Privacy Policy

Last updated: August 6, 2026

This privacy policy explains how we collect, use, and protect your personal data in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG).

1. Data Controller

The data controller responsible for your personal data is:

Emil Lienemann

Sole proprietor (Einzelunternehmer)

Warschauer Straße 23

10243 Berlin, Germany

Email: hi@talktweak.com

Phone: +49 15905042802

2. Personal Data We Collect

When you use our emergency contact service, we may collect the following categories of personal data:

2.1 Information You Provide

  • Contact Information: Name, email address, phone number
  • Emergency Details: Description of the technical issue, urgency level, preferred contact method
  • Payment Information: Credit card details (processed securely through our payment processor)
  • Communication Data: Content of your messages and communications with us

2.2 Automatically Collected Information

  • Technical Data: IP address, browser type, device information, operating system

3. Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contract Performance (GDPR Art. 6(1)(b)): Processing necessary to provide emergency technical support services you have requested
  • Consent (GDPR Art. 6(1)(a)): Where you have given explicit consent for specific processing activities (e.g., marketing communications)
  • Legal Obligation (GDPR Art. 6(1)(c)): Where processing is required by German or EU law (e.g., tax and accounting requirements)
  • Legitimate Interests (GDPR Art. 6(1)(f)): For fraud prevention, security, and improvement of our services, where such interests are not overridden by your rights

4. Purpose of Processing

We use your personal data for the following purposes:

  • Providing emergency technical support services
  • Processing payments and maintaining financial records
  • Communicating with you about your service requests
  • Sending service-related notifications and updates
  • Improving our services and user experience
  • Preventing fraud and ensuring security
  • Complying with legal obligations (tax, accounting, etc.)

5. Recipients of Personal Data

We may share your personal data with the following categories of recipients:

  • Stripe: Payment processing, fraud prevention, and payment records. Stripe receives your billing email, payment information, urgency level, and up to 500 characters of the issue description as PaymentIntent metadata. We do not store complete credit card details ourselves.
  • Twilio: Delivery of emergency SMS messages and automated phone calls. Twilio receives the destination and sender phone numbers, your email address, urgency level, charge amount, and excerpts from your issue description.
  • Resend: Delivery of emergency email alerts. Resend receives your email address, urgency level, charge amount, payment status, and issue description.
  • Vercel: Website hosting and serverless infrastructure. Vercel may process technical request data such as IP address, browser information, access time, and server logs in order to deliver and secure the service.
  • Legal Authorities: When required by law or to protect our legal rights

All third-party service providers are carefully selected and required to maintain appropriate security measures and comply with GDPR requirements. We ensure data processing agreements are in place where required.

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy:

  • Service Request Data: Retained for 3 years after the service is completed for customer support and quality assurance purposes
  • Payment and Financial Records: Retained for the applicable statutory retention period under German tax and commercial law
  • Communication Records: Retained for 3 years for customer service and dispute resolution purposes
  • Technical Logs: Retained for up to 12 months for security and system maintenance purposes
  • Marketing Consent: Until you withdraw consent or after 2 years of inactivity

After the retention period expires, personal data is securely deleted or anonymized.

7. International Data Transfers

Your personal data may be transferred to and processed in countries outside the EU/EEA. When we transfer data internationally, we ensure appropriate safeguards are in place:

  • EU Standard Contractual Clauses (SCCs)
  • Adequacy decisions by the European Commission
  • Binding Corporate Rules or certification mechanisms

You have the right to request information about the safeguards we have implemented for international transfers.

8. Your Rights

Under the GDPR and the German Federal Data Protection Act, you have the following rights regarding your personal data:

8.1 Right of Access

You have the right to request a copy of the personal data we hold about you and information about how we process it.

8.2 Right to Rectification

You have the right to request correction of inaccurate or incomplete personal data.

8.3 Right to Erasure

You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected or if you withdraw consent.

8.4 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.

8.5 Right to Restriction of Processing

You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data or object to processing.

8.6 Right to Object

You have the right to object to processing based on legitimate interests or for direct marketing purposes.

8.7 Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw your consent at any time. This does not affect the lawfulness of processing before withdrawal.

8.8 How to Exercise Your Rights

To exercise any of these rights, please contact us at hi@talktweak.com. We will respond to your request within one month of receipt. This period may be extended by two months where necessary, taking into account the complexity and number of requests.

9. Security Measures

We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

  • Encryption of data in transit and at rest (SSL/TLS, AES-256)
  • Access controls and authentication mechanisms
  • Regular security assessments and updates
  • Secure backup and disaster recovery procedures
  • Employee training on data protection and security
  • Confidentiality agreements with staff and contractors
  • Monitoring and logging of access to systems

10. Cookies and Tracking Technologies

We do not use analytics or advertising cookies. Stripe may use technically necessary cookies or similar technologies to process payments, prevent fraud, and secure the checkout flow. These technologies are required to provide the payment function you request.

11. Automated Decision-Making and Profiling

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you. If this changes, we will update this privacy policy and inform you accordingly.

12. Children's Privacy

Our services are not intended for children under 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

13. Changes to This Privacy Policy

We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated policy on our website with a new "Last updated" date. Your continued use of our services after such changes constitutes acceptance of the updated policy.

14. Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with the law, you have the right to lodge a complaint with the competent supervisory authority in Berlin:

Berlin Commissioner for Data Protection and Freedom of Information

Alt-Moabit 59-61

10555 Berlin, Germany

Website: www.datenschutz-berlin.de

Email: mailbox@datenschutz-berlin.de

Phone: +49 30 13889-0

15. Contact Us

If you have any questions about this privacy policy or our data processing practices, please contact us:

Emil Lienemann

Sole proprietor (Einzelunternehmer)

Warschauer Straße 23

10243 Berlin, Germany

Email: hi@talktweak.com

Phone: +49 15905042802