Datenschutzerklärung

For bchic UG (haftungsbeschränkt), protecting the confidentiality, integrity, and availability of your data that we collect, process, or store on our website and in connection with the use of our bchic analytics platform is very important. We use various security procedures to protect your personal data. With this privacy notice, we inform you about the type, scope, and purposes of processing personal data in connection with the use of our website (https://www.bchic.de), our social media presence, as well as in connection with the use of the bchic analytics platform, who is responsible for this data processing, and about the rights you have as a data subject. Personal data refers to data that can be related (directly or indirectly) to you personally and provides conclusions about your identity, such as name, gender, address, or usage data (e.g., your IP address).

Controller, Contact, and Data Protection Officer

The controller within the meaning of Art. 4 No. 7 of the General Data Protection Regulation (GDPR) for the data processing operations described in this privacy policy is

bchic UG (haftungsbeschränkt) („We" or „Us")
Ilsensteineweg 37a, 14129 Berlin
Email: kontakt@bchic.studio

Our data protection officer is Leander Jo Bärwaldt, founder of bchic, who can be reached at kontakt@bchic.studio for questions or concerns regarding data protection.

1. Data Collection When Visiting Our Website

For hosting our website, we use Webflow, a service of Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, 94103, USA ("Webflow"). To ensure a smooth connection and comfortable use of our website and to increase the attractiveness of our offering for users, Webflow collects information on our behalf temporarily when you visit our website for informational purposes, e.g., information about the browser you use and the operating system. This log data is automatically transmitted and temporarily and anonymously stored as a log record ("server log files"). This data includes:

  • IP address of the device from which access to our website occurs. IP addresses are anonymized by removing the last octet;
  • The URL of the website from which access to our website occurred (origin or referrer URL);
  • The date, time, and duration of the access;
  • Time zone difference to Greenwich Mean Time (GMT);
  • The message whether the access was successful (access status/HTTP status code);
  • The amount of data transferred in each case;
  • The device (PC, mobile phone), operating system, and information about the internet browser used;
  • Language and version of the browser software.

The anonymized IP addresses are deleted after 24 hours at the latest. We have concluded a data processing agreement with the provider in accordance with Art. 28(3) GDPR. Webflow is certified under the EU-US Data Privacy Framework:

https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt0000000TT9jAAG&status=Active

You can access Webflow's privacy policy here: https://webflow.com/legal/privacy

The legal basis for this processing is our legitimate interest in the smooth provision of the website within the meaning of Art. 6(1) lit. f) GDPR.

2. Inquiries via Email

When you contact us via email, we store the data you send us in your email (particularly your contact and communication data). We use this data exclusively to process your inquiry. Our employees are trained in handling your data and are contractually obligated to confidentiality.

The legal basis for this data processing is Art. 6(1) lit. f) GDPR (legitimate interest). Our legitimate interest is to respond to your inquiry. If your inquiry is aimed at concluding a contract, the legal basis is Art. 6(1) lit. b) GDPR (contract performance).

We delete your data as soon as the purpose of processing no longer applies, typically when your inquiry has been fully answered. In some cases, we must store your data longer due to legal retention obligations. This may be the case, for example, if your inquiry is related to a contract or warranty. In these cases, we delete your data no later than after the expiration of the legal retention period (e.g., 10 years after contract conclusion) without you having to request this separately.

Email Communication & Product Notifications via Loops

For the dispatch of system-relevant emails (so-called transactional emails, e.g., registration confirmations, password resets, invoice information) as well as for information regarding product updates and onboarding support, we use the service provider Loops Inc., USA ("Loops").

For this purpose, your email address, your name, and technical information regarding your usage behavior (e.g., login activity, features used, email open rates) are transmitted to Loops. This allows us to provide you with relevant support for using our software at the appropriate time.

Legal Basis:

System Emails (Transactional):
Processing is technically necessary for the performance of the contract (Art. 6 (1) (b) GDPR).

Onboarding & Product Tips: Processing is based on our legitimate interest in providing you with the best possible utility of our software and strengthening customer loyalty (Art. 6 (1) (f) GDPR). If you have explicitly subscribed to a newsletter, processing is based on your consent (Art. 6 (1) (a) GDPR).

Right to Object:
You may object to receiving emails that are not strictly necessary for the operation and security of your account at any time via the "Unsubscribe" link at the bottom of each email.

Data Transfer to Third Countries:
Since Loops is headquartered in the USA, data is transferred to a third country. We have concluded a Data Processing Addendum (DPA) with Loops that includes the EU Commission’s Standard Contractual Clauses (SCCs) to ensure an adequate level of data protection in accordance with Art. 46 GDPR.

3. Direct Marketing

If you enter into a paid contract for the use of our services and provide your email address, bchic may use this email address for direct marketing of similar goods or services. You have the right at any time to object to the use of your email address for this purpose, without incurring any costs other than transmission costs according to basic rates. Each email contains an unsubscribe link for this purpose. Alternatively, you can declare your objection at any time via email to kontakt@bchic.studio.

The legal basis for this data processing is Art. 6(1) lit. f) GDPR. You can object to data processing for the purpose of direct marketing at any time without giving reasons.

4. Processing of Personal Data When Registering a Customer Account

On our website, it is possible to create a customer account. A customer account is required to activate a free trial period for our platform via our website or to subscribe to paid services. If you wish to register a customer account, we will send a confirmation link to the email address you provided, through which you can access the registration form and enter the required data. The data we process as part of the registration includes in particular:

  • IP address of the device from which the registration is made;
  • The date and time of registration;
  • Your contact details, e.g., your name, your email address;
  • The name of the company you work for;
  • Address data.

The legal basis for processing the data as part of the registration is Art. 6(1) sentence 1 lit. b) GDPR.

The data will be deleted when the purpose of processing no longer applies, e.g., because you delete your customer account. In some circumstances, we may need to store this data longer in some cases due to legal retention obligations.

5. Processing of Personal Data for Paid Subscriptions

In addition to the free trial period, you also have the option to subscribe to paid services on the website through your customer account. When you complete a subscription through our website, we process the following data:

  • IP address of the device from which the order is placed;
  • The date and time of the order;
  • Contact details such as your email address;
  • Payment data;
  • The subscription you selected;
  • Any additional, supplementary data you provide during the registration process (e.g., an added "promo code").

To process payments, we transmit the necessary payment data to our commissioned payment service provider Stripe Payments Europe Ltd., Block 4, Harcourt Centre, Harcourt Road, Dublin 2, Ireland. Where necessary, Stripe also transmits the data to Stripe, Inc. in the USA. More information about data protection at Stripe and the corresponding privacy notices can be found at the following link: https://stripe.com/en-de/privacy

For payment processing, we process the Stripe Customer ID, the Subscription ID, and the abo-status. The processing is necessary for the conclusion and fulfillment of the contract. The legal basis for this data processing is Art. 6(1) sentence 1 lit. b) GDPR.

The data will be deleted when the purpose of processing no longer applies, e.g., because you cancel your subscription with bchic. In some circumstances, we may need to store this data longer in some cases due to legal retention obligations. In this case, we delete your data no later than the expiration of the legal retention period (§ 147(3) AO), i.e., after 10 years from the conclusion of the contract, without you having to request this separately.

6. Duration of Storage of Your Personal Data

Unless we have specified a shorter storage period in this privacy notice, we generally store personal data only as long as (i) this is necessary for the provision of services to you and/or (ii) this is necessary with regard to the contractual relationship with you; thereafter, the data will only be stored to the extent and for as long as we are obligated to do so due to legal retention obligations. If we no longer need the relevant personal data for the purposes described above, this personal data will only be stored for the duration of the respective legal retention obligations and will not be processed for other purposes.

7. bchic analytics – Your privacy-friendly tracking

We use bchic analytics to understand how our website is used without deploying cookies or banners.

  • What we see: bchic analytics captures anonymized data about your activities on our website, such as which pages you visit, how long you stay, and which elements you click. Your IP address is also captured.
  • Anonymization is important to us: Your IP address is anonymized immediately after capture. This means we cannot see who you are.
  • Without cookies: bchic analytics does not use cookies.
  • What we use it for: We use this data to improve our website and offerings and to create reports.
  • Legal basis: Our legitimate interest (Art. 6(1) lit. f GDPR). We want to improve our website.

For analyzing the use of our website and our platform, we use bchic analytics. bchic analytics is operated in the EU, Germany, Ilsensteinweg 37a, 14129 Berlin ("bchic analytics"). The data collected by bchic analytics is stored completely anonymously on the website operator's private cloud server, and this information cannot be traced back to the user. Additionally, all bchic servers and CDN are located in the EU, which means no data traffic occurs outside. More about this at How bchic processes data.

Necessary Cookies

These are cookies that are absolutely necessary for the functionality or provision of our offering. The legal basis for accessing or storing information on your device is § 25(2) No. 2 TTDSG;

The legal basis for the subsequent data processing associated with this is our legitimate interest in providing and ensuring comfortable use of our offering within the meaning of Art. 6(1) lit. f) GDPR.

8. Our Social Media Presence

If you use your profile on X (formerly Twitter, Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland) to contact us (e.g., by sending us a private message), we will process the communicated data exclusively for the purpose of being able to contact you. The legal basis for data processing is our legitimate interest in responding to your inquiry within the meaning of Art. 6(1) lit. f) or Art. 6(1) lit. b) GDPR if the inquiry is related to the conclusion of a contract or the execution of a contract. We delete this data no later than four weeks after storage is no longer necessary or you request deletion.

9. Your Rights as a Data Subject

Persons affected by the processing of personal data have the following rights:

  • Right to information about the personal data we process, the processing purposes, categories of recipients, the duration of storage or the criteria for determining the storage duration, the origin of the data, your rights as a data subject, the existence of automated decision-making including profiling and about the appropriate safeguards when transferring data to a third country, as well as the right to receive a copy of your personal data;
  • Right to rectification of inaccurate or incomplete personal data;
  • Right to erasure of personal data if the purpose of processing no longer applies, consent is withdrawn or there is no other legal basis, or the data was processed unlawfully, or you have objected to the processing;
  • Right to restriction of processing;
  • Right to data portability the data processing is based on consent according to Art. 6(1) lit. a) or Art. 9(2) lit. a) or on a contract according to Art. 6(1) lit. b) GDPR;
  • Right to object processing if the processing is based on legitimate interests according to Art. 6(1) lit. f) GDPR.
  • If you have consented to the processing of personal data, you can revoke your consent at any time. The revocation of consent does not affect the lawfulness of processing carried out on the basis of consent before its revocation.

Right to Object to Direct Marketing

If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes. You can declare your revocation at any time via email to kontakt@bchic.studio or send it to the postal address stated above.

You also have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data is unlawful.

We update our privacy policy when this is necessary due to changes in factual or legal circumstances or to take into account technical or economic developments. We will inform you in advance in an appropriate manner about such changes. If you continue to use our offering after receiving such notification from us, we may assume that you accept the changes to the privacy policy.