Privacy Policy
How plugwith.me handles personal data — as controller for our own customers, and as processor for the visitors who open our customers' links. Information under Articles 13 and 14 GDPR.
The short version. We store what we need to run your account and bill you. The click statistics we produce for our customers carry no IP address, no raw user agent and no cookie identifier — just a slug, a timestamp, a coarse device and browser class and a country code. We do not sell data, do not run advertising, and do not train models on your content. The one place third parties do receive visitor data is when a customer switches on their own marketing pixel — and since version 2.0 those pixels do not load until the visitor agrees.
1. Controller and contact
Eray Yilmaz, sole proprietor, trading as plugwith.me
Europaring 90, 53757 Sankt Augustin, Germany
Email: info@ponyagcy.com · Phone: +49 156 79 729 585
VAT ID: DE320911103
For privacy matters write to info@ponyagcy.com with "Privacy" in the subject line. We answer within one month (Article 12(3) GDPR).
Data protection officer. We are not required to designate one: we do not meet the thresholds of Article 37(1) GDPR or § 38 BDSG. Requests go to the address above.
Representatives. We are established in the European Union, so no representative under Article 27 GDPR is required.
On the United Kingdom: Article 27 of the UK GDPR requires a UK representative from a controller outside the UK that offers goods or services to data subjects in the UK. We have assessed this and consider that we do not: the Service is offered globally in English only, priced in US dollars, with no UK-specific marketing, domain, currency, language or payment method, and no UK-targeted advertising — the factors the test actually turns on. A UK resident can sign up, but mere accessibility of a website is not an offer directed at a territory. We keep this under review and will appoint and name a UK representative here if we begin targeting the UK or if UK users become a material part of our customer base. If you are in the UK and want to exercise a right, write to the address above — nothing about this assessment reduces your rights or our response times.
2. What the Service does, and the two roles we play
plugwith.me is a multi-tenant SaaS platform. Customers create short URLs of the form plugwith.me/<slug> that either redirect straight to a destination they choose, or show a page of buttons. When such a page is opened inside a social-media app's in-app browser, it can hand the visitor out to the device's real browser or to a native app.
That produces two clearly separated data flows, with different responsibilities:
| Flow | Whose data | Our role | Governed by |
|---|---|---|---|
| Marketing site, signup, dashboard, billing, support | Our customers | Controller | Sections 4–8 of this policy |
| Someone opens a customer's slug page | End visitors | Processor for that customer | Section 9 and the DPA |
If you are an end visitor and want to exercise your rights over data collected on a slug page, the controller is the customer who owns that slug. Contact us anyway — we will forward your request to them without undue delay and help them answer it.
3. Categories at a glance
| Data | Purpose | Legal basis | Kept for |
|---|---|---|---|
| Server access logs (IP, time, URL, user agent, referrer, status) | Delivery, security, rate limiting | Art. 6(1)(f) — secure operation | Up to 30 days at Netlify; not copied into our database |
| Account (display name, email, password hash) | Running your account | Art. 6(1)(b) | Contract term + 30 days |
| Link and page configuration | Providing the link function | Art. 6(1)(b) | Contract term + 30 days |
| Uploaded images | Avatars and share previews | Art. 6(1)(b) | Until you delete them |
| Billing data at Stripe, invoices | Payment, tax, accounting | Art. 6(1)(b) and (c) | 10 years (§ 147 AO, § 257 HGB) |
| Legal acceptance record (Terms, AUP, 18+, withdrawal acknowledgement) | Evidence that the contract was validly formed | Art. 6(1)(c) and (f) — accountability | Contract term + 3 years |
| Support correspondence | Answering you | Art. 6(1)(b) and (f) | 3 years from the end of the year of the last message |
| Click events on slug pages | Statistics for the customer | Art. 6(1)(f) of the customer — see 9.1 | 90 days raw |
| Abuse and moderation records | Enforcing the AUP, DSA duties | Art. 6(1)(c) and (f) | 6 months, longer if a case is open |
4. Visiting the marketing site
4.1 Server logs
Every request reaches an edge node of our hosting provider, Netlify, which records the IP address, date and time, the URL and HTTP method, the user agent and referrer where sent, the status code and the number of bytes transferred. Purpose: delivering the site, defending against abuse, and enforcing the rate limit of 60 requests per IP per minute. Legal basis: Article 6(1)(f) GDPR — our legitimate interest in operating the Service securely; there is no less intrusive way to serve a web page or to stop an attack. Netlify retains these logs under its own policy, as a rule for no longer than 30 days. We do not copy them into our application database.
4.2 Fonts
The "Inter" typeface (SIL Open Font License 1.1) is served from our own domain as two WOFF2 files under /assets/fonts/. Google Fonts is not embedded anywhere on this site and no font request leaves our domain. (An earlier version of this policy listed Google as a recipient for fonts. That was wrong and has been corrected.)
4.3 No tracking on our own pages
The marketing site, the legal pages, the blog and the signup and login pages run no analytics, no advertising tags, no heatmaps, no A/B tooling and no third-party embeds. There is no consent banner on those pages because there is nothing to consent to. The only storage we place is listed in section 6.
5. Registration, dashboard and support
5.1 Signing up
We collect a display name, an email address and a password. The password is only ever stored as a bcrypt hash by our processor Supabase; we never see it in clear text and cannot recover it. Legal basis: Article 6(1)(b) GDPR. Providing these three items is necessary to conclude the contract — without them we cannot create an account (Article 13(2)(e) GDPR).
At signup we also record that you accepted the Terms, the Acceptable Use Policy and this policy, and that you confirmed you are 18 or older, together with the timestamp and the version of each document. We need this to demonstrate that the contract was validly concluded and that we meet our age and content obligations. Legal basis: Article 6(1)(c) and (f) GDPR.
5.2 Email confirmation and password reset
Confirmation and password-reset emails are sent by Supabase Auth using its built-in mail delivery. We do not operate a separate email marketing tool and do not send newsletters. (An earlier version of this policy named Resend, Inc. as a processor. No such integration exists; the entry has been removed.)
5.3 Your link configuration
Slugs, buttons, uploaded images, geo-block lists, pixel identifiers, model and profile names and all other settings are stored in your tenant row in our Postgres database at Supabase. Legal basis: Article 6(1)(b) GDPR. Kept for the term of the contract; deleted from production within 30 days of termination and from backups within a further 90 days (section 12).
Images you upload go into a publicly readable storage bucket, because they are used as avatars and as Open Graph preview images on public pages. Do not upload anything you are not willing to make public.
5.4 Payments and invoices
When you take a paid plan, Stripe Payments Europe, Ltd. (Ireland) and its affiliates collect your name, billing address, VAT ID where given, and payment-instrument data directly, as their own controller. We never see full card or bank details; Stripe passes us a customer ID, a subscription ID, a status and invoice metadata. Legal basis: Article 6(1)(b) GDPR for performing the contract, and Article 6(1)(c) GDPR for the invoice content required by § 14 UStG.
We mirror the invoice PDFs Stripe issues into a private storage bucket so that we can meet German record-keeping duties (GoBD) and so that you can download them from the dashboard. Those PDFs are kept for 10 years and are outside the scope of an erasure request (Article 17(3)(b) GDPR).
Stripe's own privacy notice: stripe.com/privacy.
5.5 Support
If you email us we process the content of your message, your address and any information you choose to include, to answer you. Legal basis: Article 6(1)(b) GDPR where it concerns the contract, otherwise Article 6(1)(f). Our mailbox is hosted by our email provider; correspondence is kept for three years from the end of the year of the last message.
6. Cookies and storage on your device
Full inventory, including what customers' pixels place on visitors' devices, is on the Cookie Policy page. In summary, on our own pages we use only what is strictly necessary within the meaning of § 25(2) no. 2 TDDDG and Article 5(3) of Directive 2002/58/EC, so no consent is required:
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
sb-*-auth-token | Local storage | Keeps you signed in (Supabase Auth session) | Until sign-out or expiry |
admin_session | Cookie, HttpOnly | Operator login at /admin only — never set for customer accounts | Session |
deeplinker_theme | Local storage | Remembers your chosen colour scheme | Until cleared |
plugwith.intent.plan, plugwith.intent.interval | Local storage | Carries the plan you picked on the pricing page into checkout | Until cleared |
plugwith.last_login_bounce | Session storage | Prevents a redirect loop when a session has expired | Until the tab closes |
age_verified | Session storage | On a slug page with the 18+ gate: stops re-asking on every click | Until the tab closes |
pw_consent | Local storage | On a slug page with a marketing pixel: records the visitor's consent decision so it is not asked again. Set only after an actual choice. | 6 months |
Every one of these is first-party. Since version 2.2 no third-party script is loaded on any page of this service — the Supabase client the customer area needs is served from our own domain. The pw_consent entry is itself strictly necessary — it exists solely to give effect to the choice you made and to avoid asking again — but it is only ever written once you have made that choice.
7. Recipients and processors
We disclose personal data only to the processors below, each under a contract meeting Article 28(3) GDPR, and to public authorities where we are legally obliged to. We do not sell personal data, do not share it for cross-context behavioural advertising, and do not use it to train machine-learning models.
| Provider | Function | Where processed | Transfer safeguard |
|---|---|---|---|
| Netlify, Inc. (US) | Hosting, CDN, edge functions, rate limiting, access logs | Global edge network; EU points of presence serve EU visitors | EU–US Data Privacy Framework and EU Standard Contractual Clauses |
| Supabase, Inc. (US) | Postgres database, authentication, file storage, auth email | United States — AWS us-east-2 (Ohio) |
EU Standard Contractual Clauses (Module 3) plus the measures in 7.1. Supabase is not certified under the EU–US Data Privacy Framework, so the Framework's adequacy decision does not apply to this transfer. |
| Stripe Payments Europe, Ltd. (Ireland) with Stripe, Inc. (US) | Payment, subscription management, invoicing, Stripe Tax | Ireland and the United States | EU–US Data Privacy Framework and Standard Contractual Clauses; Stripe is a separate controller for payment data |
The authoritative, dated list — which we update before any change takes effect — is at plugwith.me/subprocessors. Customers on paid plans can subscribe there to be notified 30 days before a subprocessor changes, and may object under section 6 of the DPA.
7.1 International transfers — including where your account data actually lives
Be clear about this: our production database, authentication store and file storage run in the United States, in the AWS region us-east-2 (Ohio). Your account data, your link configuration, your uploaded images and the click events for your links are stored there, not in the EU. We are a German controller and this is a transfer to a third country under Chapter V GDPR.
Netlify and Stripe are certified under the EU–US Data Privacy Framework, so transfers to them are covered by the European Commission's adequacy decision of 10 July 2023 and need no further instrument.
Supabase is not DPF-certified. That transfer therefore rests on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 3, processor to processor), supplemented by the UK Addendum and the Swiss annex where those regimes apply. The clauses are incorporated into the DPA, which also passes them through to you.
Our transfer impact assessment, in short
The Court of Justice requires that the SCCs actually deliver essentially equivalent protection in practice. We assessed this and record the result here rather than asserting a conclusion:
- What is exposed. Account data (display name, email, bcrypt password hash), link configuration, uploaded images, and click events. No special-category data, no content of communications, no payment credentials, no government identifiers.
- The click events are the bulk of the data and carry no identifier at all — no IP, no raw user agent, no cookie or device ID, nothing linking two events by the same visitor (section 9.1). A US authority compelling that table would obtain records that identify nobody. This is the single most effective safeguard we have, and it is a design decision rather than a contractual promise.
- The residual risk is the account layer — a customer's name and email address. That is real and we do not minimise it.
- Legal exposure. Supabase is a US cloud provider and is in principle within reach of the CLOUD Act and, if it qualifies as an electronic communications service provider, of FISA § 702. We are not aware of any request having been made. Under section 9.6 of the DPA we require notice of any binding request where notice is lawful, a challenge to any request that appears unlawful or excessive, and disclosure of the minimum permissible.
- Technical measures. Encryption in transit (TLS 1.2+) and at rest (AES-256); passwords stored only as bcrypt hashes and never recoverable; row-level security with no public policies, so the data is reachable only through our own server-side functions; the service-role key never leaves the server.
- Conclusion. We consider the safeguards adequate for the data actually involved. We keep this under review and are evaluating a move of the production project to Supabase's Frankfurt region (
eu-central-1), which would remove the transfer for stored data entirely. If we move, this section changes and we will announce it under section 15.
You can request a copy of the relevant clauses from us; commercially sensitive commercial terms may be redacted. If you object to this transfer, tell us — for account data we can discuss options, and you can exercise the rights in section 10 at any time.
7.2 Other disclosures
We disclose data to courts, law-enforcement or supervisory authorities where a valid legal obligation requires it, and to our tax adviser and, if it ever becomes necessary, to legal counsel or a debt-collection service — in each case limited to what is needed. In the event of a sale or reorganisation of the business, data may pass to the acquirer; we would inform you in advance and you could terminate (section 16.1 of the Terms).
8. Automated decisions and profiling
We do not carry out automated decision-making producing legal effects or similarly significant effects within the meaning of Article 22(1) GDPR, and we do not build profiles of individuals.
Bot detection and geo-blocking evaluate a single request as it happens and either serve or do not serve a public page. Nothing is stored about the individual and no profile is built. Abuse detection may flag content automatically, but no account is suspended and no appeal is decided by automated means alone — a person always decides (section 6.4 of the AUP).
Artificial intelligence. plugwith.me contains no AI system. We neither provide nor deploy one within the meaning of Regulation (EU) 2024/1689, we do not use AI to make or prepare decisions about you, and we do not use customer data or visitor data to train any model.
9. When someone opens a customer's link
For everything in this section we act as processor on behalf of the customer who owns the slug. That customer is the controller. The DPA governs it and applies to every plan, including the free plan.
9.1 Click statistics
One event row is written per page open and per button click, containing:
- the slug that was opened;
- a timestamp;
- a coarse device class —
ios,android,desktoporother— derived from the user agent; - a coarse browser class — for example
safari,chrome, orinstagramfor a visit from the Instagram in-app browser; - an ISO country code, which Netlify derives from the IP address at the edge;
- flags recording whether bot protection or the geo-block filtered the request, and why;
- for a button click, the button's label and destination URL.
No IP address, no raw user agent, no cookie identifier, no device fingerprint and no account identifier is stored on these rows, and nothing links two events by the same visitor. We consider the result anonymous within the meaning of recital 26 GDPR. We say so having applied the reasonable-means test, and we are aware that a supervisory authority might take a different view of a rare combination such as a single visit from a very small country; the design is deliberately kept coarse so that this stays theoretical. Legal basis, in so far as personal data is involved at all: Article 6(1)(f) GDPR — the customer's legitimate interest in knowing whether their links work, with a very low impact on the visitor. Raw events are kept for 90 days; the aggregates derived from them are anonymous and are kept indefinitely.
9.2 Bot protection and geo-block
The user agent and the country code derived from the IP address are evaluated in the request itself, to reject automated traffic or to redirect visitors from countries the customer has excluded. Nothing persistent is created. Legal basis: Article 6(1)(f) GDPR.
9.3 The in-app browser escape
The hand-off from an in-app browser to the system browser is executed entirely on the device by a script that attempts a sequence of URL schemes. It sends no data to us or to anyone else. It reads nothing from the device beyond the user agent string already present in the request.
9.4 A customer's own marketing pixels
A customer can add their own Meta (Facebook), Google Analytics, TikTok or Snap pixel to a page. Where one is configured, the third party receives the visitor's IP address, browser identifiers, the URL and page-view events, and may set or read its own cookies for its own purposes.
These pixels do not load until the visitor agrees. A page carrying a pixel shows a consent notice with a genuine reject option. Nothing is loaded, and no third-party request is made, unless "Accept" is chosen. The decision is stored locally as pw_consent for six months and can be changed at any time from the "Privacy choices" link in the page footer. Choosing to reject leaves the page fully usable.
Who is responsible. The controller for the processing carried out by these third parties is the customer who enabled the pixel — in some configurations jointly with the pixel provider. It is not plugwith.me: we neither determine the purposes nor receive the data. Our customers are contractually required to have a valid legal basis for it (section 7.3 of the Terms). To exercise your rights against a pixel provider, use their own channels: Meta, Google, TikTok, Snap.
9.5 What we do not do
We set no cookie of our own on slug pages, run no advertising network, operate no cross-site identifier, and do not combine data from different customers' links.
10. Your rights
You have the right, free of charge, to:
- access your data and the details of its processing (Article 15 GDPR);
- rectify inaccurate data and complete incomplete data (Article 16);
- erase your data (Article 17), unless a retention duty applies — see section 12;
- restrict processing (Article 18);
- receive the data you gave us in a structured, commonly used, machine-readable format and have it transmitted to another controller (Article 20). The dashboard offers a self-service export;
- object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) (Article 21). Where we cannot show compelling legitimate grounds that override your interests, we stop;
- withdraw consent at any time with effect for the future, without affecting the lawfulness of processing before withdrawal (Article 7(3));
- complain to a supervisory authority (Article 77).
Write to info@ponyagcy.com. We may ask for information to confirm your identity — only where we have genuine doubts, and only as much as is needed. We answer within one month, extendable by two months for complex requests, in which case we tell you why.
Complaining to a supervisory authority. You may lodge a complaint with a data protection supervisory authority — in particular the authority of the member state where you live, where you work, or where you believe the infringement took place (Article 77(1) GDPR). Any of them will take your complaint and forward it to the competent authority if it is not itself competent, so you do not have to work out which one that is. If you would rather write to the authority responsible for us, ask us at info@ponyagcy.com and we will name it and pass on its contact details.
11. Additional rights in other jurisdictions
11.1 United Kingdom
Where UK GDPR applies, the rights in section 10 apply equivalently and you may complain to the Information Commissioner's Office (ico.org.uk). Transfers into the UK are covered by the UK adequacy regulations; transfers out are covered by the International Data Transfer Addendum to the EU SCCs.
11.2 Switzerland
Where the Swiss FADP applies, references to the GDPR are read as references to the corresponding FADP provisions and the supervisory authority is the FDPIC (edoeb.admin.ch).
11.3 United States — notice at collection and state rights
This section is the notice at collection required by § 1798.100(a) CCPA and serves the equivalent notices under the comprehensive privacy laws of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware and the other states that have adopted them.
Categories collected, why, and for how long
| Statutory category | What that is here | Purpose | Retention |
|---|---|---|---|
| Identifiers | Display name, email address, account and tenant ID | Creating and running your account; support | Contract term + 30 days |
| Commercial information | Plan, subscription status, invoices | Billing, tax and accounting | 10 years (statutory) |
| Internet or network activity | Server access logs; the coarse click events described in section 9.1 | Delivering the Service, security, statistics for our customer | Logs up to 30 days; events 90 days |
| Geolocation data | A two-letter country code derived at the edge. No precise location, ever. | Geo-blocking and country statistics | 90 days |
| Visual information | Images you upload as avatars or preview cards | Displaying your pages | Until you delete them |
| Inferences | None. We build no profiles and draw no inferences about individuals. | — | — |
| Sensitive personal information | None collected. No government ID, no precise geolocation, no account credentials of other services, no health, biometric, racial, religious, union or sexual-orientation data. | — | — |
Sources: you, directly; your browser and device, automatically; and Stripe, for payment status. We disclose these categories only to the service providers in section 7, and only for the business purposes named there.
No sale, no sharing, no targeted advertising
We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding 12 months — and we do not intend to. This includes the personal information of minors, whom we do not knowingly serve at all. We do not process personal information for targeted advertising, and we do not use or disclose sensitive personal information for any purpose that would trigger a right to limit. Because there is no sale or sharing, there is no "Do Not Sell or Share My Personal Information" link to provide.
Your rights
- Know and access — what we collect, use and disclose, and a copy in a portable format.
- Correct inaccurate personal information.
- Delete, subject to the statutory retention duties in section 12.
- Opt out of sale, sharing, targeted advertising and profiling — nothing to opt out of, but the request will be honoured and confirmed.
- Non-discrimination. We will not deny you the Service, charge you a different price, give you a lower quality of service, or penalise you in any way for exercising a privacy right. We operate no financial-incentive or loyalty programme.
How to exercise them
Email info@ponyagcy.com with "Privacy request" in the subject. We confirm receipt within 10 business days and respond substantively within 45 days, extendable once by a further 45 days where reasonably necessary, in which case we tell you why before the first period ends.
Verification. We verify a request by matching it against the email address on the account. For a deletion or a copy of your data we may ask you to confirm from that address or, where the account is inactive, to confirm two additional data points we already hold. We ask for the minimum needed and never for a copy of an identity document.
Authorised agents. An agent may act for you if they provide written permission signed by you, and we may still contact you to confirm it and to verify your own identity. An agent acting under a valid power of attorney does not need the separate confirmation.
Appeal. If we refuse a request, we tell you why and how to appeal. To appeal, reply to our refusal with "Appeal" in the subject within 60 days. A person reviews it and we answer in writing within 45 days, explaining the reasons. If the appeal is denied, you may contact your state Attorney General — the address is given in our decision. This appeal process is offered to residents of every state, not only those whose law requires one.
Opt-out preference signals and Do Not Track
We honour the Global Privacy Control signal. On a customer link page carrying a marketing pixel, a GPC signal is treated as a refusal and the pixel is never loaded — no banner is shown, because you have already answered. On our own pages there is nothing a signal would need to switch off. There is no industry consensus on the older "Do Not Track" header, so we do not respond to it separately; GPC covers the same ground.
California Shine the Light
California Civil Code § 1798.83 lets California residents ask, once a year and free of charge, for a list of the personal information disclosed to third parties for those parties' own direct marketing. We make no such disclosures. Requests may still be sent to info@ponyagcy.com and we will confirm this in writing.
Who is responsible for a customer's pixel
Where a customer's marketing pixel is involved, the business under US state law is that customer, not us. We act as their service provider and process the data only on their documented instructions, on the terms in section 13 of the DPA.
11.4 Brazil, Canada and elsewhere
Where the LGPD, PIPEDA or a comparable law applies, we honour the equivalent rights on the same terms and through the same contact address.
12. How long we keep things
| Data | Retention | Why |
|---|---|---|
| Netlify access logs | Up to 30 days | Provider policy; security |
| Account and link configuration | Contract term, then 30 days in production and a further 90 days in backups | Lets you reactivate; backup rotation cannot delete selectively |
| Uploaded images | Deleted with the account, on the same schedule | — |
| Raw click events | 90 days | Analytics window; longer history is served from anonymous aggregates |
| Anonymous aggregates | Indefinite | No longer personal data |
| Invoices and accounting records | 10 years | § 147 AO, § 257 HGB, GoBD — overrides erasure requests (Art. 17(3)(b) GDPR) |
| Legal acceptance records | Contract term + 3 years | Limitation period for contractual claims |
| Support correspondence | 3 years from the end of the year of the last message | Limitation period |
| Moderation and abuse records | 6 months, longer while a case is open | DSA duties, defence of claims |
Deleting your account in the dashboard starts this schedule immediately. Data that must be retained is blocked from all other use.
13. Security
We apply technical and organisational measures appropriate to the risk (Article 32 GDPR). In particular:
- TLS 1.2 or higher enforced on every connection, with HSTS including subdomains and preload;
- a Content Security Policy that enumerates every permitted script and connection host, plus
X-Frame-Options: DENY,X-Content-Type-Options: nosniffand a restrictivePermissions-Policy; - passwords stored only as bcrypt hashes, by Supabase Auth;
- rate limiting of 60 requests per IP per minute at the edge;
- tenant isolation enforced in every query by
tenant_id, on tables with row-level security enabled and no public policies — all access runs through server-side edge functions; - the invoice bucket is private with no public read and time-limited signed URLs;
- uploads restricted to JPEG, PNG and WebP up to 2 MB;
- production access limited to authorised persons with multi-factor authentication;
- secrets held only in the hosting provider's encrypted environment store, never in the repository.
The full list is Annex II to the DPA. Our security overview and responsible-disclosure policy are at plugwith.me/security.
Breaches. If a personal data breach occurs we notify the competent supervisory authority within 72 hours where the breach is likely to result in a risk to individuals (Article 33), and we inform affected individuals without undue delay where the risk is high (Article 34). Where we act as processor, we notify the customer without undue delay so that they can meet their own deadline.
14. Children
The Service is for adults. You must be 18 or older to hold an account (section 4.1 of the Terms), and we do not knowingly collect data from anyone under 18. If you believe a minor has given us data, tell us at info@ponyagcy.com and we will delete it and close the account.
15. Changes to this policy
We update this policy when the processing changes. The version and effective date at the top always identify the applicable text. Where a change materially affects you, we notify you by email and in the dashboard at least 30 days in advance. Previous versions are available on request.
Hinweis für deutschsprachige Nutzerinnen und Nutzer
Diese Datenschutzerklärung ist in englischer Sprache verfasst, weil der Dienst ausschließlich auf Englisch angeboten wird. Sie enthält sämtliche Pflichtangaben nach Art. 13 und 14 DSGVO. Verantwortlicher ist Eray Yilmaz, Europaring 90, 53757 Sankt Augustin. Eine Beschwerde können Sie bei jeder Datenschutz-Aufsichtsbehörde einreichen, insbesondere bei der Ihres Wohnorts, Arbeitsplatzes oder des Orts des mutmaßlichen Verstoßes (Art. 77 Abs. 1 DSGVO); ist sie nicht zuständig, leitet sie Ihre Beschwerde weiter. Ihre Rechte auf Auskunft, Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit, Widerspruch und Widerruf einer Einwilligung sowie das Beschwerderecht ergeben sich aus Art. 15 bis 21 und Art. 77 DSGVO und sind in Abschnitt 10 beschrieben. Auf Anfrage an info@ponyagcy.com stellen wir Ihnen eine deutschsprachige Zusammenfassung dieser Erklärung zur Verfügung.