bgunderlay bgunderlay bgunderlay

Privacy Policy

Last updated: August 27, 2026

1. Scope and General Information

InterLIR GmbH takes the protection of personal data seriously. This Privacy Policy explains
which personal data we process when you use the publicly accessible website
interlir.com, the purposes for which processing takes place, the legal bases
on which we rely, which recipients may be involved, how long data is stored, and what rights
you have.

Personal data means any information relating to an identified or identifiable natural person.
This may include, in particular, your name, email address, IP address, device or session
identifiers, as well as the content of communications.

This Privacy Policy applies to the publicly accessible website and its contact, newsletter,
email marketing, and support functions. Where an email address collected through the InterLIR
customer portal, during account registration, or within an existing customer relationship is
used for newsletter or direct marketing purposes, Section 14 of this Privacy Policy applies
to such use. Separate privacy notices may apply to other processing activities relating to
the customer portal, user accounts, contractual services, payments, KYC and compliance checks,
or other processing activities outside the publicly accessible website.

2. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

InterLIR GmbH
Josef-Orlopp-Straße 54
10365 Berlin
Germany

Phone: +49 30 700142706
Email: [email protected]

3. Data Protection Officer

We have appointed an external Data Protection Officer:

DataGAP GmbH
Mr Markus Altenburg
Bessemerstraße 82
12103 Berlin
Germany

Phone: +49 30 577 10 513
Email: [email protected]

4. Legal Bases and Access to End-User Equipment

Depending on the purpose and circumstances of the processing, we rely in particular on the
following legal bases:

  • Art. 6(1)(a) GDPR, where you have given your consent;
  • Art. 6(1)(b) GDPR, where processing is necessary for the performance of a contract or in order to take steps at your request prior to entering into a contract;
  • Art. 6(1)(c) GDPR, where processing is necessary for compliance with a legal obligation;
  • Art. 6(1)(f) GDPR, where processing is necessary for the purposes of our legitimate interests or those of a third party, except where such interests are overridden by your interests, fundamental rights, or freedoms.

Where information is stored on your end-user equipment or access is gained to information
already stored on your end-user equipment, Section 25 of the German Telecommunications
Digital Services Data Protection Act (TDDDG – Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz)
additionally applies. Storage or access that is strictly necessary to provide a digital
service explicitly requested by you or to carry out the transmission of a communication is
based on Section 25(2) TDDDG. Cookies, local storage entries, identifiers, and comparable
technologies that are not strictly necessary are used only after prior consent pursuant to
Section 25(1) TDDDG. Where personal data is processed in this context, we generally base the
subsequent processing on Art. 6(1)(a) GDPR.

5. General Principles on Storage Duration

We store personal data only for as long as necessary for the respective purpose. Specific
storage periods are stated below where possible. After expiry of the relevant period, the data
is deleted or irreversibly anonymised, unless further storage is required or permitted by law,
for example due to commercial or tax law retention obligations, an ongoing security incident,
or for the establishment, exercise, or defence of legal claims.

Withdrawal of consent takes effect for the future. An effective objection terminates processing
based on legitimate interests unless there are compelling legitimate grounds for the processing
or the processing serves the establishment, exercise, or defence of legal claims.

6. Website Hosting, Database, Backups and Server Logs

6.1 Hosting Provider and Region

The website and the associated database are operated in a self-administered WordPress
environment on infrastructure located in the AWS Europe (Frankfurt) region with the identifier
eu-central-1. The AWS contracting party regularly responsible for customers
in the European Economic Area is:

Amazon Web Services EMEA SARL
38 Avenue John F. Kennedy
L-1855 Luxembourg
Luxembourg

InterLIR GmbH administers the server environment, the WordPress installation, and the database.
AWS provides the underlying cloud infrastructure and acts as a processor insofar as personal
data is processed on our behalf. The relevant data protection terms and the AWS Data Processing
Addendum apply to this processing.

6.2 Data Processed

When accessing and operating the website, the following data in particular may be processed:

  • IP address and source port;
  • date and time of the request;
  • requested hostname, URL, page, file, or other resource;
  • HTTP method, status code, headers, and transferred data volume;
  • referrer URL;
  • browser, device, and operating system information;
  • network, security, access, error, and diagnostic information;
  • data transmitted via website functions, in particular contact, newsletter, and support functions;
  • website and database content contained in encrypted backup and recovery copies.

6.3 Purposes and Legal Bases

We process this data to establish connections to the website, provide requested content,
ensure availability and integrity, detect and resolve errors, defend against attacks and
unauthorised access, administer the website, and perform backup and recovery operations.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests lie in the secure, reliable,
efficient, and error-free operation of the website and the protection of our systems.
Where hosted data is processed to handle a contractual or pre-contractual request,
Art. 6(1)(b) GDPR additionally applies.

6.4 Storage Duration

Standard server access and error logs are generally deleted or irreversibly anonymised after
30 days. Relevant entries may be stored for longer where necessary to investigate
a specific security incident, prevent further abuse, comply with a legal obligation, or establish,
exercise, or defend legal claims. The extended storage ends as soon as the additional purpose no
longer applies.

Encrypted website and database backups are retained in a rotating backup system for up to
180 days and are subsequently overwritten or securely deleted. Backups are used
exclusively for recovery, availability, security, and business continuity purposes and not for
routine operational processing. If a backup is restored, the applicable deletion, restriction,
objection, and retention rules are reapplied to the restored environment.

6.5 Processing Outside the EEA

The primary website workloads are configured for the Frankfurt region. Limited processing or
access outside the European Union or the European Economic Area cannot be excluded where this
is necessary for support, service administration, security, sub-processors, or compliance with
binding legal obligations. Third-country transfers take place exclusively in accordance with
Art. 44 et seq. GDPR, in particular on the basis of an applicable adequacy decision or the
Standard Contractual Clauses of the European Commission and, where necessary, supplementary
safeguards.

7. Cloudflare

7.1 Provider and Functions

We use Cloudflare as a DNS service, reverse proxy, content delivery network, caching, and
security service. Requests to areas routed through Cloudflare pass through Cloudflare’s
network before reaching our origin server.

Cloudflare, Inc.
101 Townsend Street
San Francisco, California 94107
USA

7.2 Data, Purposes and Legal Basis

Cloudflare may process, in particular, the following data:

  • IP address;
  • date and time of the request;
  • requested hostname, URL, page, file, or resource;
  • HTTP method, status code, headers, referrer, and data volume;
  • browser, device, operating system, protocol, routing, and connection information;
  • approximate network region;
  • security, firewall, challenge, performance, and network error information;
  • information relating to automated, suspicious, abusive, fraudulent, or malicious traffic;
  • website resources temporarily transmitted or cached via the Cloudflare network.

The processing serves domain resolution, connection forwarding, efficient delivery and caching
of content, load reduction, availability, attack mitigation, abuse prevention, and the
investigation of technical or security-related incidents. The legal basis is Art. 6(1)(f) GDPR.
Our legitimate interests lie in the secure, stable, and efficient provision of the website and
protection against attacks and abuse.

7.3 Processing on Our Behalf, Global Network and Transfers

Cloudflare acts as a processor insofar as Cloudflare processes traffic, cached content, logs,
and security metadata on our behalf. The relevant data protection terms and the Cloudflare
Data Processing Addendum apply. Cloudflare operates a globally distributed network. It therefore
cannot be guaranteed that all traffic, decryption, or metadata processing takes place exclusively
within the EEA.

Third-country transfers take place in accordance with Art. 44 et seq. GDPR. Depending on the
recipient and the respective processing, transfers may be based on an applicable adequacy decision,
including the EU-U.S. Data Privacy Framework for appropriately certified recipients, or on
Standard Contractual Clauses and supplementary safeguards.

7.4 Storage Duration and Technologies on End-User Equipment

Cloudflare stores traffic, network, performance, and security metadata for the periods applicable
to the deployed services and the current account configuration. Data made available to us is stored
by us only for as long as necessary for administration, troubleshooting, security monitoring, or
incident investigation.

Cloudflare security features may use cookies or comparable technologies to distinguish legitimate
users from automated or abusive traffic, maintain security checks, enable load balancing, or protect
the website. The specific technologies used, their purposes, and storage periods are specified in the
cookie settings. Strictly necessary security technologies are based on Section 25(2) TDDDG.
Technologies requiring consent are activated only after consent pursuant to Section 25(1) TDDDG
and, where personal data is processed, Art. 6(1)(a) GDPR.

8. TLS Encryption

The website uses TLS encryption to protect data transmitted between your browser and our systems.
An encrypted connection can generally be recognised by “https://” in the address bar. Despite
appropriate technical and organisational measures, absolute security of electronic transmissions
cannot be guaranteed.

9. Cookies, Similar Technologies and Consent Management

9.1 Necessary and Consent-Based Technologies

We use cookies and comparable browser storage technologies. Strictly necessary technologies are
used only insofar as required to transmit communications, provide the website or a function
explicitly requested by you, maintain security, or store your privacy preferences. Access to
end-user equipment in these cases is based on Section 25(2) TDDDG. Subsequent processing of
personal data is based, depending on the purpose, on Art. 6(1)(b), (c), or (f) GDPR.

Analytics functions, support-chat identifiers, and other non-essential technologies are used only
after prior consent pursuant to Section 25(1) TDDDG and Art. 6(1)(a) GDPR. You may change or
withdraw your selection at any time with effect for the future via the cookie settings.
Withdrawal is as easy as giving consent.

9.2 Real Cookie Banner

We use the locally operated WordPress plugin Real Cookie Banner to obtain,
manage, and document consents and to block non-essential services before consent has been given.
The plugin and the associated consent database are operated within our own WordPress environment.
Merely using the consent management tool does not transmit consent data to the manufacturer of
the plugin.

Depending on the current configuration, the following information in particular may be processed and documented:

  • consent, rejection, or subsequent modification of a decision;
  • selected services and service groups;
  • date and time of the decision;
  • a pseudonymous consent identifier (UUID);
  • a hash generated from a truncated IP address, where this function is configured;
  • version and configuration of the consent dialog;
  • page and language context in which the decision was made;
  • button used and, where activated, interactions with the consent dialog;
  • information concerning the browser view and previous consent settings.

Real Cookie Banner uses first-party cookies or local storage entries whose names typically begin
with real_cookie_banner. They link the browser to the documented decision, apply
the selected preferences, and prevent the same decision from being requested on every page view.
The specific storage duration depends on the configuration used and is displayed in the cookie
settings; it may be up to 365 days.

We base the server-side documentation of consent on Art. 6(1)(c) GDPR in conjunction with the
accountability and proof obligations under Art. 5(2) and Art. 7(1) GDPR. Art. 6(1)(f) GDPR may
additionally apply to the reliable administration of the consent mechanism and the defence of
legal claims. Our legitimate interest lies in legally compliant and technically reliable consent
management. Storage on or access to end-user equipment for the purpose of storing your privacy
preferences is based on Section 25(2) TDDDG insofar as this is strictly necessary to provide and
retain those preferences.

Server-side evidence of consent is generally retained until the end of the third calendar year
following the calendar year in which the consent was withdrawn, replaced, or otherwise terminated,
unless longer storage is required due to a specific legal dispute or a legal obligation. This
storage serves accountability purposes and the establishment, exercise, or defence of legal claims.

10. Language Selection with Polylang

We use the locally installed WordPress plugin Polylang to provide the website
in multiple languages. Polylang may set a first-party cookie named pll_language
to store your selected language and display the same language version on subsequent visits.
Under the current configuration, the cookie is stored for up to one year and is not used for
advertising or cross-site tracking.

Storage and access are based on Section 25(2) TDDDG insofar as the cookie serves the language
function explicitly selected by you. Where personal data is processed, Art. 6(1)(f) GDPR is the
legal basis. Our legitimate interest lies in the consistent provision of a multilingual website.

11. Google Analytics 4

11.1 Provider and Activation

We use Google Analytics 4 exclusively after you have granted consent to the use of technologies under the “Statistics” category in our privacy preferences. The provider is:

Google Ireland Limited
Gordon House, Barrow Street
Dublin 4
Ireland

Our Measurement IDs are G-Y6NRVCFSS1 and G-2WVS7G6BKT.

Google Analytics remains inactive and blocked until you have provided active consent, or if consent has been refused or revoked. We do not use a cross-site User ID or transmit any directly identifiable personal data to Google Analytics.

11.2 Data and Purposes

After consent has been given, the following data in particular may be processed:

  • IP address and the approximate geographic region derived from it;
  • browser, device, operating system, screen, and language information;
  • date and time of access;
  • pages accessed and referrer URL;
  • session and usage information;
  • scroll events, outbound clicks, internal search queries, file downloads, and form interactions, where Enhanced Measurement is enabled accordingly;
  • cookie, device, and session identifiers.

We use Google Analytics to measure and understand use of the website, identify possible technical
and content improvements, and generate aggregated analyses. The legal bases are Section 25(1)
TDDDG and Art. 6(1)(a) GDPR.

11.3 Storage Duration, Processing on Our Behalf and Third-Country Transfers

The retention period for event and user data in our current Google Analytics configuration is
set to two months. This setting does not necessarily result in deletion of data
already incorporated into aggregated standard reports. Specific cookies, browser storage
technologies, and their respective lifespans are specified in the cookie settings.

Google processes analytics data on our behalf in accordance with the applicable data protection
terms. Processing by Google LLC or other Google entities in the USA cannot be ruled out.
Third-country transfers take place in accordance with Art. 44 et seq. GDPR, in particular on
the basis of an applicable adequacy decision, including the EU-U.S. Data Privacy Framework where
the recipient and processing are covered by it, or on the basis of the European Commission’s
Standard Contractual Clauses and supplementary safeguards.

12. Intercom Messenger and AI-Powered Support

12.1 Provider and Consent-Based Activation

We use Intercom Messenger as a live chat and support channel. The Messenger is not activated,
sets no Intercom identifiers, and transmits no visitor data to Intercom before you have consented
to the support chat service via the cookie settings.

Intercom R&D Unlimited Company
124 St Stephen’s Green
Dublin 2, D02 C628
Ireland

Intercom acts as a processor insofar as conversation content, contact details, identifiers,
attachments, and associated support data are processed on our behalf. The relevant data
protection terms and the Intercom Data Processing Addendum apply.

12.2 Data Processed

After activation and during use, the following data in particular may be processed:

  • IP address, date and time, as well as page and referrer information;
  • browser, device, operating system, language, and connection information;
  • visitor, device, session, conversation, and message identifiers;
  • information relating to loading and use of the Messenger;
  • content of messages and AI-generated responses;
  • name, email address, telephone number, company, account, or service information voluntarily provided by you;
  • uploaded files, images, screenshots, and other attachments;
  • routing, escalation, processing status, quality, and feedback information;
  • information relating to spam, abuse, fraud, technical errors, or security incidents.

12.3 Purposes

We process this data in particular to:

  • provide the Messenger and maintain conversation continuity;
  • receive, understand, route, and respond to enquiries;
  • provide AI-generated responses to general support questions;
  • hand enquiries over to authorised personnel where human review is required;
  • organise customer communications and document relevant instructions or decisions;
  • detect and prevent spam, abuse, fraud, and technical or security-related incidents;
  • evaluate the quality, accuracy, consistency, and security of support.

12.4 AI Assistant Tiffany [AI]

Intercom Messenger includes an AI-based support assistant labelled
Tiffany [AI]. No later than the beginning of the first interaction, it is made
clear and distinguishable that you are interacting with an AI system. The assistant generates
responses on the basis of your message, the relevant conversation context, approved support
materials, service documentation, and other knowledge sources provided by InterLIR.

AI-generated responses may be incomplete, outdated, or inaccurate. They do not constitute binding
contractual, legal, financial, KYC, compliance, abuse, or availability decisions. You may request
handover to a human support agent at any time. Matters requiring substantial assessment are handled
or reviewed by authorised personnel.

The assistant is not used to make decisions based solely on automated processing that produce
legal effects concerning you or similarly significantly affect you within the meaning of
Art. 22 GDPR.

Please do not transmit passwords, authentication credentials, payment card data, private keys,
special categories of personal data within the meaning of Art. 9 GDPR, or information that is
not necessary for handling your enquiry through the Messenger.

12.5 Legal Bases

Activation of the Messenger and use of its non-essential cookies and local storage identifiers
are based on your consent pursuant to Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

Once you send an enquiry, processing is carried out on the basis of Art. 6(1)(b) GDPR insofar as
necessary for the performance of a contract or for pre-contractual measures taken at your request.
General business and support enquiries, secure operation, spam and abuse prevention, internal
routing, and quality assurance are based on Art. 6(1)(f) GDPR. Our legitimate interests lie in
efficient and consistent support, short response times, secure operation, protection against abuse,
and the documentation and improvement of customer communications.

12.6 Quality Assurance and Use of Conversation Content

Authorised personnel may review conversations and AI responses for support, troubleshooting,
security, and quality assurance purposes. We do not use identifiable or merely pseudonymised
conversation content to train general external AI models. Where Intercom engages external model
providers for AI functions, their processing is governed by the data protection terms agreed
with Intercom and the current sub-processor configuration.

When creating internal examples for evaluation or improvement, we first remove or replace
information by which a person can be identified. Working copies that remain identifiable or
pseudonymised are access-restricted and are deleted or effectively anonymised within
90 days of selection. Content containing credentials, payment information,
private keys, special categories of personal data, or data that cannot reliably be separated
from an identifiable person is not used for this purpose.

The selection, review, and de-identification of suitable content are based on Art. 6(1)(f) GDPR.
Our legitimate interests lie in the reliability, security, accuracy, and quality of support.
You may object on grounds relating to your particular situation by contacting
[email protected].

12.7 Cookies and Local Storage

Depending on the current Intercom configuration, the following first-party identifiers in particular may be used:

  • intercom-id-da83sgtu: visitor identifier for recognition and maintaining conversation continuity;
  • intercom-session-da83sgtu: session identifier, under the current configuration generally with a lifespan of up to seven days;
  • intercom-device-id-da83sgtu: device identifier that may be used, among other things, for abuse prevention.

The specific cookies or local storage entries used, their purposes, and lifespans are displayed
in the cookie settings according to the current website and Intercom configuration. You can clear
browser data using your browser functions. This may end the active session or remove the association
of the browser with previous conversations; conversation content already stored in Intercom or other
systems is not automatically deleted as a result.

12.8 Storage Duration

Intercom may automatically delete inactive visitor records that have not been accessed for nine
months, provided that no user, customer, or conversation record exists that requires further storage.

Conversations relating to an active customer, account, service, or contract are stored for the
duration of the relationship and for as long as open enquiries, obligations, complaints, security
matters, or disputes remain. After final resolution, relevant communications are generally retained
until the end of the third calendar year following the year of resolution, unless a shorter period
is sufficient or longer retention is required.

Individual messages or attachments may, where the statutory requirements and corresponding
classification are met, be retained in particular for six years as other commercial
records subject to retention, eight years as accounting vouchers, or
ten years as commercial books, inventories, opening balance sheets, annual financial
statements, or comparable documents. Data required for pending or reasonably foreseeable legal claims
may be stored until final resolution of the matter and expiry of the relevant limitation periods.

Closing or archiving a conversation is not equivalent to final deletion. Deletion from active systems
may require additional time before it takes effect on protected provider backups. Remaining backup
copies are not used for normal operations and are deleted or overwritten in accordance with the
applicable backup retention schedules.

12.9 Sub-Processors and Third-Country Transfers

Depending on the Intercom functions and hosting options used, Intercom entities and sub-processors
may provide services for hosting, storage, databases, real-time communication, content delivery,
security, logging, support, and AI processing. External model and infrastructure providers may be
involved in selected AI functions. The specific list of sub-processors may change and is monitored
under the contractual arrangements with Intercom.

Processing may take place in the USA and other countries outside the EEA, in particular where
selected AI, infrastructure, or support functions are provided outside a regional hosting environment.
Third-country transfers take place pursuant to Art. 44 et seq. GDPR, in particular on the basis of an
applicable adequacy decision or the European Commission’s Standard Contractual Clauses and, where
necessary, supplementary safeguards.

12.10 Withdrawal, Human Support and Data Protection Rights

You may withdraw your consent to the support chat at any time with effect for the future via the
cookie settings. This prevents future activation of the Messenger; communications already stored
are not automatically deleted as a result. You may request human support directly in the Messenger
or through our other contact channels. To exercise your data protection rights, please use the
contact details in Section 21.

13. Contact Forms, Email and Telephone

When you contact us via a website form, email, telephone, or Messenger, we process the information
required to handle and respond to your enquiry. This may include, in particular, your name, email
address, telephone number, company, subject, message content, attachments, and technical communication
metadata.

Where the enquiry concerns an existing or prospective contract, Art. 6(1)(b) GDPR is the legal basis.
Other business enquiries are processed on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies
in receiving, organising, and responding to enquiries and transparently documenting business
communications. Where a form requests consent for a separate voluntary purpose, that processing is
based on Art. 6(1)(a) GDPR.

13.1 Technical Email Delivery via Google

For the technical sending and receiving of certain website and business communications, we use a
Google/Gmail connection integrated into WordPress via WP Mail SMTP. The provider for customers in
the EEA is generally:

Google Ireland Limited
Gordon House, Barrow Street
Dublin 4
Ireland

In this context, sender and recipient addresses, subject lines, message content, headers, delivery
status, and technical metadata may be processed. The legal basis depends on the purpose of the
respective message, in particular Art. 6(1)(b) GDPR for contract-related or pre-contractual
communication and Art. 6(1)(f) GDPR for other business communications and reliable technical
email delivery.

Processing by Google LLC or other Google entities in third countries cannot be ruled out.
Transfers take place in accordance with Art. 44 et seq. GDPR, in particular on the basis of an
applicable adequacy decision, including the EU-U.S. Data Privacy Framework where applicable,
or on the basis of Standard Contractual Clauses and supplementary safeguards.

13.2 Retention Period for Enquiries

Enquiries that do not lead to a customer relationship are generally deleted or effectively
anonymised no later than the end of the third calendar year following the year in which the
enquiry was conclusively resolved, and earlier where further storage is no longer necessary.
Statutory retention obligations, security matters, and legal claims remain unaffected. For
Intercom communications, the specific periods in Section 12.8 additionally apply.

14. Newsletter, Customer Updates and Email Marketing

14.1 Scope and Content of Marketing Communications

We may send email communications containing IPv4 market information and analysis, Marketplace
and service updates, selected offers for the purchase or lease of IPv4 addresses, technical tools
and resources, industry news, articles, information about InterLIR services, and relevant company
updates. These communications may be sent as periodic newsletters or as individual marketing or
customer-update emails.

Marketing communications are separate from operational or transactional emails that are required
for account administration, authentication and security, contractual performance, service delivery,
compliance, KYC, abuse handling, billing, transactions, or processing an enquiry. Confirmation of
an email address for account activation, authentication, or security purposes does not in itself
constitute consent to receive marketing communications.

14.2 Marketing Based on Consent and Double Opt-In

You may voluntarily subscribe to InterLIR marketing communications through a newsletter registration
form or, where offered, by making a separate voluntary selection in the InterLIR portal or another
InterLIR interface. Marketing consent is not required merely to create or maintain a portal account
or to use a service for which such consent is not necessary.

Where marketing communications are based on consent, the legal basis for processing your email
address and associated subscription information is Art. 6(1)(a) GDPR. For advertising by electronic
mail, we obtain prior explicit consent where required pursuant to Section 7(2) No. 2 of the German
Unfair Competition Act (UWG – Gesetz gegen den unlauteren Wettbewerb).

Where we use a double opt-in procedure, you receive a confirmation email at the address provided
after submitting the subscription request. The address is activated for consent-based marketing only
after the confirmation step has been successfully completed. The confirmation message serves to
verify the subscription and does not itself constitute a marketing newsletter.

A confirmation performed solely to verify a portal account, customer account, login, authentication
process, or contact address is separate from newsletter double opt-in and does not in itself
constitute consent to marketing.

14.3 Marketing to Existing Customers

In certain cases, we may use an email address obtained directly from an existing customer in
connection with the sale of an InterLIR good or service to send direct advertising for our own
similar goods or services without obtaining separate marketing consent, but only where all
requirements of Section 7(3) UWG are satisfied.

This means, in particular, that the email address must have been obtained in connection with the
relevant customer relationship, the address may be used exclusively for direct advertising of
InterLIR’s own similar goods or services, the customer must not have objected to such use, and the
customer must have been clearly informed when the address was collected, and again on every use,
that they may object to use of the address for direct marketing at any time without incurring costs
other than transmission costs according to the basic tariffs.

Where these requirements are met, the associated processing of personal data is based on
Art. 6(1)(f) GDPR. Our legitimate interest lies in informing existing customers about our own
services, offers, developments, market information, and resources that are sufficiently related to
or similar to the services forming the basis of the existing customer relationship. We take into
account the nature and duration of the customer relationship, the similarity and relevance of the
advertised services, the content and frequency of communications, the reasonable expectations of
the recipient, and the unrestricted right to object to direct marketing.

Mere registration of a portal account, creation of a user profile, or confirmation of an email
address does not in itself establish the conditions for marketing under Section 7(3) UWG. Where
the requirements of Section 7(3) UWG are not fulfilled, we send promotional newsletters or
comparable marketing emails only where another valid legal basis exists, in particular valid consent.

14.4 Documentation of Eligibility for Marketing Communications

We document the information necessary to determine and demonstrate why an email address is eligible
to receive marketing communications. The information recorded depends on the applicable legal basis.

For consent-based marketing, this may include, in particular, the email address, date and time of
the subscription request and confirmation, source page or interface, website language, version and
wording of the consent declaration, confirmation status, and technical information necessary for
secure operation and documentation of the double opt-in procedure. An IP address alone is not treated
as sufficient evidence of marketing consent.

For existing-customer marketing under Section 7(3) UWG, the documentation may include the customer
or account identifier, when and how the email address was obtained, the relevant customer transaction
or service relationship, the category of goods or services forming the basis of that relationship,
the marketing information and notice of the right to object provided when the address was collected,
the applicable version of that notice, and the current objection or suppression status. We may also
document the assessment that the advertised InterLIR goods or services are sufficiently similar to the
goods or services forming the basis of the existing customer relationship.

This documentation serves accountability, compliance with applicable marketing and data protection
requirements, prevention of unlawful marketing, and the establishment, exercise, or defence of legal
claims. Depending on the documentation concerned, the legal bases are Art. 6(1)(c) GDPR in conjunction
with the applicable accountability and proof obligations, including Art. 5(2) and Art. 7(1) GDPR where
consent is relied upon, and Art. 6(1)(f) GDPR. Our legitimate interests include demonstrating lawful
marketing eligibility, reliably observing objections and withdrawals, and defending against legal claims.

14.5 Dispatch and List Management with Twilio SendGrid

We use Twilio SendGrid to send double opt-in confirmation emails where applicable,
manage marketing recipients and suppression lists, honour unsubscribes and objections, and dispatch
newsletters and other marketing communications via SendGrid Marketing Campaigns, Single Sends, or
comparable SendGrid functionality.

For a company established in Germany or the EEA, the relevant Twilio contracting party under the
current Twilio contractual terms is generally:

Twilio Ireland Limited
70 Sir John Rogerson’s Quay
Dublin 2, D02 R296
Ireland

In connection with the email marketing service, your email address, where required for list
management the status of your marketing eligibility or applicable legal basis, where necessary
information concerning subscription or origin from a customer relationship, confirmation status,
objection and suppression status, message and delivery information, as well as technical identifiers
and metadata relating to transmission may be processed. Detailed evidence supporting marketing
eligibility may remain in InterLIR systems instead of being transmitted to SendGrid where SendGrid
does not require such data for the dispatch function.

Insofar as Twilio processes this data on our behalf, the processing is carried out on the basis
of a Data Processing Agreement pursuant to Art. 28 GDPR. Twilio entities and sub-processors may
also process data outside the EEA. Third-country transfers take place pursuant to Art. 44 et seq.
GDPR and the applicable transfer mechanisms, in particular on the basis of an adequacy decision
or the European Commission’s Standard Contractual Clauses and supplementary safeguards.

14.6 Measurement and Tracking in Newsletters

Twilio SendGrid technically provides functions for recipient-specific open and click tracking.
These functions are disabled for our marketing communications.

We do not use tracking pixels to determine whether a specific recipient has opened a marketing
email. Links in our marketing emails are not rewritten by SendGrid for the purpose of
recipient-specific click tracking. We therefore do not collect recipient-specific open or click
data for analytics or marketing purposes.

14.7 Technical Delivery, Bounce, Complaint and Suppression Data

Irrespective of the disabled open and click tracking, technical email delivery information may
be processed insofar as necessary for the operation, security, and reliability of the dispatch
system. This may include successful or delayed deliveries, bounces or non-deliveries, invalid
addresses, spam complaints, unsubscribes, objections, and suppression status.

We use this information to ensure reliable delivery, protect the security and reputation of the
sending infrastructure, avoid repeated delivery attempts to invalid addresses, prevent unlawful
or unwanted marketing, and reliably honour withdrawals, objections, and unsubscribes. The legal
basis is generally Art. 6(1)(f) GDPR. Our legitimate interests lie in the secure and reliable
operation of email dispatch and the avoidance of unwanted messages. Where storage is required
to comply with a legal obligation or to reliably observe a withdrawal or objection,
Art. 6(1)(c) GDPR may additionally apply.

14.8 Withdrawal, Objection, Unsubscribing and Re-Subscription

Where marketing communications are based on your consent, you may withdraw that consent at any
time with effect for the future. Withdrawal does not affect the lawfulness of processing carried
out on the basis of consent before its withdrawal.

Where personal data is processed for direct marketing purposes on the basis of Art. 6(1)(f) GDPR,
you have the right to object to such processing at any time. If you object to processing for direct
marketing purposes, your personal data will no longer be processed for those purposes.

You may withdraw consent or object to marketing by using the unsubscribe link contained in every
marketing email or by contacting us using the contact details provided in this Privacy Policy.
You are not required to state a reason for an objection to direct marketing. Unsubscribing or
objecting must not incur costs other than transmission costs according to the basic tariffs and
is implemented without unnecessary obstacles.

Following withdrawal, objection, or unsubscribe, your email address will no longer be used for
the marketing communications covered by the respective withdrawal, objection, or unsubscribe.
We may retain limited suppression information necessary to ensure that your choice is respected
and that no further advertising is sent contrary to your withdrawal or objection.

If you subsequently voluntarily subscribe again to consent-based marketing and, where applicable,
successfully complete the double opt-in procedure, that confirmation constitutes new consent for
future marketing within the scope described at the time of re-subscription. A marketing suppression
resulting from a previous withdrawal may be lifted only where the new consent has been validly
documented. Technical blocks resulting from bounces, invalid addresses, security restrictions, or
spam complaints are not automatically lifted by re-subscription.

14.9 Storage Duration

Unconfirmed consent-based newsletter registrations are not used for newsletter marketing. Where
a double opt-in confirmation link is configured to remain valid for 48 hours,
unconfirmed registration records are generally deleted no later than seven days
after the request unless temporarily longer storage is required to investigate abuse, security
incidents, or technical errors.

For consent-based marketing, the email address and active subscription status are stored until you
withdraw consent, unsubscribe, or the relevant marketing activity is otherwise terminated. For
existing-customer marketing under Section 7(3) UWG, the email address is used for marketing only
for as long as the statutory requirements remain satisfied, the relevant customer relationship and
similarity of the advertised services continue to support such use, and no objection has been made.

Evidence of consent may be retained after withdrawal or termination generally until the end of the
third calendar year following the calendar year of termination insofar as necessary to fulfil
accountability and proof obligations or to establish, exercise, or defend legal claims. Such further
storage is not based on the withdrawn consent but on the legal bases applicable to documentation and
defence of legal claims.

Documentation necessary to demonstrate eligibility for existing-customer marketing may likewise be
retained for an appropriate period after the final marketing use or termination of eligibility,
generally until the end of the third calendar year following the relevant calendar year, insofar as
necessary to demonstrate compliance with applicable requirements or to establish, exercise, or defend
legal claims.

Suppression information required to implement a withdrawal, unsubscribe, or objection to direct
marketing may be stored for as long as necessary to reliably prevent further advertising contrary
to the recipient’s choice. Suppression information is not used to send further advertising.

15. External Links and Corporate Social Media

15.1 External Links

The website contains ordinary links to external websites and services, including social networks,
messengers, registries, and technical resources. Merely displaying a standard external link does
not result in personal data being transmitted to the external operator. If you click such a link,
you leave our website. The respective external operator may then process personal data in accordance
with its own privacy terms.

15.2 LinkedIn

InterLIR GmbH operates a corporate page on LinkedIn:
InterLIR GmbH on LinkedIn.

If you contact InterLIR through LinkedIn, for example by sending us a direct message, we process
the information made available to us through that communication insofar as necessary to receive,
assess, and respond to your enquiry. This may include your name or profile name, information
visible to us in connection with your LinkedIn profile, the content of your message, attachments,
and other information that you voluntarily provide.

Where the communication concerns an existing contract or measures taken at your request prior to
entering into a contract, the legal basis is Art. 6(1)(b) GDPR. Other business
enquiries and the operation and moderation of our corporate presence are processed on the basis
of Art. 6(1)(f) GDPR. Our legitimate interests lie in maintaining a professional
corporate presence, communicating with interested persons and business partners, responding to
enquiries, and protecting the profile against misuse.

The retention principles for enquiries described in Section 13.2 apply accordingly
to communications processed by InterLIR through LinkedIn.

LinkedIn independently processes personal data in connection with the provision and operation of
its platform. For users in the European Union, European Economic Area, and Switzerland,
LinkedIn Ireland Unlimited Company is the controller for such platform processing.
Further information is available in the
LinkedIn Privacy Policy.

LinkedIn also provides InterLIR with statistical information concerning the use of our corporate
page (“Page Insights”). For the processing of personal data used to generate Page Insights relating
to LinkedIn members in the European Economic Area or Switzerland,
InterLIR GmbH and LinkedIn Ireland Unlimited Company act as joint controllers within the
meaning of Art. 26 GDPR
.

LinkedIn is responsible under the applicable arrangement for the processing of the underlying
member data required to provide Page Insights and for the obligations allocated to LinkedIn under
that arrangement. InterLIR receives Page Insights only in aggregated form. LinkedIn does not provide
InterLIR with personal data through Page Insights that enables InterLIR to identify individual
LinkedIn members from those statistics.

InterLIR uses Page Insights to evaluate the general reach and use of its LinkedIn presence and to
improve its corporate communications. Insofar as processing by InterLIR is involved, the legal
basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in evaluating and
improving our professional communications.

The allocation of responsibilities between InterLIR and LinkedIn and further information concerning
Page Insights are available in the
LinkedIn Page Insights Joint Controller Addendum.
Data subjects may exercise their GDPR rights against either joint controller. If InterLIR receives
a request specifically concerning Page Insights, we will handle the request in accordance with
that arrangement.

15.3 Telegram

InterLIR GmbH operates the public Telegram channel
InterLIR on Telegram.

If you contact InterLIR through Telegram’s direct messaging function, we process the information
made available to us through that communication insofar as necessary to receive, assess, and
respond to your enquiry. This may include your Telegram name or username, profile information
visible to us, the content of your message, attachments, and other information that you
voluntarily provide.

Where the communication concerns an existing contract or measures taken at your request prior to
entering into a contract, the legal basis is Art. 6(1)(b) GDPR. Other business
enquiries and the operation and moderation of our Telegram presence are processed on the basis
of Art. 6(1)(f) GDPR. Our legitimate interests lie in maintaining an additional
communication channel, responding to enquiries, publishing company information, and protecting
the channel against misuse.

The retention principles for enquiries described in Section 13.2 apply accordingly
to communications processed by InterLIR through Telegram.

Telegram Messenger Inc. independently processes personal data in connection with the provision
and operation of the Telegram service. InterLIR does not determine the purposes and means of
Telegram’s general platform processing. Further information concerning such processing and the
exercise of rights against Telegram is available in the
Telegram Privacy Policy.

16. Recipients and Processors

Within InterLIR GmbH, access to personal data is granted only to persons who require such access
for their respective duties. Depending on the processing activity, recipients or processors may
include providers of hosting, cloud infrastructure, security, IT, analytics, consent management,
communications, email delivery, support, legal advice, tax services, compliance, and audits.
Courts, supervisory authorities, law enforcement authorities, or other public bodies may also
receive personal data insofar as disclosure is required or permitted by law.

Where a service provider processes personal data on our behalf, the processing is carried out on
the basis of a contract or another binding legal instrument pursuant to Art. 28(3) GDPR.

17. Transfers to Third Countries

Where personal data is transferred to recipients outside the EEA, this takes place exclusively
in accordance with Art. 44 et seq. GDPR.

Depending on the recipient and the respective processing, transfers may in particular be based
on an adequacy decision of the European Commission pursuant to Art. 45 GDPR. This includes the
adequacy decision concerning the EU-U.S. Data Privacy Framework where the respective US recipient
is validly certified and the transfer concerned is covered by that framework. Where no applicable
adequacy decision exists, transfers may in particular be based on the European Commission’s
Standard Contractual Clauses and, where necessary, supplementary technical and organisational
safeguards. In exceptional cases, a transfer may be based on an applicable derogation under
Art. 49 GDPR.

You may request further information regarding the safeguards applicable to a specific transfer
or a copy of the applicable safeguards by contacting
[email protected]. Information may be redacted
insofar as necessary to protect confidential information, trade secrets, security measures, or
rights of third parties.

18. Obligation to Provide Data

Providing personal data when using the website is generally voluntary. Certain technical data is
processed automatically because the website could otherwise not be provided securely and
functionally. Data marked as mandatory in forms is required to process the respective function or
enquiry. Where data is required for a contract, pre-contractual measures, or compliance with a legal
obligation, the relevant service may not be provided without such data.

19. Automated Decision-Making

In connection with the publicly accessible website, we do not use automated decision-making,
including profiling, that produces legal effects concerning you or similarly significantly affects
you within the meaning of Art. 22 GDPR. The AI assistant generates or supports responses but does
not make binding contractual, financial, KYC, compliance, abuse, or availability decisions.

20. Your Rights

Subject to the statutory requirements, you have in particular the following rights:

  • right of access pursuant to Art. 15 GDPR;
  • right to rectification pursuant to Art. 16 GDPR;
  • right to erasure (“right to be forgotten”) pursuant to Art. 17 GDPR;
  • right to restriction of processing pursuant to Art. 18 GDPR;
  • right to data portability pursuant to Art. 20 GDPR;
  • right to object pursuant to Art. 21 GDPR;
  • right to withdraw consent pursuant to Art. 7(3) GDPR;
  • right to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR.

20.1 Withdrawal of Consent

You may withdraw consent you have given at any time with effect for the future. Withdrawal does
not affect the lawfulness of processing carried out on the basis of consent before its withdrawal,
nor processing based on another legal basis. Consent relating to cookies and services can be changed
or withdrawn via the cookie settings. Section 14.8 additionally applies to newsletters and email
marketing.

20.2 Right to Object Pursuant to Art. 21 GDPR


Where we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right, on grounds
relating to your particular situation, to object at any time to the processing of personal data
concerning you. This also applies to profiling based on this provision.


Following an objection, we will no longer process the personal data concerned unless we can
demonstrate compelling legitimate grounds for the processing which override your interests,
rights, and freedoms, or the processing serves the establishment, exercise, or defence of
legal claims.

20.3 Direct Marketing


Where personal data is processed for direct marketing purposes, you have the right to object
at any time to the processing of personal data concerning you for such marketing. This also
applies to profiling to the extent that it is related to such direct marketing. Following your
objection, personal data will no longer be processed for direct marketing purposes.

21. Complaints and Exercising Your Rights

You have the right to lodge a complaint with a data protection supervisory authority, in particular
in the Member State of your habitual residence, place of work, or place of the alleged infringement.
The supervisory authority competent for InterLIR GmbH is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61
10555 Berlin
Germany
Phone: +49 30 13889-0
Email: [email protected]

To exercise your rights, you may contact:

InterLIR GmbH:
[email protected]
Data Protection Officer:
[email protected]

To prevent unauthorised disclosure of personal data, we may request information reasonably
necessary to verify your identity. You do not need to delete browser cookies or local storage
entries before exercising your rights.

22. Changes to this Privacy Policy

We update this Privacy Policy whenever processing activities, deployed services, configurations,
or legal requirements change. The version currently published on the website is authoritative.
The date of the most recent update is stated at the beginning of this Privacy Policy.

Cookie Consent with Real Cookie Banner Privacy settings