Legal
Privacy Policy
As of: July 2026
This is a machine translation for convenience. The legally binding version is the German original — read the German version.
1. Controller
Controller within the meaning of the General Data Protection Regulation (GDPR):
SilentLink UG (haftungsbeschränkt)
Heinz-Fangman-Straße 2–6, 42287 Wuppertal, Germany
Represented by the Managing Director Darrel Hozaifeh
Email: info@silentlink.de
2. Overview and legal bases
This statement informs you about how we process personal data when you visit the website silentlink.de (including ordering) and when you use the SilentLink platform (activation, customer account, mediation of messages and calls). We only process what is necessary for the respective purpose. The legal bases are in particular Art. 6(1)(b) GDPR (contract), (f) GDPR (legitimate interest) and (a) GDPR (consent) as well as § 25 TDDDG for the storage of and access to information on your device.
3. Hosting and server log files
Our website is operated by a specialised hosting and content delivery provider that makes the site available and protects it against attacks. In doing so, connection data is automatically processed (in particular IP address, date and time, page accessed, referrer URL as well as browser and operating system information). The basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR); the data is stored only for a short time. For recipients and third countries, see section 10.
4. Cookies and consent
Our website itself does not set any tracking cookies. We store technically necessary information in your browser's local storage (§ 25(2) TDDDG): the content of your shopping cart and your choice in the cookie banner. Services requiring consent (analysis and marketing, see section 7) are only loaded after your consent via the cookie banner (Art. 6(1)(a) GDPR, § 25(1) TDDDG); after your consent, these services may set their own cookies or similar identifiers for measurement and marketing purposes. You can adjust or withdraw your consent at any time with effect for the future: Open cookie settings.
5. Shop, ordering and payment
For the catalogue, shopping cart and checkout we use an e-commerce platform. During the ordering process we process the data required for processing (order data, name, address, email address, payment information) on the basis of Art. 6(1)(b) GDPR. Payment is made via the payment methods offered at checkout (including credit card, PayPal, Klarna as well as wallet payments); your payment data is processed directly by the respective payment service provider. In the case of purchase on account or in instalments, a credit check may be carried out by the payment service provider.
6. Customer reviews
Verified customer reviews may be embedded on product pages. For this we use a review service that processes the order reference, name or abbreviation and review content (Art. 6(1)(f) GDPR). The reviews are embedded statically; when the page is loaded, no transmission to the service takes place.
7. Analysis and marketing
For reach measurement, web analysis as well as for marketing and social media purposes, we use corresponding services — but exclusively with your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). Only after your consent via the cookie banner are these loaded; in doing so, pseudonymous usage and event data (e.g. page views, interactions, truncated IP address, device information) is processed and, in part, hashed contact data is transmitted to marketing partners. For individual marketing services, there is joint controllership with the provider (Art. 26 GDPR).
Which specific services and providers are used in detail can be seen in the cookie settings; there you can withdraw your consent at any time with effect for the future.
8. Contact and forms
When you contact us by email or via our contact and enquiry forms, we process your information (in particular email address, request, optionally name or company) in order to process your enquiry and send you a confirmation of receipt (Art. 6(1)(b) or (f) GDPR). For sending emails we use a dispatch service provider as a processor.
If you use our online withdrawal function (Cancel contract), we process the data provided there to process your withdrawal and to fulfil our statutory obligation to promptly confirm receipt (Art. 6(1)(b) and (c) GDPR). The data is deleted as soon as it is no longer required and no statutory retention obligations preclude this.
9. SilentLink platform (customer account, activation and mediation)
A core function of our products is the anonymous mediation of contact: whoever scans a contact code never sees your contact data at any time; the transmission takes place exclusively via our platform to the channel you have chosen. For the use of the platform we process your account and contact data (in particular name, email address and the stored contact channels) as well as the information you voluntarily store for your product (Art. 6(1)(b) GDPR).
Mediation of messages and calls. If a finder gets in touch via a contact code, we process the content of the report as well as the contact data voluntarily provided in the process in order to deliver the message to you via the chosen channel (Art. 6(1)(b) and (f) GDPR). For delivery we use specialised communication service providers. In the case of anonymous calls, your phone number remains hidden from the caller; we store callers' phone numbers exclusively in pseudonymised (hashed) form.
Scan notification and location. If a contact code is scanned, we inform the owner about the scan. This notification may contain an approximate location at city level that is estimated from the IP address of the scanning device; this is pointed out on the scan page (Art. 6(1)(f) GDPR). Your exact location (GPS) is only transmitted if you actively release it on the scan page (Art. 6(1)(a) GDPR); the release is voluntary. To convert a released location into an address, we use a map service.
Misuse and fraud prevention. When scanning, we process technical information about the access (including IP address, browser and device information as well as characteristics for detecting misuse) for security and fraud detection (Art. 6(1)(f) GDPR); for this we use a corresponding service provider. We store this data for this purpose for a maximum of three months.
Paid plans. If you conclude a paid plan, we process payment and invoicing via a payment service provider (Art. 6(1)(b) GDPR). We retain invoices within the scope of the statutory retention obligations.
Emergency and health information. Insofar as you voluntarily store special categories of personal data (such as emergency or health information) for certain products so that these can be displayed if needed, we process these exclusively on the basis of your explicit consent and because you yourself designate this information for display (Art. 9(2)(a) and (e) GDPR). You are responsible for the content you enter; you can change or delete it at any time.
10. Recipients and transfer to third countries
We only pass on personal data insofar as this is necessary for the stated purposes — in particular to carefully selected processors (categories: hosting/IT operations, communication, payment, shipping, map, analysis and marketing service providers) with whom data processing agreements under Art. 28 GDPR exist, as well as to bodies to which we are legally obliged to disclose. Insofar as data is thereby transferred to countries outside the EU/EEA (in particular the USA), this is safeguarded by appropriate guarantees — as a rule EU standard contractual clauses or a certification under the EU-US Data Privacy Framework. We will provide you with an overview of the processors used on request.
11. Storage period
We store personal data only for as long as it is necessary for the respective purposes or statutory retention obligations exist (in particular under commercial and tax law, 6 or 10 years). On the platform, we generally delete finder reports and associated histories after 30 days and technical data for misuse prevention after three months at the latest. If you delete your account, we remove your personal data after a withdrawal period of 30 days; documents to be retained by law (in particular invoices) remain unaffected.
12. Your rights
You have the following rights under the GDPR:
- Access (Art. 15), rectification (Art. 16), erasure (Art. 17) and restriction (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
- Complaint to a supervisory authority (Art. 77 GDPR) — competent for us: State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia
13. Changes
We adapt this statement when the data processing or the legal situation changes; the version published here at any given time applies.