Data privacy

Data privacy

Last updated: 09.07.2026

hallo theo GmbH (hereinafter: "we", "us") welcomes you to our website www.buildtheo.com (hereinafter: "Website"). Our principle is to collect only what we need and to process this information solely to provide you with the service you expect.

1. Controller

1. Controller

The controller responsible for the processing of personal data on our website within the meaning of the General Data Protection Regulation (hereinafter: "GDPR") is:


hallo theo GmbH

Saarbrücker Straße 21

10405 Berlin

+49 (0) 30 340 430 00

support(at)hallotheo.de


For data protection-related inquiries or to exercise your data subject rights, you may contact us at any time by email at datenschutz(at)hallotheo.de.

2. Data Protection Officer

2. Data Protection Officer

Our appointed Data Protection Officer is:

Kertos GmbH

Brienner Straße 41

80333 München

Email: dataprivacy(at)kertos.io

3. What Is Personal Data?

3. What Is Personal Data?

Personal data is any information relating to an identified or identifiable natural person. This includes, for example, your name, age, address, telephone number, date of birth, email address, or IP address. Information that we cannot (or can only with disproportionate effort) link to your person — for example through anonymization — does not constitute personal data. The processing of personal data (e.g. collection, retrieval, use, storage, or transmission) always requires a legal basis, such as your consent.

Personal data is any information relating to an identified or identifiable natural person. This includes, for example, your name, age, address, telephone number, date of birth, email address, or IP address. Information that we cannot (or can only with disproportionate effort) link to your person — for example through anonymization — does not constitute personal data. The processing of personal data (e.g. collection, retrieval, use, storage, or transmission) always requires a legal basis, such as your consent.

4. Data Processing for the Provision and Use of the Website

4. Data Processing for the Provision and Use of the Website

We use your personal data only where necessary to provide our website and services.

When you visit our website, your browser automatically transmits personal data to our server, where it is stored in a log file.


We collect the following information without any action on your part and store it until it is automatically deleted:

  • The IP address of your computer

  • Date and time of your access

  • The name and URL of the file you retrieve

  • The website from which you came (referrer URL)

  • Your browser, possibly the operating system of your computer, and the name of your internet provider


We process this data to:

  • Ensure a smooth connection to the website

  • Enable convenient use of our website

  • Guarantee IT security

4.2 Legal Basis

4.2 Legal Basis

We process this data on the basis of Art. 6(1)(f) GDPR. The data listed must be processed in order to provide the website and to enable its secure and convenient use. This is in the legitimate interest of our company.

We process this data on the basis of Art. 6(1)(f) GDPR. The data listed must be processed in order to provide the website and to enable its secure and convenient use. This is in the legitimate interest of our company.

4.3 Retention Period and Data Deletion

4.3 Retention Period and Data Deletion

The data collected is deleted as soon as it is no longer required for the website. This occurs no later than 30 days after collection. The collection and storage of data are necessary to operate the website; therefore, the user cannot object to this processing. In certain cases, we store data for longer periods where required by law.

The data collected is deleted as soon as it is no longer required for the website. This occurs no later than 30 days after collection. The collection and storage of data are necessary to operate the website; therefore, the user cannot object to this processing. In certain cases, we store data for longer periods where required by law.

5. Recipients of Personal Data

5. Recipients of Personal Data

Within our company, only those individuals who require access to your personal data for the stated purposes have access to it. Your personal data will only be passed on to external recipients where we are legally permitted to do so or where you have given your consent.

5.1 Services for the Provision of the Website

5.1 Services for the Provision of the Website

Framer

Purpose: Provision of web hosting services and related services for the management and operation of our website

Recipient: Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, Netherlands

Data processed: Website usage data (e.g. visitor numbers, page views)

Server logs (e.g. IP addresses, access times)

Legal basis: Legitimate interest pursuant to Art. 6(1)(f) GDPR

Retention period: Data is stored for the duration of the contractual relationship and thereafter in accordance with statutory retention obligations

Further information: https://www.framer.com/legal/privacy-statement/

6. Contact by Email

6. Contact by Email

If you contact us by email, we process the personal data you provide (e.g. name, email address, content of your message) exclusively for the purpose of handling and responding to your inquiry. The legal basis for this is generally our legitimate interest in communicating with you pursuant to Art. 6(1)(f) GDPR, or — where your inquiry relates to the conclusion or performance of a contract — the performance of pre-contractual measures or the performance of a contract pursuant to Art. 6(1)(b) GDPR. Your data will be stored only for as long as necessary to process your inquiry. It will not be passed on to third parties unless we are legally required to do so or it is strictly necessary for handling your request.

7. Data Security and Security Measures

We ensure that your personal data remains secure and confidential. To prevent data manipulation, loss, or misuse, we employ technical and organizational security measures, which we regularly review and update to keep pace with technological developments.


Please note that other individuals or institutions on the internet may disregard data protection rules. Unencrypted data in particular, such as emails, may be accessible to third parties. We have no control over this. Please protect your data through encryption or other measures to prevent misuse.

8. Data Retention

Personal data is deleted or blocked once the purpose for which it was stored no longer applies. Storage may continue if required by European or national law. Data is also blocked or deleted when the statutory retention period expires, unless the data is required in connection with a contract.

9. Rights of Data Subjects

You have the following rights with regard to your personal data:


a) Right of access: You may find out whether we process your personal data. If so, you have the right to know what data is involved, why we use it, who receives it, and how long we retain it.

b) Right to rectification: You may request that incorrect data be corrected promptly. You may also have incomplete data completed.

c) Right to erasure: You may request that we delete your data. This applies where it is no longer necessary, where you withdraw your consent, or where the data has been processed unlawfully.

d) Right to restriction of processing: You may request that we restrict the processing of your data, for example where it is inaccurate.

e) Right to data portability: You may receive your data in a commonly used, machine-readable format.

f) Right to object: You may object to the processing of your data at any time, particularly in the case of direct marketing. This also applies to profiling for advertising purposes.

g) Right to withdraw consent: You may withdraw your consent to the use of your data at any time with effect for the future. The lawfulness of processing carried out prior to withdrawal remains unaffected.

Complaints: You may lodge a complaint with a supervisory authority if you believe your rights have been infringed.

10. Change History

08.07.26 Version 1.0: First version of the revised privacy notice

Copyright hallo theo GmbH 2026

Copyright hallo theo GmbH 2026

Copyright hallo theo GmbH 2026