As of: August 9, 2026
InterLIR GmbH takes the protection of personal data seriously. This Privacy Policy explains which personal data we process when you use the publicly accessible website interlir.com, the purposes for which processing occurs, the legal bases we rely on, which recipients may be involved, how long data is stored, and what rights you have.
Personal data means any information relating to an identified or identifiable natural person. This can include, in particular, name, email address, IP address, device or session identifiers, as well as the content of a communication.
This Privacy Policy applies to the publicly accessible website as well as its contact, newsletter, email marketing, and support functions. Insofar as an email address collected through the InterLIR customer portal, account registration, or an existing customer relationship is used for newsletter or direct marketing purposes, Section 14 of this Privacy Policy applies to that use. Separate privacy notices may apply to other processing associated with the customer portal, user accounts, contractual services, payments, KYC and compliance checks, or other processing activities outside of the publicly accessible website.
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
InterLIR GmbH
Josef-Orlopp-Straße 54
10365 Berlin
Germany
Phone: +49 30 700142706
Email: [email protected]
We have appointed an external Data Protection Officer:
DataGAP GmbH
Mr. Markus Altenburg
Bessemerstraße 82
12103 Berlin
Germany
Phone: +49 30 577 10 513
Email: [email protected]
Depending on the purpose and circumstances of the processing, we rely in particular on the following legal bases:
Insofar as information is stored in your end-user equipment or access is gained to information already stored in your end-user equipment, Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG – Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz) additionally applies. Storage or access that is strictly necessary to provide a digital service explicitly requested by you or to carry out the transmission of a communication is conducted on the basis of Section 25(2) TDDDG. Cookies, local storage entries, identifiers, and comparable technologies that are not strictly necessary are deployed only following prior consent pursuant to Section 25(1) TDDDG. Insofar as personal data is processed in the process, we generally base the subsequent processing on Art. 6(1)(a) GDPR.
We store personal data only for as long as necessary for the respective purpose. Specific storage periods are specified below where possible. Upon expiry of a period, data is deleted or irreversibly anonymized, provided that further storage is not required or permitted by law, such as due to commercial or tax law retention obligations, an ongoing security incident, or to establish, exercise, or defend legal claims.
The withdrawal of consent takes effect for the future. An effective objection terminates processing based on legitimate interests, unless compelling legitimate grounds exist or the processing serves the establishment, exercise, or defense of legal claims.
The website and the associated database are operated in a self-administered WordPress environment on infrastructure located in the AWS Europe (Frankfurt) region, identifier eu-central-1. The AWS contracting party regularly responsible for customers in the European Economic Area is:
Amazon Web Services EMEA SARL
38 Avenue John F. Kennedy
L-1855 Luxembourg
Luxembourg
InterLIR GmbH administers the server environment, the WordPress installation, and the database. AWS provides the underlying cloud infrastructure and acts as a processor insofar as personal data is processed on our behalf. The relevant data protection terms and the Data Processing Addendum of AWS apply to this processing.
When accessing and operating the website, the following data in particular may be processed:
We process this data to establish connections to the website, provide requested content, ensure availability and integrity, detect and resolve errors, defend against attacks and unauthorized access, administer the website, and perform backup and recovery operations.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests lie in the secure, reliable, efficient, and error-free operation of the website as well as the protection of our systems. Insofar as hosted data is processed to handle a contractual or pre-contractual request, Art. 6(1)(b) GDPR additionally applies.
Standard server access and error logs are generally deleted or irreversibly anonymized after 30 days. Relevant entries may be stored for longer if necessary to investigate a specific security incident, prevent further abuse, fulfill a legal obligation, or establish, exercise, or defend legal claims. The extended storage ends as soon as the additional purpose ceases to apply.
Encrypted website and database backups are retained in a rotating backup system for up to 180 days and subsequently overwritten or securely deleted. Backups serve exclusively recovery, availability, security, and business continuity purposes, not routine operational processing. If a backup is restored, the applicable deletion, restriction, objection, and retention rules are re-applied to the restored environment.
Primary website workloads are configured for the Frankfurt region. Limited processing or access outside the European Union or the European Economic Area cannot be excluded insofar as necessary for support, service administration, security, sub-processors, or compliance with binding legal obligations. Third-country transfers occur only in accordance with Art. 44 et seq. GDPR, in particular on the basis of an applicable adequacy decision or the Standard Contractual Clauses of the European Commission and, where necessary, supplementary safeguards.
We use Cloudflare as a DNS service, reverse proxy, content delivery network, caching, and security service. Requests to areas routed via Cloudflare pass through Cloudflare’s network before reaching our origin server.
Cloudflare, Inc.
101 Townsend Street
San Francisco, California 94107
United States
Cloudflare may process in particular the following data:
The processing serves domain resolution, connection forwarding, efficient content delivery and caching, load reduction, availability, attack mitigation, abuse prevention, as well as the investigation of technical or security incidents. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests lie in the secure, stable, and efficient provision of the website and protection against attacks and abuse.
Cloudflare acts as a processor insofar as it processes traffic, cached content, logs, and security metadata on our behalf. The relevant data protection terms and the Data Processing Addendum of Cloudflare apply. Cloudflare operates a globally distributed network. Therefore, it cannot be guaranteed that all traffic, decryption, or metadata processing occurs exclusively within the EEA.
Third-country transfers take place in accordance with Art. 44 et seq. GDPR. Depending on the recipient and processing, transfers may be based on an applicable adequacy decision, including the EU-U.S. Data Privacy Framework for appropriately certified recipients, or on Standard Contractual Clauses and supplementary safeguards.
Cloudflare stores traffic, network, performance, and security metadata for the timeframes applicable to the deployed services and current account configuration. We store data made available to us only for as long as necessary for administration, troubleshooting, security monitoring, or incident investigation.
Cloudflare security features may deploy cookies or similar technologies to distinguish legitimate users from automated or abusive traffic, maintain security checks, enable load balancing, or protect the website. The specific technologies deployed, purposes, and storage durations are specified in the cookie settings. Strictly necessary security technologies are based on Section 25(2) TDDDG. Technologies requiring consent are activated only after consent pursuant to Section 25(1) TDDDG and, insofar as personal data is processed, Art. 6(1)(a) GDPR.
The website uses TLS encryption to protect data transmitted between your browser and our systems. An encrypted connection is usually recognizable by “https://” in the address bar. Despite appropriate technical and organizational measures, absolute security of electronic transmissions cannot be guaranteed.
We use cookies and comparable browser storage technologies. Strictly necessary technologies are deployed only insofar as necessary to transmit communications, provide the website or a function explicitly requested by you, maintain security, or store your privacy choices. Access to the end-user equipment in these cases is based on Section 25(2) TDDDG. Subsequent processing of personal data relies on Art. 6(1)(b), (c), or (f) GDPR depending on the purpose.
Analytics functions, support chat identifiers, and other non-essential technologies are used only following prior consent pursuant to Section 25(1) TDDDG and Art. 6(1)(a) GDPR. You can change or revoke your selection at any time with effect for the future via the cookie settings. Revocation is as easy as granting consent.
We use the locally operated WordPress plugin Real Cookie Banner to obtain, manage, and document consents and to block non-essential services prior to consent. The plugin and the associated consent database are operated within our own WordPress environment. No consent data is transmitted to the manufacturer of the plugin merely through the deployment of the consent tool.
Depending on current configuration, the following information in particular may be processed and documented:
Real Cookie Banner uses first-party cookies or local storage entries whose names typically begin with real_cookie_banner. They link the browser to the documented decision, apply the selection, and avoid prompting for the same decision on every page view. The specific storage duration depends on the configuration used and is displayed in the cookie settings; it can be up to 365 days.
We base the server-side documentation of consent on Art. 6(1)(c) GDPR in conjunction with accountability and proof obligations under Art. 5(2) and Art. 7(1) GDPR. Art. 6(1)(f) GDPR may additionally apply for the reliable administration of the consent mechanism and defense against legal claims. Our legitimate interest lies in legally compliant and technically reliable consent management. Storage on or access to end-user equipment to store your privacy choice is based on Section 25(2) TDDDG insofar as strictly necessary to provide and remember this selection.
Server-side proof of consent is generally retained until the end of the third calendar year following the calendar year in which consent was revoked, replaced, or otherwise terminated, unless longer storage is required due to specific litigation or a legal obligation. This storage serves accountability and the establishment, exercise, or defense of legal claims.
We use the locally installed WordPress plugin Polylang to provide the website in multiple languages. Polylang may set a first-party cookie named pll_language to store your chosen language and present the same language version upon subsequent visits. Under current configuration, the cookie is stored for up to one year and is not used for advertising or cross-site tracking.
Storage and access are based on Section 25(2) TDDDG insofar as the cookie serves the language function explicitly selected by you. Insofar as personal data is processed, Art. 6(1)(f) GDPR forms the legal basis. Our legitimate interest lies in the consistent provision of a multilingual website.
We use Google Analytics 4 exclusively after you have consented to the use of analytics technologies. Provider is:
Google Ireland Limited
Gordon House, Barrow Street
Dublin 4
Ireland
Our Measurement ID is G-Y6NRVCFSS1.
Google Analytics remains blocked as long as no consent for analytics technologies is given or if consent has been rejected. We do not use a cross-site User ID and do not transmit user-provided contact details such as email addresses or phone numbers to Google Analytics.
Upon consent, the following data in particular may be processed:
We use Google Analytics to measure and understand website usage, identify potential technical and content improvements, and generate aggregated evaluations. Legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
The retention period for event and user data in our current Google Analytics configuration is set to two months. This setting does not necessarily result in the deletion of data already included in aggregated standard reports. Specific cookies, browser storage technologies, and respective lifespans are specified in the cookie settings.
Google processes analytics data on our behalf pursuant to applicable data protection terms. Processing by Google LLC or other Google entities in the United States cannot be ruled out. Third-country transfers take place in accordance with Art. 44 et seq. GDPR, in particular based on an applicable adequacy decision, including the EU-U.S. Data Privacy Framework insofar as recipients and processing are covered, or based on European Commission Standard Contractual Clauses and supplementary safeguards.
We use Intercom Messenger as a live chat and support channel. The Messenger is not activated, sets no Intercom identifiers, and transmits no visitor data to Intercom before you have consented to the support chat service via the cookie settings.
Intercom R&D Unlimited Company
124 St Stephen’s Green
Dublin 2, D02 C628
Ireland
Intercom acts as a processor insofar as conversation contents, contact details, identifiers, attachments, and associated support data are processed on our behalf. The relevant data protection terms and the Data Processing Addendum of Intercom apply.
Upon activation and during use, the following data in particular may be processed:
We process this data in particular to:
The Intercom Messenger includes an AI-based support assistant labeled as Tiffany [AI]. At the latest at the start of the first interaction, it is made clear and distinguishable that you are interacting with an AI system. The assistant generates responses based on your message, relevant conversation context, released support materials, service documentation, and other knowledge sources provided by InterLIR.
AI-generated responses may be incomplete, outdated, or inaccurate. They do not constitute binding contractual, legal, financial, KYC, compliance, abuse, or availability decisions. You may request handoff to a human support agent at any time. Matters requiring substantial assessment will be processed or reviewed by authorized personnel.
The assistant is not used to make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR.
Please do not transmit passwords, authentication credentials, payment card data, private keys, special categories of personal data within the meaning of Art. 9 GDPR, or information not necessary for handling your inquiry in the Messenger.
Activation of the Messenger and deployment of its non-essential cookies and local storage identifiers are based on your consent pursuant to Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
As soon as you send an inquiry, processing is conducted on the basis of Art. 6(1)(b) GDPR insofar as necessary for the performance of a contract or pre-contractual measures at your request. General business and support inquiries, secure operation, spam and abuse prevention, internal routing, and quality assurance are based on Art. 6(1)(f) GDPR. Our legitimate interests lie in efficient and consistent support, prompt response times, secure operation, protection against abuse, and the documentation and improvement of customer communication.
Authorized personnel may review conversations and AI responses for support, troubleshooting, security, and quality assurance. We do not use identifiable or merely pseudonymous conversation content to train general external AI models. Insofar as Intercom engages external model providers for AI features, their processing is governed by the data protection terms agreed with Intercom and the current sub-processor configuration.
When creating internal examples for evaluation or improvement, we first remove or replace information that can identify a person. Working copies that remain identifiable or pseudonymized are access-restricted and deleted or effectively anonymized within 90 days of selection. Content containing credentials, payment information, private keys, special categories of personal data, or data that cannot be reliably separated from an identifiable person will not be used for this purpose.
The selection, review, and de-identification of suitable content are based on Art. 6(1)(f) GDPR. Our legitimate interests lie in the reliability, security, accuracy, and quality of support. You may object on grounds relating to your particular situation by contacting [email protected].
Depending on the current Intercom configuration, the following first-party identifiers in particular may be used:
The specific cookies or local storage entries used, their purposes, and lifespans are displayed in the cookie settings according to the current website and Intercom configuration. You can clear browser data via your browser functions. This may end the active session or remove the association of the browser with previous conversations; conversation contents already stored in Intercom or other systems are not automatically deleted thereby.
Intercom may automatically delete inactive visitor records that have not been seen for nine months, provided no user, customer, or conversation record exists requiring further storage.
Conversations concerning an active customer, account, service, or contract are stored for the duration of the relationship and as long as open inquiries, obligations, complaints, security matters, or disputes exist. Upon final resolution, relevant communications are generally retained until the end of the third calendar year following the year of resolution, unless a shorter period suffices or longer retention is required.
Individual messages or attachments may be retained, where statutory classification and requirements are met, in particular for six years as other commercial records subject to retention, eight years as accounting vouchers, or ten years as commercial books, inventories, opening balance sheets, annual financial statements, or comparable documents. Data required for pending or reasonably foreseeable legal claims may be stored until final resolution of the matter and expiry of relevant limitation periods.
Closing or archiving a conversation is not equivalent to final deletion. Deletion from active systems may require additional time before taking effect on protected provider backups. Remaining backup copies are not used for normal operations and are deleted or overwritten according to applicable backup retention schedules.
Depending on the Intercom features and hosting options used, Intercom entities and sub-processors may provide services for hosting, storage, databases, real-time communication, content delivery, security, logging, support, and AI processing. For selected AI features, external model and infrastructure providers may be involved. The specific list of sub-processors is subject to change and is monitored under contractual arrangements with Intercom.
Processing may take place in the United States and other countries outside the EEA, particularly when selected AI, infrastructure, or support features are provided outside a regional hosting environment. Third-country transfers take place pursuant to Art. 44 et seq. GDPR, in particular based on an applicable adequacy decision or European Commission Standard Contractual Clauses and, where necessary, supplementary safeguards.
You may revoke your consent to the support chat with effect for the future via the cookie settings. This prevents future activation of the Messenger; already stored communications are not automatically deleted thereby. You may request human support directly in the Messenger or via our other contact channels. To exercise your data protection rights, please use the contact details in Section 21.
When you contact us via a website form, email, telephone, or Messenger, we process the information required to handle and answer your request. This may include in particular name, email address, phone number, company, subject, message content, attachments, and technical communication metadata.
If the request concerns an existing or prospective contract, Art. 6(1)(b) GDPR forms the legal basis. We process other business inquiries based on Art. 6(1)(f) GDPR. Our legitimate interest lies in receiving, organizing, and answering inquiries and transparently documenting business communications. Insofar as a form requests consent for a separate, voluntary purpose, that processing is based on Art. 6(1)(a) GDPR.
For the technical sending and receiving of certain website and business communications, we use a Google/Gmail connection integrated in WordPress via WP Mail SMTP. The provider for customers in the EEA is generally:
Google Ireland Limited
Gordon House, Barrow Street
Dublin 4
Ireland
In this context, sender and recipient addresses, subject lines, message contents, headers, delivery status, and technical metadata may be processed. The legal basis depends on the purpose of the respective message, being in particular Art. 6(1)(b) GDPR for contract-related or pre-contractual communication, and Art. 6(1)(f) GDPR for other business communication and reliable technical email dispatch.
Processing by Google LLC or other Google entities in third countries cannot be ruled out. Transfers take place in accordance with Art. 44 et seq. GDPR, in particular based on an applicable adequacy decision, including the EU-U.S. Data Privacy Framework where applicable, or Standard Contractual Clauses and supplementary safeguards.
Inquiries that do not lead to a customer relationship are generally deleted or effectively anonymized no later than the end of the third calendar year following the year in which the inquiry was conclusively resolved, and earlier if further storage is no longer necessary. Statutory retention obligations, security matters, and legal claims remain unaffected. For Intercom communications, the special timeframes in Section 12.8 apply additionally.
We may send email communications containing IPv4 market insights and analysis, marketplace and service updates, selected IPv4 purchase or lease offers, technical tools and resources, industry news, articles, information about InterLIR services, and relevant company updates. These communications may be sent as periodic newsletters or as individual marketing or customer-update emails.
Marketing communications are separate from operational or transactional emails that are necessary for account administration, authentication and security, contractual performance, service delivery, compliance, KYC, abuse handling, billing, transactions, or the processing of an inquiry. Confirmation of an email address for account activation, authentication, or security purposes does not by itself constitute consent to receive marketing communications.
You may voluntarily subscribe to InterLIR marketing communications through a newsletter registration form or, where offered, by making a separate voluntary selection in the InterLIR portal or another InterLIR interface. Marketing consent is not required merely to create or maintain a portal account or to use a service for which such consent is not necessary.
Where marketing communications are based on consent, the legal basis for processing your email address and related subscription information is Art. 6(1)(a) GDPR. For advertising by electronic mail, we obtain prior explicit consent where required pursuant to Section 7(2) No. 2 of the German Unfair Competition Act (UWG – Gesetz gegen den unlauteren Wettbewerb).
Where we use a double opt-in procedure, you receive a confirmation email at the address provided after submitting the subscription request. The address is activated for consent-based marketing only after the confirmation step has been successfully completed. The confirmation message serves to verify the subscription and does not itself constitute a marketing newsletter.
A confirmation performed solely to verify a portal account, customer account, login, authentication process, or contact address is separate from newsletter double opt-in and does not by itself constitute consent to marketing.
In certain cases, we may use an email address obtained directly from an existing customer in connection with the sale of an InterLIR good or service to send direct advertising for our own similar goods or services without obtaining separate marketing consent, but only where all requirements of Section 7(3) UWG are satisfied.
This means, in particular, that the email address must have been obtained in connection with the relevant customer relationship, the address may be used only for direct advertising of InterLIR’s own similar goods or services, the customer must not have objected to such use, and the customer must have been clearly informed when the address was collected, and again in every marketing communication, that they may object to the use of the address for direct marketing at any time without costs other than transmission costs according to the basic tariffs.
Where these requirements are fulfilled, the associated processing of personal data is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in informing existing customers about our own services, offers, developments, market information, and resources that are sufficiently related to or similar to the services forming the existing customer relationship. We take into account the nature and duration of the customer relationship, the similarity and relevance of the advertised services, the content and frequency of communications, the reasonable expectations of the recipient, and the unrestricted right to object to direct marketing.
Mere registration of a portal account, creation of a user profile, or confirmation of an email address does not by itself establish the conditions for marketing under Section 7(3) UWG. Where the requirements of Section 7(3) UWG are not fulfilled, we send promotional newsletters or comparable marketing emails only where another valid legal basis exists, in particular valid consent.
We document information necessary to determine and demonstrate why an email address is eligible to receive marketing communications. The information recorded depends on the applicable legal basis.
For consent-based marketing, this may include the email address, date and time of the subscription request and confirmation, source page or interface, website language, version and wording of the consent declaration, confirmation status, and technical information necessary for the secure operation and documentation of the double opt-in procedure. An IP address alone is not treated as sufficient proof of marketing consent.
For existing-customer marketing under Section 7(3) UWG, documentation may include the customer or account identifier, when and how the email address was obtained, the relevant customer transaction or service relationship, the category of goods or services forming that relationship, the marketing information and objection notice provided when the address was collected, the applicable version of that notice, and the current objection or suppression status. We may also document the assessment that the advertised InterLIR goods or services are sufficiently similar to the goods or services forming the existing customer relationship.
This documentation serves accountability, compliance with applicable marketing and data protection requirements, prevention of unauthorized marketing, and the establishment, exercise, or defense of legal claims. Depending on the documentation concerned, the legal bases are Art. 6(1)(c) GDPR in conjunction with applicable accountability and proof obligations, including Art. 5(2) and Art. 7(1) GDPR where consent is relied upon, and Art. 6(1)(f) GDPR. Our legitimate interests include demonstrating lawful marketing eligibility, reliably honoring objections and withdrawals, and defending against legal claims.
We use Twilio SendGrid to send double opt-in confirmation emails where applicable, manage marketing recipients and suppressions, honor unsubscribes and objections, and dispatch newsletters and other marketing communications via SendGrid Marketing Campaigns, Single Sends, or comparable SendGrid functionality.
For a company based in Germany or the EEA, the relevant Twilio contracting party under current Twilio terms is:
Twilio Ireland Limited
70 Sir John Rogerson’s Quay
Dublin 2, D02 R296
Ireland
In the context of the email marketing service, your email address, marketing eligibility or legal-basis status where required for list management, subscription or customer-source information where necessary, confirmation status, objection and suppression status, message and delivery information, and technical identifiers and metadata regarding transmission and, where separately permitted, interaction with emails may be processed. Detailed evidence supporting marketing eligibility may remain in InterLIR systems rather than being transferred to SendGrid where SendGrid does not require it for the dispatch function.
Insofar as Twilio processes this data on our behalf, processing is conducted based on a Data Processing Agreement pursuant to Art. 28 GDPR. Twilio entities and sub-processors may also process data outside the EEA. Third-country transfers occur in accordance with Art. 44 et seq. GDPR and applicable transfer mechanisms, in particular an adequacy decision or European Commission Standard Contractual Clauses and supplementary safeguards.
Twilio SendGrid provides optional functions for recipient-specific open and click tracking. Individual InterLIR mailings may be configured without such recipient-specific tracking. Where open tracking is disabled, we do not intentionally use a tracking pixel to determine whether an individual recipient has opened that mailing. Where click tracking is disabled, newsletter links are not intentionally rewritten by SendGrid for the purpose of recording recipient-specific click events.
Where recipient-specific open or click tracking is enabled for a particular marketing communication, an HTML email may contain a small transparent image that can register retrieval of the message, and links may be routed through a tracking address that can register a click. Depending on the technical process, this may involve the processing of the email recipient or campaign identifier, date and time, requested tracking resource or link, IP address, browser or device information, and related technical metadata.
We use recipient-specific open or click tracking only where the required prior consent has been obtained. Insofar as personal interaction data is processed for these purposes, the legal basis is Art. 6(1)(a) GDPR. Insofar as tracking technologies store information in end-user equipment or access information stored there, consent pursuant to Section 25(1) TDDDG is additionally required where applicable. A newsletter subscription, portal account, or existing-customer relationship alone does not constitute consent to recipient-specific open or click tracking.
Metrics on opens and clicks do not always reliably reflect actual individual recipient behavior. Email providers, security systems, anti-spam filters, link scanners, caching mechanisms, or privacy features may automatically retrieve images, pre-screen links, or trigger other technical operations that can be registered as interactions.
Independently of recipient-specific open and click tracking, technical email delivery information may be processed insofar as necessary for the operation, security, and reliability of the dispatch system. This may include successful or delayed deliveries, bounces, invalid addresses, spam complaints, unsubscribes, objections, and suppression status.
We use this information to ensure reliable delivery, protect the security and reputation of the sending infrastructure, avoid repeated delivery attempts to invalid addresses, prevent unauthorized or unwanted marketing, and reliably honor withdrawals, objections, and unsubscribes. The legal basis is generally Art. 6(1)(f) GDPR. Our legitimate interests lie in the secure and reliable operation of email dispatch and the avoidance of unsolicited messages. Insofar as storage is required to comply with a legal obligation or to ensure observance of a withdrawal or objection, Art. 6(1)(c) GDPR may additionally apply.
Where marketing communications are based on your consent, you may withdraw that consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
Where personal data is processed for direct marketing purposes on the basis of Art. 6(1)(f) GDPR, you have the right to object to such processing at any time. If you object to processing for direct marketing purposes, your personal data will no longer be processed for those purposes.
You may withdraw consent or object to marketing by using the unsubscribe link contained in every marketing email or by contacting us using the details provided in this Privacy Policy. We do not require you to state a reason for a direct-marketing objection. Unsubscribing or objecting must not incur costs other than transmission costs according to the basic tariffs and is implemented without unnecessary obstacles.
Following withdrawal, objection, or unsubscribe, your email address will no longer be used for the marketing communications covered by that request. We may store limited suppression information necessary to ensure that your choice is respected and that further marketing is not sent contrary to your withdrawal or objection.
If you later voluntarily subscribe again to consent-based marketing and, where applicable, successfully complete double opt-in, that confirmation constitutes new consent for future marketing within the scope described at the time of subscription. A marketing suppression based on a previous withdrawal may be lifted only where the new consent is validly documented. Technical blocks resulting from bounces, invalid addresses, security restrictions, or spam complaints are not automatically lifted by re-subscription.
Unconfirmed consent-based newsletter registrations are not used for newsletter marketing. Where a double opt-in confirmation link is configured to remain valid for 48 hours, unconfirmed registration records are generally deleted no later than seven days after the request, unless temporary longer storage is required to investigate abuse, security incidents, or technical errors.
For consent-based marketing, the email address and active subscription status are stored until you withdraw consent, unsubscribe, or the relevant marketing activity is otherwise terminated. For existing-customer marketing under Section 7(3) UWG, the email address is used for marketing only for as long as the statutory requirements remain fulfilled, the relevant customer relationship and similarity of the advertised services continue to support such use, and no objection has been made.
Proof of consent may be retained after withdrawal or termination generally until the end of the third calendar year following the calendar year of termination, insofar as necessary to fulfill accountability and proof obligations or to establish, exercise, or defend legal claims. This further storage is not based on the withdrawn consent, but on the legal bases applicable to the documentation and defense of claims.
Documentation necessary to demonstrate eligibility for existing-customer marketing may likewise be retained for an appropriate period after the final marketing use or termination of eligibility, generally until the end of the third calendar year following the relevant calendar year, insofar as necessary to demonstrate compliance with applicable requirements or to establish, exercise, or defend legal claims.
Suppression information required to enforce a withdrawal, unsubscribe, or direct-marketing objection may be stored for as long as necessary to reliably prevent further marketing contrary to the recipient’s choice. Suppression information is not used to send further advertising.
The website contains ordinary links to external websites and services, including social networks, messengers, registries, and technical resources. The mere display of a standard link does not result in a data transfer to the external operator. If you click such a link, you leave our website. The external operator may then process your IP address, connection data, and, depending on browser settings and technical design, information regarding the previously visited page. The respective external operator is responsible for subsequent processing.
Within InterLIR GmbH, access to personal data is granted only to individuals who require such access for their respective tasks. Depending on the processing activity, recipients or processors may include providers for hosting, cloud infrastructure, security, IT, analytics, consent management, communication, email dispatch, support, legal counsel, tax, compliance, and auditing. In addition, courts, regulatory authorities, law enforcement agencies, or other public bodies may be recipients insofar as disclosure is required or permitted by law.
Where a service provider processes personal data on our behalf, we enter into a Data Processing Agreement pursuant to Art. 28 GDPR or incorporate equivalent data protection provisions into the contractual relationship.
Insofar as personal data is transferred to recipients outside the EEA, this occurs only in accordance with Art. 44 et seq. GDPR. Depending on recipient and processing, transfers may be based on an adequacy decision, valid certification under the EU-U.S. Data Privacy Framework, European Commission Standard Contractual Clauses, supplementary technical and organizational safeguards, or, in exceptional cases, an applicable derogation under Art. 49 GDPR.
You may request further information on safeguards applicable to a specific transfer or a copy of applicable safeguards at [email protected]. Information may be redacted to the extent necessary to protect confidential information, trade secrets, security measures, or rights of third parties.
Providing personal data when using the website is generally voluntary. Certain technical data is processed automatically because the website cannot otherwise be delivered securely and functionally. Data marked as mandatory in forms is required to process the respective function or inquiry. Insofar as data is required for a contract, pre-contractual measures, or a legal obligation, the relevant service may not be provided without this data.
In connection with the publicly accessible website, we do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. The AI assistant generates or assists responses but does not make binding contractual, financial, KYC, compliance, abuse, or availability decisions.
Under statutory conditions, you have in particular the following rights:
You may withdraw granted consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal, nor processing based on another legal basis. Consent for cookies and services can be modified or revoked via cookie settings. For newsletters and email marketing, Section 14.8 applies additionally.
Insofar as we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you. This also applies to profiling based on this provision.
Following an objection, we will no longer process the personal data concerning you unless we can demonstrate compelling legitimate grounds for processing that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.
Where personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing. This includes profiling to the extent that it is related to such direct marketing. Following your objection, personal data will no longer be processed for direct marketing.
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement. The supervisory authority competent for InterLIR GmbH is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61
10555 Berlin
Germany
Phone: +49 30 13889-0
Email: [email protected]
To exercise your rights, you may contact:
InterLIR GmbH: [email protected]
Data Protection Officer: [email protected]
To prevent unauthorized disclosure of personal data, we may request information reasonably necessary to verify your identity. You do not need to delete browser cookies or local storage entries before exercising your rights.
We update this Privacy Policy whenever processing activities, deployed services, configurations, or legal requirements change. The version currently published on the website is decisive. The date of the last update is specified at the beginning of this Privacy Policy.
Live chat is provided by Intercom and is loaded only after you enable it. You can also contact us without enabling the chat.