Trustolino Logo

Privacy Policy

1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Trustolino GmbH
Rottfeldstr. 15–17
68199 Mannheim
Germany

Represented by:
Managing Director Felix Schüßler
Email: [Add email address]


2. General Information on Data Processing

The protection of your personal data is important to us. We process personal data exclusively in compliance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR) and relevant national data protection provisions.

Personal data is any information relating to an identified or identifiable natural person, such as name, email address, or IP address.


3. Visiting Our Website

When you access our website, technically necessary information is processed to ensure the secure and stable delivery of the service.

In particular, the following data may be processed:

  • IP address
  • Date and time of access
  • Accessed URL
  • Browser type and browser version
  • Operating system
  • HTTP status codes
  • Technical connection data
  • Access and error logs

Processing takes place exclusively to deliver the website and ensure system security and stability.

Legal basis: Art. 6 (1) lit. f GDPR
Our legitimate interest lies in the secure, stable, and functional provision of our online services.


4. Backend Infrastructure and Database Services (Convex)

To operate our backend functions, database, and automated data workflows on this website, we use the reactive Backend-as-a-Service platform Convex.

Service Provider:
Convex, Inc.
548 Market St #61788
San Francisco, CA 94104
USA
Privacy Policy: https://www.convex.dev/privacy

Convex handles in particular on our behalf:

  • Backend infrastructure and server functions
  • Reactive database management
  • Automated scheduled tasks and data cleanup (crons)
  • Technical security measures and rate limiting
  • Protection against abuse and unauthorized access
  • Technical logging and error analysis

Processed Data

In the context of service provision, the following data may be processed:

  • IP address (anonymized or hashed for rate limiting)
  • Technical connection data
  • Access logs
  • Error and security logs
  • Pre-registration data (name, email address, language preference, timestamp, confirmation status)

Server Location

Our Convex deployment infrastructure is hosted in the AWS Frankfurt region (eu-west-1, Germany, EU).

Data Processing Agreement and International Transfers

A Data Processing Agreement (DPA pursuant to Art. 28 GDPR) incorporating the European Commission's Standard Contractual Clauses (SCCs) has been concluded with Convex, Inc.

Legal Bases

  • Art. 6 (1) lit. b GDPR (Performance of a contract or pre-contractual measures)
  • Art. 6 (1) lit. f GDPR (Legitimate interest in secure, stable, and efficient operation)

5. Pre-Registration for Trustolino

On our website, we offer interested users the opportunity to pre-register for the future launch of Trustolino.

In doing so, we process the following data:

  • First and last name
  • Email address
  • Language preference
  • Time of registration

We use this data exclusively to:

  • Inform you about the platform launch,
  • Send registration invitations,
  • Provide information regarding Trustolino.

Data is not passed on to third parties for advertising purposes.

Legal basis: Art. 6 (1) lit. a GDPR (Consent)


6. Double Opt-In Procedure

Registration for pre-registration follows the double opt-in procedure.

After submitting your email address, you will receive a confirmation email. Your registration is only completed once you click the confirmation link contained therein.

This procedure serves to verify your consent and prevent fraudulent registrations.

Legal basis: Art. 6 (1) lit. a GDPR
You can revoke your consent at any time with effect for the future.


7. Email Communication

When you contact us by email, we process the data you provide to handle your inquiry.

This includes in particular:

  • Name
  • Email address
  • Content of your message
  • Any additional information you provide voluntarily

Processing is carried out solely to process your request.

Legal bases:

  • Art. 6 (1) lit. b GDPR
  • Art. 6 (1) lit. f GDPR

8. Email Infrastructure

We use corresponding mail server services for sending and receiving our emails.

In the course of email communication, technical communication data may be processed and stored. Processing takes place exclusively to ensure reliable email operations.

Legal basis: Art. 6 (1) lit. f GDPR


9. Cookies

No analysis, marketing, or advertising cookies are used on this pre-launch website.

Where technically necessary mechanisms are required to provide individual functions, these are used exclusively within the legally permissible scope.


10. Data Security

We implement appropriate technical and organizational security measures to protect personal data against loss, manipulation, unauthorized access, or other unlawful processing.

This includes in particular:

  • Encrypted data transmission (SSL/TLS)
  • Access restrictions
  • Authentication mechanisms
  • Security and monitoring systems
  • Protection against abuse and cyber attacks

11. Storage Duration

We store personal data only as long as necessary for the respective processing purposes or as required by statutory retention periods.

Pre-registration

Confirmed waitlist data is retained:

  • Until the platform launches,
  • Until a user account is created, or
  • Until the data subject withdraws their consent or requests erasure.

Unconfirmed pre-registrations are automatically and permanently deleted from the database after the 30-minute confirmation window expires via automated background processes (Convex Crons).

Technical Logs

Technical log data is generally stored for a maximum of 7 days in accordance with the current infrastructure configuration.

Backups

Daily backups are created to ensure operational stability. These are currently retained for up to 7 days and subsequently overwritten or deleted.


12. Your Rights

Under the GDPR, you have the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7 (3) GDPR)

To exercise your rights, you can contact us at any time using the contact address provided above.


13. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data.

Competent authorities include in particular the supervisory authority of your habitual residence, place of work, or the place of the alleged infringement.


14. Changes to this Privacy Policy

We reserve the right to adapt this privacy policy if necessary due to technical, legal, or organizational changes.

The current version is available on this website at all times.