processing of their personal data violates the GDPR or other data protection regulations.
In particular, the complaint may be lodged with a supervisory authority in the Member State of the habitual residence, workplace or place of alleged data protection infringement.
For our company headquarters in the Netherlands, the following supervisory authority is basically responsible:
Autoriteit Persoonsgegevens
Postal address:
Postbus 93374
2509 AJ The Hague
Netherlands
Visitor address:
Bezuidenhoutseweg 30
2594 AV The Hague
Netherlands
Website: https://www.autoriteitpersoonsgegevens.nl
Complaint form: https://www.autoriteitpersoonsgegevens.nl/een-tip-of-klacht-indienen-bij-de-ap
The right of appeal shall be without prejudice to other administrative or judicial remedies.
Part 41: Definitions
-
Personal data
Personal data is any information relating to an identified or identifiable natural person.
-
Person concerned
The data subject is any natural person whose personal data is processed.
-
Processing
Processing is any operation related to personal data, such as collection, storage, use, transmission, deletion or restriction.
-
Accountable person
The controller is the body which decides on the purposes and means of processing personal data.
-
Processors
Processor is an entity that processes personal data on behalf of a controller.
-
Consent
Consent is a voluntary, informed and unambiguous statement by which a data subject agrees to a particular processing.
-
Pseudonymisation
Pseudonymisation means that personal data can no longer be assigned to a specific person without additional information.
-
Anonymity
Anonymization means that a personal reference no longer exists and the person concerned can no longer be identified.
-
Cookies
Cookies are small files or information that can be stored on a user’s device.
-
Logfiles
Logfiles are technical log data that can arise when accessing a website or platform.
Part 42: Amendments to this Privacy Policy
We may adjust this privacy policy if our platform, services used, legal requirements or data processing changes.
The current version is available on TrustFair.de.
In the event of significant changes, registered users can also be informed by e-mail or in the account area.
An amendment to this data protection declaration does not create a new legal basis for data already collected. If a consent is required for a new processing, this will be obtained before the beginning of the processing.
Part 43: Contact
For questions about data protection, the processing of personal data or the exercise of affected rights, please contact us at:
Scriptfabrik B.V.
Pastoor Jacobsweg 27
6226 VV Maastricht
Netherlands
E-mail: welcome@trustfair.de
Website: https://www.trustfair.de