Skip to content

Legal

Privacy Policy

1. Privacy at a glance

The following notices provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you.

Data collection on this website

Data processing on this website is carried out by the website operator. Their contact details can be found in the section “Information about the responsible party” in this privacy policy.

Your data is collected when you provide it to us. This may be data that you enter in a contact form, for example.

Other data is collected automatically or with your consent when you visit the website by our IT systems. This is primarily technical data (e.g. internet browser, operating system or time of page access).

Some of the data is collected to ensure error-free provision of the website. Other data may be used to analyze your user behavior.

You have the right at any time to receive free information about the origin, recipient and purpose of your stored personal data. You also have the right to request the correction or deletion of this data.

2. Hosting

This website is hosted externally. The personal data collected on this website is stored on the servers of the hosting provider.

External hosting is carried out for the purpose of fulfilling contracts with our potential and existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of secure, fast and efficient provision of our online services by a professional provider (Art. 6 para. 1 lit. f GDPR).

Website hosting provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.

Additional sub-processors for the Rinqo platform services: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (primary hosting, ISO 27001:2022); Microsoft Ireland Operations Ltd., One Microsoft Place, Dublin 18, Ireland (Azure OpenAI Service, EU Data Boundary, Sweden Central region); Twilio Ireland Limited, 3 Dublin Landings, Dublin, Ireland (telephony/SIP); Deepgram Inc. (Speech-to-Text, EU region setup); KugelAudio GmbH, Schäfertrift 6, 30657 Hannover, Germany (text-to-speech, EU hosting).

We have concluded a data processing agreement (DPA) per GDPR Art. 28 with every sub-processor. The complete sub-processor list with addresses, processing purposes and SCC status is on the Security page.

Note on third-country transfer: Deepgram is a US corporation operating an EU region setup — your data processing stays in the EU. KugelAudio is a German company with EU hosting, so no third-country transfer applies. Microsoft Ireland additionally uses the EU Data Boundary (binding EU residency for Azure OpenAI). EU Standard Contractual Clauses (SCC) are in place with all providers involving third-country transfers.

3. General information and mandatory disclosures

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.

Responsible for data processing on this website: Sven Pflüger, Schusterstraße 40, 79098 Freiburg im Breisgau. Email: kontakt@rinqo.de, Phone: +49 1523 3555336.

Storage duration

Unless a more specific storage period has been stated within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data.

Legal basis for data processing

Insofar as you have consented to data processing, processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR. Consent can be revoked at any time.

Revocation of your consent

Many data processing operations are only possible with your express consent. You can revoke consent that has already been given at any time. The legality of the processing carried out until the revocation remains unaffected.

Right to object

If data processing is based on Art. 6 para. 1 lit. e or f GDPR, you have the right at any time to object to the processing of your personal data for reasons arising from your particular situation.

Right to lodge a complaint

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority.

Right to data portability

You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format.

Information, correction, deletion

Within the framework of applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin, recipients and the purpose of data processing, and if applicable, a right to correction or deletion of this data.

SSL/TLS encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content.

Contact form (Brevo)

When you contact us via the contact form on our website, the data you provide (name, email address, company if applicable, and message) will be processed to handle your inquiry.

For sending contact form messages, we use the service Brevo (formerly Sendinblue). Provider: Brevo (Sendinblue), 106 boulevard Haussmann, 75008 Paris, France.

Brevo processes your data on our behalf on servers within the European Union. We have concluded a data processing agreement (DPA) with Brevo that ensures GDPR-compliant processing of your data.

The legal basis for processing is Art. 6 para. 1 lit. b GDPR (processing your inquiry) or Art. 6 para. 1 lit. f GDPR (legitimate interest in efficient handling of inquiries). Your data will be deleted after your inquiry has been processed, unless legal retention obligations apply.

AI interaction notice (EU AI Act, Art. 50)

Rinqo operates AI agents for phone, chat and email. Under Article 50 of Regulation (EU) 2024/1689 on artificial intelligence (the “EU AI Act”, fully applicable from 02 August 2026), providers must inform natural persons at the start of an interaction that they are interacting with an AI system.

Our agents identify themselves as AI to end customers at the start of every interaction. Synthetic voice output is disclosed as AI-generated. Escalation to a human is available at any time.

Further information on model architecture, providers used (Microsoft Azure OpenAI Service, KugelAudio, Deepgram) and training-data exclusion is available on the AI transparency page.

Cookies and tracking (TDDDG)

The German Telecommunications and Digital Services Data Protection Act (TDDDG, in force since 14 May 2024, replacing TTDSG) regulates privacy on end-user devices. Under § 25 TDDDG, consent is generally required for storing or reading information on your device (e.g. cookies) — except for strictly technically necessary information.

This website currently uses no non-essential cookies, pixels or trackers. We do not use Google Analytics, Meta Pixel or comparable tracking tools. A consent banner is therefore not required.

If we introduce analytics or advertising tools in the future, we will obtain your consent beforehand via a consent management tool and update this privacy policy accordingly.

Objection to advertising emails

The use of contact data published as part of the imprint obligation for sending unsolicited advertising and information materials is hereby objected to.

Source: e-recht24.de