hallo theo GmbH (hereinafter: "we", "us") welcomes you to our website www.buildtheo.com (hereinafter: "Website"). Our principle is to collect only what we need and to process this information solely to provide you with the service you expect.
The controller responsible for the processing of personal data on our website within the meaning of the General Data Protection Regulation (hereinafter: "GDPR") is:
hallo theo GmbH
Saarbrücker Straße 21
10405 Berlin
+49 (0) 30 340 430 00
For data protection-related inquiries or to exercise your data subject rights, you may contact us at any time by email at datenschutz(at)hallotheo.de.
Our appointed Data Protection Officer is:
Kertos GmbH
Brienner Straße 41
80333 München
Email: dataprivacy(at)kertos.io
We use your personal data only where necessary to provide our website and services.
When you visit our website, your browser automatically transmits personal data to our server, where it is stored in a log file.
We collect the following information without any action on your part and store it until it is automatically deleted:
The IP address of your computer
Date and time of your access
The name and URL of the file you retrieve
The website from which you came (referrer URL)
Your browser, possibly the operating system of your computer, and the name of your internet provider
We process this data to:
Ensure a smooth connection to the website
Enable convenient use of our website
Guarantee IT security
Within our company, only those individuals who require access to your personal data for the stated purposes have access to it. Your personal data will only be passed on to external recipients where we are legally permitted to do so or where you have given your consent.
Framer
Purpose: Provision of web hosting services and related services for the management and operation of our website
Recipient: Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, Netherlands
Data processed: Website usage data (e.g. visitor numbers, page views)
Server logs (e.g. IP addresses, access times)
Legal basis: Legitimate interest pursuant to Art. 6(1)(f) GDPR
Retention period: Data is stored for the duration of the contractual relationship and thereafter in accordance with statutory retention obligations
Further information: https://www.framer.com/legal/privacy-statement/
If you contact us by email, we process the personal data you provide (e.g. name, email address, content of your message) exclusively for the purpose of handling and responding to your inquiry. The legal basis for this is generally our legitimate interest in communicating with you pursuant to Art. 6(1)(f) GDPR, or — where your inquiry relates to the conclusion or performance of a contract — the performance of pre-contractual measures or the performance of a contract pursuant to Art. 6(1)(b) GDPR. Your data will be stored only for as long as necessary to process your inquiry. It will not be passed on to third parties unless we are legally required to do so or it is strictly necessary for handling your request.
7. Data Security and Security Measures
We ensure that your personal data remains secure and confidential. To prevent data manipulation, loss, or misuse, we employ technical and organizational security measures, which we regularly review and update to keep pace with technological developments.
Please note that other individuals or institutions on the internet may disregard data protection rules. Unencrypted data in particular, such as emails, may be accessible to third parties. We have no control over this. Please protect your data through encryption or other measures to prevent misuse.
8. Data Retention
Personal data is deleted or blocked once the purpose for which it was stored no longer applies. Storage may continue if required by European or national law. Data is also blocked or deleted when the statutory retention period expires, unless the data is required in connection with a contract.
9. Rights of Data Subjects
You have the following rights with regard to your personal data:
a) Right of access: You may find out whether we process your personal data. If so, you have the right to know what data is involved, why we use it, who receives it, and how long we retain it.
b) Right to rectification: You may request that incorrect data be corrected promptly. You may also have incomplete data completed.
c) Right to erasure: You may request that we delete your data. This applies where it is no longer necessary, where you withdraw your consent, or where the data has been processed unlawfully.
d) Right to restriction of processing: You may request that we restrict the processing of your data, for example where it is inaccurate.
e) Right to data portability: You may receive your data in a commonly used, machine-readable format.
f) Right to object: You may object to the processing of your data at any time, particularly in the case of direct marketing. This also applies to profiling for advertising purposes.
g) Right to withdraw consent: You may withdraw your consent to the use of your data at any time with effect for the future. The lawfulness of processing carried out prior to withdrawal remains unaffected.
Complaints: You may lodge a complaint with a supervisory authority if you believe your rights have been infringed.
10. Change History
08.07.26 Version 1.0: First version of the revised privacy notice