1. Data Controller
The data controller responsible for the processing of your personal data is:
Goldbach Financial GmbH
Seligenstädter Straße 100
63791 Karlstein a. Main
Deutschland
Email: support@goldbach-financial.org
Telephone: +49 6188 306300
2. Personal Data We Collect
We may collect the following categories of personal data when you use our website or contact us:
- Contact information: name, email address, postal address, and telephone number provided via our contact form or direct communications.
- Enquiry data: the content of any message or enquiry you submit to us.
- Technical data: IP address, browser type and version, operating system, referring URLs, pages visited, and timestamps, collected automatically via server logs and cookies.
- Cookie data: preferences and session information stored via cookies as described in our Cookie Policy.
3. Purposes and Legal Bases for Processing
We process your personal data on the following legal bases and for the following purposes:
- Responding to enquiries (Article 6(1)(b) GDPR – contractual necessity / pre-contractual steps): When you contact us, we process your contact details and the content of your message in order to respond to your enquiry.
- Website operation and security (Article 6(1)(f) GDPR – legitimate interests): We process technical data for the purpose of operating, maintaining, and securing our website. Our legitimate interest is the secure and efficient functioning of our online service.
- Compliance with legal obligations (Article 6(1)(c) GDPR): Where required by German or EU law, we may process personal data to fulfil our legal obligations.
- Consent (Article 6(1)(a) GDPR): Where you have given explicit consent — for example, in relation to non-essential cookies — we process your data on that basis. You may withdraw consent at any time.
4. How We Use Your Data
We use collected personal data solely for the purposes described above. We do not use your personal data for automated decision-making or profiling. We do not sell, rent, or share your personal data with third parties for marketing purposes.
5. Data Sharing and Recipients
We may share your personal data with the following categories of recipients where necessary:
- Hosting and infrastructure providers: Our website is hosted by a third-party provider acting as a data processor under a data processing agreement (DPA). The provider operates within the EU/EEA and is bound by GDPR obligations.
- Email service providers: Where we use a third-party email platform to manage communications, that provider acts as a data processor under a DPA.
- Legal and regulatory authorities: We may disclose data to competent authorities where required by law or in response to lawful requests.
We do not transfer personal data to third countries outside the EU/EEA unless adequate safeguards are in place in accordance with Chapter V of the GDPR.
6. Retention Periods
We retain personal data only for as long as is necessary for the purposes for which it was collected:
- Contact enquiry data is retained for up to 24 months from the date of last correspondence, unless a longer period is required by applicable law.
- Technical log data is typically retained for 30 days.
- Cookie data is retained in accordance with our Cookie Policy.
After the applicable retention period, personal data is securely deleted or anonymised.
7. Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights with respect to your personal data:
- Right of access (Article 15): You have the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of that data.
- Right to rectification (Article 16): You have the right to have inaccurate personal data corrected and incomplete data completed.
- Right to erasure (Article 17): You have the right to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, or where processing is unlawful.
- Right to restriction of processing (Article 18): You have the right to request that we restrict the processing of your personal data in certain circumstances.
- Right to data portability (Article 20): Where processing is based on consent or a contract and is carried out by automated means, you have the right to receive your personal data in a structured, machine-readable format.
- Right to object (Article 21): You have the right to object to processing based on our legitimate interests.
- Right to withdraw consent (Article 7(3)): Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing prior to withdrawal.
To exercise any of these rights, please contact us at support@goldbach-financial.org. We will respond within one month of receiving your request.
8. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority. The competent supervisory authority for Goldbach Financial GmbH is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Postfach 3163
65021 Wiesbaden
Deutschland
Website: datenschutz.hessen.de
9. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. These measures are reviewed regularly and updated as necessary.
10. Links to Third-Party Websites
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites and recommend that you review their privacy policies independently.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The date of the most recent revision will always be indicated at the top of this page. We encourage you to review this policy periodically.
12. Contact
If you have any questions about this Privacy Policy or the way we handle your personal data, please contact us:
Goldbach Financial GmbH
Seligenstädter Straße 100
63791 Karlstein a. Main
Deutschland
Email: support@goldbach-financial.org
Telephone: +49 6188 306300