As of: July 19, 2026
The protection of your personal data is important to us. With this
Privacy Policy, we inform you about which personal data we process when you
visit our website, for what purposes the processing takes place, on which
legal bases we rely, and what rights you are entitled to.
Personal data is any information relating to an identified or
identifiable natural person. This includes, for example, your name, email address,
IP address, device identifiers, and the content of messages.
This Privacy Policy applies to the publicly accessible website
interlir.com. Supplementary privacy notices may apply to
separate customer portals, registration, contractual, payment, or KYC processes.
The controller for the processing of personal data on this website is:
InterLIR GmbH
Josef-Orlopp-Straße 54
10365 Berlin
Germany
Phone:
+49 30 700142706
Email:
[email protected]
We have appointed an external Data Protection Officer:
DataGAP GmbH
Mr. Markus Altenburg
Bessemerstraße 82
12103 Berlin
Germany
Phone:
+49 30 577 10 513
Email:
[email protected]
Depending on the nature and purpose of the respective processing, we rely
in particular on the following legal bases:
Insofar as information is stored on your terminal equipment or already
stored information is accessed, the requirements of Section 25 TDDDG apply additionally.
Storage and access that are strictly necessary from a technical perspective can be
based on Section 25(2) TDDDG. For cookies, identifiers, and comparable
technologies that are not strictly necessary, we generally obtain consent pursuant to
Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR.
In principle, we store personal data only as long as necessary for the
respective processing purpose.
If no specific retention period is stated for a particular processing
operation, we delete the data when:
Statutory commercial and tax retention obligations as well as retentions
for the establishment, exercise, or defense of legal claims remain unaffected.
Our website is hosted in a virtual server environment managed by us at
Amazon Web Services. To the best of our current knowledge, the server resources
are located in the AWS region eu-central-1 within the European Union.
We operate a self-managed WordPress installation, including the associated
database, on this server. Amazon Web Services provides the technical infrastructure.
The administration of the server, the WordPress installation, and the database is
carried out by InterLIR GmbH or by persons authorized by us.
The provider for customers in the European Economic Area is generally:
Amazon Web Services EMEA SARL
38 Avenue John F. Kennedy
L-1855 Luxembourg
In the context of hosting, the following data in particular may be processed:
The processing is carried out for the purpose of technical provision, secure and
stable operation, maintenance, and error analysis of our website.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest consists in the
secure, stable, and economic provision of our website. Insofar as the processing
is necessary for the performance of a contract or to take steps prior to entering
into a contract, Art. 6(1)(b) GDPR is the legal basis.
Amazon Web Services processes data partly on our behalf within the framework of
providing the infrastructure. The data protection conditions of Amazon Web Services
integrated into the contractual relationship apply to this processing.
Access from countries outside the European Union or the European Economic
Area cannot be completely ruled out, particularly in the context of support,
security, or administrative services. Third-country transfers only take place in
compliance with Art. 44 et seq. GDPR.
To ensure that our website is provided securely, stably, and quickly, we
use services from Cloudflare. Cloudflare is used in particular as a DNS service,
reverse proxy, content delivery network, caching, and security layer.
Data traffic to the areas of our website provided via Cloudflare is technically
routed through Cloudflare’s infrastructure. Cloudflare may process the following
data in particular:
The processing serves to ensure the availability, security, and performance
of our website, to detect and prevent attacks and abusive access, and to
deliver content efficiently.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest consists in protecting
our website from attacks, ensuring stable operation, and providing content quickly.
The provider is:
Cloudflare, Inc.
101 Townsend Street
San Francisco, California 94107
USA
Cloudflare processes data partly on our behalf. The data protection conditions
of Cloudflare integrated into the contractual relationship apply to this processing.
Cloudflare operates a globally distributed infrastructure. Therefore, it cannot be
ruled out that data is also processed outside the European Union or the European
Economic Area. Such transfers are carried out in compliance with Art. 44 et seq. GDPR.
We have not set up separate storage of HTTP or WAF logs via Cloudflare Log
Explorer. Independently of this, Cloudflare may process technical traffic,
security, and metadata in the context of providing its services. The retention
period depends on the specific service used, the contractual terms, and technical
requirements.
When you access our website, technical access data is automatically
processed. This may include, in particular, the following data:
The processing is carried out to technically provide our website, ensure its
stability and security, detect errors, and fend off abusive or unauthorized
access.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest consists in the
secure, stable, and error-free operation of our website.
The data is deleted or anonymized as soon as it is no longer required for the
stated purposes, unless longer storage is necessary for security reasons, to
investigate an incident, or due to statutory obligations.
Our website uses TLS encryption to protect the transmission of confidential
content. You can recognize an encrypted connection in particular by the use
of “https://” in your browser’s address bar.
Despite appropriate technical and organizational measures, complete security
of electronic data transmissions cannot be guaranteed.
Our website uses cookies and similar technologies, including entries in the
local storage of the browser. Cookies are small pieces of information that
can be stored on or read from your terminal equipment.
We use technically necessary technologies insofar as they are required to
provide the website, its security functions, and the functions explicitly
requested by you.
This may include, in particular, technologies for storing your cookie settings,
session management, defense against attacks, and the technical provision of the
website.
The storage or access is carried out, provided the legal requirements are met,
on the basis of Section 25(2) TDDDG. The subsequent processing of personal
data is carried out on the basis of Art. 6(1)(b) or (f) GDPR, depending on the
purpose.
Analytical, advertising, and other technologies that are not strictly necessary
are generally used on the basis of your prior consent.
The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR. You can
withdraw or change your consent at any time with effect for the future via the
cookie settings.
The lawfulness of the processing carried out on the basis of your consent up
to the time of withdrawal remains unaffected by the withdrawal.
We use the WordPress plugin Real Cookie Banner to obtain,
manage, and document consent for cookies, similar technologies, and services
that are not strictly necessary. The plugin also enables us to block such
services until the required consent has been given.
Real Cookie Banner is operated locally within our WordPress installation.
Consent data is stored in our website database and is not transmitted to the
plugin manufacturer merely because the consent tool is used.
In this context, the following information in particular may be processed and
documented:
Real Cookie Banner stores technically necessary cookies or comparable browser
storage entries, in particular entries whose names begin with
real_cookie_banner. These entries are used to associate your
browser with the stored consent decision, apply your selection, and avoid
requesting the same decision again on every page view. The default storage
period may be up to 365 days, depending on our current configuration.
The processing is necessary to comply with our legal obligations to obtain and
demonstrate valid consent and to respect your selection. The legal basis is
Art. 6(1)(c) GDPR. To the extent that the processing also serves the reliable
operation and administration of the consent mechanism, Art. 6(1)(f) GDPR
applies; our legitimate interest is the legally compliant and technically
reliable management of consent. Storage of or access to information on your
terminal equipment is based on Section 25(2) TDDDG because it is strictly
necessary to provide the consent management function requested and to record
your privacy choice.
You can change or withdraw your selection at any time with effect for the
future by opening the cookie settings available on our website. Withdrawal is
as easy as giving consent. The lawfulness of processing carried out before the
withdrawal remains unaffected.
We use the WordPress plugin Polylang to provide our website in
several languages and to display the appropriate language version.
Depending on the configuration and your use of the language switcher, Polylang
may store a first-party cookie named pll_language. This cookie
stores the language selected by you or determined for the website so that the
corresponding language version can be displayed during subsequent visits.
The cookie does not serve advertising or cross-site tracking purposes. It is
usually stored for up to one year, subject to the current technical
configuration of the website.
Storage and access are based on Section 25(2) TDDDG because the language cookie
is required to provide the language version expressly selected by you. To the
extent that personal data is processed, the legal basis is Art. 6(1)(f) GDPR.
Our legitimate interest consists in providing a consistent multilingual
website and retaining the language selection made by visitors.
Some pages of our website contain embedded videos from YouTube. YouTube is a
service provided in the European Economic Area by:
Google Ireland Limited
Gordon House, Barrow Street
Dublin 4
Ireland
The embedded YouTube player is blocked by our consent management system until
you give consent to the corresponding service. Before consent, only a local
placeholder or content blocker should be displayed and no connection to
YouTube should be established through the embedded player.
After you give consent and activate or load the video, your browser establishes
a connection to Google and YouTube servers. In particular, the following data
may then be processed:
Google may use the data to provide the video, ensure security, prevent fraud,
measure use, improve its services, and, depending on your Google settings and
the embedding configuration, personalize content or advertising.
The storage of or access to information on your terminal equipment and the
subsequent processing of personal data take place only on the basis of your
consent pursuant to Section 25(1) TDDDG and Art. 6(1)(a) GDPR. You can withdraw
or change your consent at any time with effect for the future via the cookie
settings.
Where technically implemented, videos may be embedded using YouTube’s
privacy-enhanced mode via the domain youtube-nocookie.com.
This reduces certain storage before interaction but does not replace the need
to block the player until consent where data is transmitted to Google or
information is stored on or accessed from the terminal equipment.
Google may process data in the United States and other countries outside the
European Union and the European Economic Area. Such transfers take place in
compliance with Art. 44 et seq. GDPR, in particular on the basis of an
applicable adequacy decision or appropriate safeguards such as the European
Commission’s standard contractual clauses.
The retention period is determined by Google and depends on the type of data,
the purpose of processing, the applicable Google account settings, and whether
the data is aggregated or deleted by the user.
We use Google Analytics 4, a web analysis service provided by:
Google Ireland Limited
Gordon House, Barrow Street
Dublin 4
Ireland
Google Analytics is used on our website with the measurement ID
G-Y6NRVCFSS1.
Google Analytics enables us to evaluate the use of our website and to
compile reports on website activity. In this context, the following data
in particular may be processed:
Enhanced event measurement in Google Analytics is enabled. A separate
cross-device User-ID is not currently used by us. Furthermore, we have not
enabled any function for transmitting user-provided contact data, such as
email addresses or phone numbers, to Google Analytics.
Google Analytics uses cookies and similar technologies to recognize users,
devices, and sessions. According to the current configuration of our consent
management, Google Analytics is not loaded if analytical cookies are rejected.
The legal bases for the use of Google Analytics are Section 25(1) TDDDG and
Art. 6(1)(a) GDPR.
You can withdraw or change your consent at any time with effect for the
future via the cookie settings.
In our Google Analytics configuration, a retention period of two months is
set for certain event data. Certain user-related data can be stored for up
to 14 months.
In the event of renewed activity, the retention period for user-related data
can start again. The retention settings do not necessarily affect all
aggregated standard reports.
In the context of using Google Analytics, it cannot be ruled out that data is
also transmitted to Google LLC or other Google-affiliated companies in the United States.
Third-country transfers take place in compliance with Art. 44 et seq. GDPR,
in particular on the basis of an adequacy decision or appropriate safeguards
such as standard contractual clauses.
Technical components of Google’s advertising and delivery infrastructure may
be loaded on our website. This may include, in particular, domains and
services used by Google for the delivery, quality assurance, fraud prevention,
or measurement of advertising content.
The provider is generally Google Ireland Limited. In the context of this
processing, the following data in particular may be processed:
Insofar as cookies or comparable technologies that are not strictly necessary
are used here, the legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
Insofar as processing is carried out exclusively to ensure security, prevent
fraud, or for technical transmission, the processing may additionally be
based on Art. 6(1)(f) GDPR. Our legitimate interest consists in the secure
and abuse-free provision of the website.
Google may also process data outside the European Union or the European
Economic Area. Third-country transfers take place in compliance with
Art. 44 et seq. GDPR.
We use the Intercom Messenger on our website to provide visitors and users
with a contact and support option via live chat. The messenger is generally
available on all pages of our website and can also be used by non-registered
visitors.
The provider is:
Intercom R&D Unlimited Company
2nd Floor, Stephen Court
18–21 St. Stephen’s Green
Dublin 2
Ireland
Intercom processes personal data partly as a processor on our behalf.
The data protection conditions of Intercom integrated into the contractual
relationship apply to this processing.
When accessing our website and using the messenger, the following data in
particular may be processed:
For non-registered visitors, the initial assignment is generally carried out
using anonymous identifiers. If you share your name, email address, company,
or other information in the course of a conversation, this data will also be
processed in connection with your inquiry.
Processing is carried out in particular to:
The Intercom Messenger uses cookies and entries in the local storage of our
website. According to the current technical configuration, these include in
particular:
The standard retention period for the session identifier is generally seven
days. The device identifier can generally be stored for up to 270 days and
extended upon renewed activity. Entries in local storage can remain until
deleted by the user, the browser, or a technical function.
According to the current technical configuration, the Intercom Messenger is
loaded as soon as the website is accessed. Technical connection data and
Intercom identifiers may therefore be processed before you actively start a
conversation.
Insofar as you actively use the messenger and send us an inquiry, processing
is carried out to handle your inquiry.
If your inquiry relates to the initiation or performance of a contract,
Art. 6(1)(b) GDPR is the legal basis.
For general contact and support inquiries, Art. 6(1)(f) GDPR is the legal
basis. Our legitimate interest consists in the efficient processing of inquiries,
the organization of our customer communication, and the secure operation of
our support system.
Insofar as Intercom stores information on your terminal equipment or reads
already stored information and consent is legally required for this,
Section 25(1) TDDDG and Art. 6(1)(a) GDPR are the applicable legal bases.
The content of conversations and associated contact data are stored as long
as necessary to process your inquiry, document customer communication, fulfill
contractual or statutory obligations, or for the establishment, exercise, or
defense of legal claims.
Storage beyond this only takes place if there is a statutory basis for doing so.
Intercom may use additional sub-processors to provide the service. Processing
in the United States or other countries outside the European Union and the
European Economic Area cannot be completely ruled out.
Third-country transfers take place in compliance with Art. 44 et seq. GDPR,
in particular on the basis of an adequacy decision or appropriate safeguards
such as standard contractual clauses.
You can delete Intercom cookies and entries in the local storage via the
settings of your browser. This may cause the assignment to previous
conversations to be lost.
To exercise your data protection rights, you can also contact
[email protected].
When you contact us by email, phone, or via the Intercom Messenger, we
process the details you provide to handle and answer your inquiry.
This may include, in particular, the following data:
If the contact is made in connection with an existing or potential
contractual relationship, Art. 6(1)(b) GDPR is the legal basis.
For other business inquiries, processing is carried out on the basis of
Art. 6(1)(f) GDPR. Our legitimate interest consists in processing and
answering your inquiry.
The data will be deleted when the inquiry has been conclusively processed and
there are no statutory retention obligations, contractual requirements, or
legitimate grounds for further storage.
Fonts may be loaded via Google servers on our website. When such a font is
loaded, your browser establishes a connection to Google servers.
In this context, the following data in particular may be processed:
The provider is Google Ireland Limited. Processing by Google LLC or other
Google-affiliated companies in the United States cannot be completely ruled out.
Insofar as the external provision of fonts is not technically strictly
necessary, it takes place on the basis of your consent pursuant to
Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
Insofar as no information is stored on or read from your terminal equipment,
the data transmission may additionally be based on Art. 6(1)(f) GDPR. Our
legitimate interest consists in a uniform, readable, and technically reliable
presentation of our website.
Our website may load JavaScript libraries, in particular jQuery, via an
external Content Delivery Network. This may establish a connection between
your browser and the server of the respective CDN provider.
In this context, your IP address, browser and device information, the page
accessed, the time of retrieval, and technical connection data may be processed.
The processing is carried out for the technical provision of website functions.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest consists in the
stable, secure, and efficient provision of the website.
Insofar as information is stored on or read from your terminal equipment in
this context, the requirements of Section 25 TDDDG apply additionally.
Our website is operated using the open-source software WordPress. WordPress
is installed on our own server environment operated at Amazon Web Services and
is administered by us or authorized service providers.
The mere use of the self-hosted WordPress software does not automatically
lead to a transmission of personal data to WordPress.com or Automattic.
Individual WordPress functions may load external resources. This may include,
in particular, resources for displaying emojis from WordPress.org.
When retrieving such resources, the respective external provider may receive
your IP address, browser information, the page accessed, and the time of retrieval.
The processing is carried out for the technically correct presentation of the
website content. The legal basis is Art. 6(1)(f) GDPR. Insofar as information
is stored on or read from your terminal equipment, the requirements of
Section 25 TDDDG apply additionally.
Our website contains links to external websites and services, in particular
to social media platforms, messengers, registries, and other specialized offers.
When a standard link is merely displayed, no data is generally transferred to
the operator of the linked website. Only when you click on the link do you
leave our website. The operator of the external website may then process your
IP address, technical connection data, and, if applicable, the previously
visited page.
The operator of the external website is responsible for data processing on
that website.
Within InterLIR GmbH, only those persons receive access to personal data who
require this access to perform their tasks.
Furthermore, personal data may be transmitted to the following categories
of recipients:
Insofar as a service provider processes personal data on our behalf, we enter
into a data processing agreement pursuant to Art. 28 GDPR or integrate
corresponding contractual terms into the contractual relationship.
Some of the service providers we use may process personal data outside the
European Union and the European Economic Area.
A third-country transfer only takes place if the requirements of Art. 44 et
seq. GDPR are met. The following may be considered as a basis for transfer:
The applicable basis depends on the respective service provider and the
specific processing.
Exclusively automated decision-making within the meaning of Art. 22 GDPR,
including profiling, which produces legal effects concerning you or similarly
significantly affects you, does not take place in connection with the publicly
accessible website, unless expressly stated otherwise for a specific processing
operation.
The provision of personal data when visiting the website is generally voluntary.
However, certain technical data is processed automatically because the website
cannot otherwise be provided securely and functionally.
Insofar as certain data is required for the processing of an inquiry, for the
initiation or performance of a contract, or to fulfill statutory obligations,
the respective service may not be provided without this data.
Under the statutory conditions, you have the following rights in particular:
You can withdraw any consent you have given at any time with effect for the
future. The withdrawal does not affect the lawfulness of the processing
carried out on the basis of your consent up to the time of withdrawal.
You can change or withdraw consent to cookies and comparable technologies via
the cookie settings on our website.
If we process personal data on the basis of Art. 6(1)(f) GDPR, you have the
right, under Art. 21 GDPR, to object to the processing at any time on grounds
relating to your particular situation. This also applies to profiling based
on this provision.
Following an objection, we will no longer process the data concerned unless
we can demonstrate compelling legitimate grounds for the processing which
override your interests, rights, and freedoms, or for the establishment,
exercise, or defense of legal claims.
Where personal data is processed for direct marketing purposes, you have the
right to object at any time to the processing of personal data concerning you
for such marketing. This also applies to profiling to the extent that it is
related to such direct marketing. After your objection, your personal data
will no longer be processed for these purposes.
You have the right to lodge a complaint with a data protection supervisory
authority if you consider that the processing of your personal data violates
the GDPR.
The supervisory authority responsible for InterLIR GmbH is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
You can also contact the data protection supervisory authority of your
habitual residence, your place of work, or the place of the alleged
infringement.
To exercise your data protection rights, you can contact us or our Data
Protection Officer directly:
Email:
[email protected]
Data Protection Officer:
[email protected]
To avoid unauthorized disclosure, we may request additional information
necessary to confirm your identity.
We may adjust this Privacy Policy if our processing activities, the services
used, or the legal requirements change.
The current version published on this website applies in each case. You can
find the date of the last update at the beginning of this Privacy Policy.