The controller for the processing described here is:
Luis Scharf, trading as BirdProxies
Waldstraße 81, 65451 Kelsterbach, Germany
[email protected]
We are not required to appoint a Data Protection Officer under Art. 37 GDPR or § 38 BDSG, and none is appointed. Data protection enquiries go to the address above and are handled by the controller personally.
| Purpose | Legal basis |
|---|---|
| Running your account, delivering the service, billing | Art. 6 (1) (b) GDPR, performance of the contract |
| Invoices, bookkeeping, tax records | Art. 6 (1) (c) GDPR, legal obligation |
| Security, fraud and abuse prevention, keeping the site up | Art. 6 (1) (f) GDPR, legitimate interests |
| Analytics and non-essential cookies | Art. 6 (1) (a) GDPR and § 25 (1) TDDDG, your consent |
| Marketing email | Art. 6 (1) (a) GDPR, your consent, withdrawable at any time |
Where we rely on legitimate interests, our interest is in operating a service that is not abused and stays available. You can object at any time under Art. 21 GDPR.
If you delete your account we remove your personal data except where a retention obligation applies. In that case the data is blocked from further use rather than kept in circulation.
We do not inspect the content of the traffic you route through our proxies beyond what is technically necessary to deliver it.
We do not build browsing profiles, we do not sell traffic data, and we do not hand traffic data to advertisers. Connection metadata that arises technically is processed only to route the connection, to meter the volume you have used, and to detect abuse, and is erased as soon as it is no longer needed for those purposes, in line with § 9 TDDDG.
We may be obliged to disclose data where a competent authority makes a lawful and binding request. We check every such request rather than answering it automatically.
We use the following processors and service providers. Each is bound by a data processing agreement under Art. 28 GDPR:
We do not sell personal data and we do not pass it on for third-party advertising.
Some of the providers above are based in the United States. Transfers are made either on the basis of the EU-U.S. Data Privacy Framework where the provider is certified, or on Standard Contractual Clauses under Art. 46 (2) (c) GDPR together with supplementary measures. You can request a copy of the safeguards from us at any time.
Under the GDPR you have the right to:
Write to [email protected]. We answer within one month.
You also have the right to complain to a supervisory authority. The one responsible for us is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany
Traffic to and from this site is encrypted with TLS. Passwords are stored only as bcrypt hashes. Access to production systems is limited to the controller. These measures are reviewed as the service changes; no measure makes a system perfectly secure, and we do not claim otherwise.
Our services are directed at adults. We do not knowingly collect data from persons under 18. If you believe a minor has given us data, tell us and we will delete it.
We update this policy when the service or the law changes. The current version is always the one on this page, with the date shown below. Material changes affecting registered users are announced by email.