Information pursuant to Art. 13 and 14 GDPR
Last updated: September 2026
This translation is provided for information only. Only the German version is legally binding. German version
The controller within the meaning of the General Data Protection Regulation (GDPR) for the processing described in this policy is:
PARPALİ YAZILIM VE BİLİŞİM HİZMETLERİ TİCARET LİMİTED ŞİRKETİ
Beştepe Mah.
Yenimahalle / Ankara, Türkiye
Represented by: Ömer Dural
Email: info@fibreact.com
Phone: +90 552 251 06 53
For questions about data protection, you can reach us at datenschutz@fibreact.com.
We are the controller for the processing of personal data when you visit our website, during registration and contract processing, when sending e-mail information, in support, in the marketplace including the publication of reviews, and when handling enquiries and notices.
Personal data that our customers process with FibreAct – such as data of their employees, job and installation data, location data, photos and enquiries via the contact form of a company website – we process as a processor under Art. 28 GDPR on behalf of and on the instructions of the respective customer. The customer company is the controller in this respect. Please address requests concerning these data to the company; if such a request reaches us, we forward it to the company. Sections 13 to 16 additionally describe how the platform processes these data.
When you visit our website and the company websites provided via our platform, we process technically necessary data: IP address, date and time of access, requested address, previously visited page (referrer), browser type and operating system, status code and amount of data transferred.
The processing serves to deliver the website, to ensure security and stability, in particular to defend against attacks, and to analyse errors. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in these purposes. To protect against overload, the IP address is also briefly used in memory to limit requests.
Server log files are generally deleted automatically after four to five weeks. Longer storage only takes place if necessary to investigate a specific security incident.
Fonts and other components of the website are loaded from our own servers. No connections to third-party servers, such as Google Fonts, are established when the website is accessed.
We only use technically necessary cookies and entries in your browser’s local storage, for example for login and to store your language and display settings. Storage and access are based on Section 25 (2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG); further processing is based on Art. 6 (1) (b) and (f) GDPR.
We do not use cookies or similar technologies for analytics, tracking or advertising purposes.
During registration, we process your e-mail address, password (only as a bcrypt hash value), company name, the name of the person acting and voluntary information such as telephone number, tax number and VAT identification number. We send a code by e-mail to confirm the e-mail address. Upon registration, we also store the time and version of the accepted Terms.
During use, we process the data of the users of the customer account as well as log data such as login times to ensure account security.
The legal basis is Art. 6 (1) (b) GDPR (conclusion and performance of the contract) and, for logging, Art. 6 (1) (f) GDPR. The data are stored for the duration of the contract and then deleted unless statutory retention obligations prevent this.
Paid services are processed via Paddle.com Market Limited, Judd House, 18–29 Mora Street, London EC1V 8BT, United Kingdom ("Paddle"). Paddle acts as reseller (merchant of record) and is an independent controller for the processing of payment and invoice data.
We transmit to Paddle the data required for processing, in particular e-mail address, company name and the booked plan. You enter payment data directly with Paddle; we only receive information about the status of subscriptions and payments. The legal basis is Art. 6 (1) (b) GDPR. The European Commission has found that the United Kingdom ensures an adequate level of data protection (Art. 45 GDPR). Further information can be found in Paddle’s privacy policy at paddle.com.
If you contact us by e-mail or telephone, we process your information to handle your request. The legal basis is Art. 6 (1) (b) GDPR where the request relates to a contract, otherwise Art. 6 (1) (f) GDPR. The data are deleted once the request has been finally handled and no statutory retention obligations exist.
We send system notifications such as confirmation codes and account notices via our own mail server in Germany.
With your consent, we send you information about FibreAct by e-mail. Sign-up, for example via a form on our information pages, uses the double opt-in procedure: you only receive messages after confirming your sign-up via the link in our confirmation e-mail. To prove consent, we store the source and time of sign-up and confirmation, the IP address and the browser identifier (user agent). The legal basis for sending is Art. 6 (1) (a) GDPR, and for the proof data Art. 6 (1) (c) in conjunction with Art. 7 (1) GDPR.
If you provided your e-mail address to us in connection with a contract for FibreAct, we may send you information about our own similar services without separate consent (Section 7 (3) of the German Act against Unfair Competition, UWG). The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in direct marketing. You can object to this use at any time without incurring any costs other than transmission costs at basic rates.
You can withdraw your consent at any time with effect for the future and object to the use for advertising at any time, via the unsubscribe link in every e-mail or by e-mail to info@fibreact.com. After unsubscribing, a permanently undeliverable address or a complaint, we store your e-mail address in a suppression list so that you receive no further messages; the legal basis is Art. 6 (1) (c) and (f) GDPR. The other data are deleted after unsubscribing unless still required to prove earlier consent.
Users can contact us via the support chat in the app and in the customer account and by e-mail. We process name, e-mail address, company affiliation, content and time of messages and any files transmitted in order to answer requests; chat and e-mail messages on the same request are combined in one case.
The legal basis is Art. 6 (1) (b) GDPR where the request relates to use of the platform, otherwise Art. 6 (1) (f) GDPR. Histories are deleted when no longer required for handling and any follow-up questions, at the latest 90 days after the end of the customer’s contract, unless statutory retention obligations prevent this.
In the marketplace, the following in particular are visible to other registered customers: company name, logo, areas of operation, services, certificates, published advertisements and reviews. Advertisements can be published without the company name. The marketplace history (category, year and role of completed jobs, without the contracting partner) is only shown if the customer activates it.
The legal basis is Art. 6 (1) (b) GDPR. Where information about sole traders or contact persons is personal data, displaying it to other customers is additionally based on Art. 6 (1) (f) GDPR; our legitimate interest and that of the users lies in initiating business relationships.
Customers with a business relationship verifiable on the platform can review each other. The name of the reviewing company, the individual ratings, the text, the date and any reply are published in the marketplace profile and, if activated, on the company website of the reviewed company. For sole traders, the company name may be personal data.
The legal basis is Art. 6 (1) (b) GDPR in relation to the reviewing customer and Art. 6 (1) (f) GDPR for publication; the legitimate interest lies in informing other companies about experiences with business partners. You can object to publication under Art. 21 GDPR.
Before publication, an automated procedure checks whether texts contain contact details or impermissible expressions. Affected reviews are held back; an employee decides on their publication. No decision based solely on automated processing within the meaning of Art. 22 GDPR takes place.
Reviews are stored until the author deletes them, they are removed after a review, or the reviewing customer’s contract ends.
You can send notices about unlawful content to meldung@fibreact.com. We process your name, e-mail address, the information about the reported content and your justification in order to examine the notice, inform you and the affected company of our decision and handle objections.
The legal basis is Art. 6 (1) (c) GDPR in conjunction with Art. 16 and 17 of Regulation (EU) 2022/2065 (Digital Services Act) and Art. 6 (1) (f) GDPR. We only disclose your identity to the affected company insofar as this is necessary for handling, for example if you assert an infringement of your own rights. The data are deleted three years after the case has been closed.
Company websites under fibreact.de/<name> or under a custom domain are offered by the respective company, which is also the controller for the data processing there and provides its own privacy notice on the website. We provide the websites technically as a processor.
Company websites use no cookies and no analytics or tracking services. Messages sent via the contact form are made available to the company in its customer account and automatically deleted after the period set by the company. To protect against abuse, we store the sender’s IP address only as a non-reversible hash value generated with a secret key.
For company websites under a custom domain, we obtain TLS certificates from the certificate authority Let’s Encrypt (Internet Security Research Group, USA). As usual for all public certificates, the domain name is entered in publicly accessible Certificate Transparency logs. To check DNS records, we query public DNS servers of Cloudflare, Inc. and Google LLC; only the domain name is transmitted.
The following processing takes place on behalf of the respective customer company, which is the controller.
Location data: the mobile app records the device’s location in order to document installation points and assign jobs to the correct work site. In the foreground, recording only takes place while the app is open. Background location recording is not enabled by default; it requires the customer company to activate it and the data subject to grant permission on the device. Permission can be revoked at any time in the device settings. Whether and to what extent location recording of employees is permissible depends on the employment relationship and agreements within the company, such as works agreements; the customer company is responsible for this.
Camera and photos: with your permission, the app accesses the camera and photo library to take and edit documentation photos and assign them to the respective job. Permission can be revoked at any time.
Push notifications: for job and appointment notifications we use Firebase Cloud Messaging from Google. A device-related push token is processed. Notifications can be deactivated in the device settings.
In order to display work site addresses on maps and assign jobs, we transmit address information (street, house number, postcode, town, without names) to the Google Maps Platform, which converts it into coordinates.
If a company uses the translation function for its company website, we transmit the website texts to be translated (such as slogan, description, services, references and image descriptions) to Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA. Contact enquiries, reviews and account data are not transmitted. Anthropic does not use the data to train AI models.
We use the following service providers as processors, who are contractually bound by our instructions:
Independent controllers are Paddle.com Market Limited (payment processing), Apple Inc. and Google LLC as operators of the app stores, and the Internet Security Research Group (Let’s Encrypt). Beyond this, we only disclose data where we are legally obliged to do so, for example to authorities.
The platform data are stored on servers in Germany. Our company has its registered office in Türkiye; there is no adequacy decision of the European Commission for Türkiye. Our employees access the data from Türkiye as required, via encrypted connections, for administration, maintenance and support purposes.
For data that we process as a processor for our customers, this takes place on the basis of the European Commission’s standard contractual clauses agreed with our customers in the data processing agreement (Art. 46 (2) (c) GDPR).
Data that we process as controller are collected directly from you; in doing so, we are directly subject to the GDPR under Art. 3 (2) GDPR. Please note that no level of data protection equivalent to European Union law has been established for Türkiye and that access by public authorities under Turkish law cannot be ruled out.
Google and Anthropic also process data in the USA. The transfers take place on the basis of the European Commission’s standard contractual clauses contained in these providers’ data processing terms (Art. 46 (2) (c) GDPR); insofar as Google Ireland Limited transfers data to Google LLC, additionally on the basis of the EU-US Data Privacy Framework, under which Google LLC is certified (Art. 45 GDPR).
Unless a specific retention period is stated in this policy, we only store personal data for as long as necessary for the respective purpose. After a contract ends, the data are deleted unless statutory retention obligations, in particular under commercial and tax law, prevent this; in that case processing is restricted.
You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR). Where processing is based on consent, you can withdraw it at any time with effect for the future (Art. 7 (3) GDPR); the lawfulness of processing carried out before withdrawal remains unaffected. Please contact datenschutz@fibreact.com.
Right to object under Art. 21 GDPR: you have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6 (1) (f) GDPR. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. You can object at any time, without giving reasons, to the processing of your data for direct marketing; the data will then no longer be processed for this purpose.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.
The information provided during registration is required to conclude the contract; without it we cannot set up a customer account. Otherwise, you are not obliged to provide us with personal data.
No decision-making based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR takes place.
We adapt this privacy policy when the legal situation or our processing changes. The version published on this page applies.