Skip to content

Draft. This page has not been approved yet and is not legally binding.

ULTIDO
Back to overview

Trust Center Privacy Notice

Draft – subject to legal review before publication.

This is a convenience translation. Only the German version is binding.

This notice applies to the Trust Center at trust.ultido.com. Under Art. 13 GDPR, it explains which personal data we process when you visit the Trust Center, request access to confidential documents or subscribe to notices. Our park apps and ultido.com have their own privacy notices.

1 Controller

ULTIDO GmbH, Rommerskirchener Straße 21, 50259 Pulheim, Germany, represented by its managing director Maximilian Lucas Arbeiter. Email: privacy@ultido.com.

2 Data protection contact

For data protection questions, contact privacy@ultido.com.

3 Processing in detail

3.1 Visiting the pages

When you visit the pages, our hosting provider processes technically necessary data: IP address, date and time, requested address, browser identifier and status code. The purpose is to deliver the pages securely and to fend off attacks. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is secure operation. We do not use analytics or marketing tools on these pages.

3.2 Access request and sign-in

For an access request we process your name, business email address, company, the documents requested and the stated purpose. You confirm your email address with a one-time code or sign-in link. The purpose is to review and handle your request. The legal basis is Art. 6(1)(b) GDPR (pre-contractual steps and the non-disclosure agreement).

3.3 Acceptance of the non-disclosure agreement

When you accept the non-disclosure agreement, we store as evidence your name, email address, company, the date and time of acceptance, the IP address, the browser identifier, the text of the acceptance checkbox, and the version and checksum of the agreement. The legal bases are Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR; our legitimate interest is evidencing the conclusion of the agreement and enforcing it.

3.4 Providing the documents

Every document we provide carries a watermark containing your email address, company, the time and an identifier. We log when and from which IP address a document was retrieved. The purpose is to protect our trade secrets and to trace unauthorised disclosure. The legal basis is Art. 6(1)(f) GDPR.

3.5 Notices about changes

You can subscribe to notices about subprocessors, certifications and security incidents. For this we process your email address, the topics you choose and the record of your consent (time, IP address, consent text). You confirm the subscription via a link in an email. The legal basis is your consent under Art. 6(1)(a) GDPR, which you can withdraw at any time via the unsubscribe link in every notice. Customers with whom we have concluded a data processing agreement are informed through the contact persons named in the contract; the legal basis for this is Art. 6(1)(f) GDPR; our legitimate interest is meeting our notification obligations under the data processing agreement.

3.6 Abuse protection

To protect the forms against automated requests we use [PLACEHOLDER: method and provider, data, seat, transfer]. The method neither stores information on your device nor reads information from it. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is protection against abuse. [LAWYER REVIEW: confirm no device access; otherwise consent under section 25(1) TDDDG]

3.7 Cookies and local storage

We store on your device only what is technically required for sign-in (a session cookie). Under section 25(2) no. 2 TDDDG no consent is required for this.

4 Recipients

4.1 Vercel Inc., USA – hosting and delivery of the pages. The functions run in Frankfurt am Main (fra1). Vercel is a US company; platform services such as network, logs and support may involve processing in the US.

4.2 Supabase Inc. – database, sign-in and document storage. The data is stored in the EU (Frankfurt am Main, eu-central-1).

4.3 [PLACEHOLDER: email provider per decision 1 – currently Resend, Inc., USA; stored data is held in the US] – sending sign-in codes, confirmations and notices.

4.4 [PLACEHOLDER: abuse-protection provider, see 3.6].

Data processing agreements under Art. 28 GDPR are in place with all recipients. [PLACEHOLDER: publish only once every one of these agreements is signed]

5 Transfers to third countries

Where data is transferred to or accessible from the US, we rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the recipient is certified, and additionally on Standard Contractual Clauses (Implementing Decision (EU) 2021/914). You can obtain a copy of the Standard Contractual Clauses by writing to privacy@ultido.com.

6 Retention

Data Retention
Server logs [PLACEHOLDER: period per Vercel configuration]
Unconfirmed access requests and subscriptions 30 days
Rejected access requests [PLACEHOLDER: period]
Acceptance record of the non-disclosure agreement Term of the agreement, then until the regular limitation period expires (three years from the end of the year in which the term ends, sections 195 and 199 BGB)
Retrieval log (IP address) 12 months
Subscriptions Until withdrawn; the consent record until the end of the third year after the year of withdrawal

7 Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can withdraw consent at any time with effect for the future (Art. 7(3)).

Right to object: Where we process data on the basis of Art. 6(1)(f) GDPR, you can object at any time on grounds relating to your particular situation (Art. 21(1) GDPR).

You can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia.

8 Obligation to provide data

Without your name, email address and company we cannot process an access request. There is no automated decision-making under Art. 22 GDPR; a person decides on access requests.

Last updated: [PLACEHOLDER: approval date]