plugwith.me ← Back to site

Privacy Policy

How plugwith.me handles personal data — as controller for our own customers, and as processor for the visitors who open our customers' links. Information under Articles 13 and 14 GDPR.

Version 2.4 Effective 4 August 2026 2.2: no third-party scripts remain Binding language: English

The short version. We store what we need to run your account and bill you. The click statistics we produce for our customers carry no IP address, no raw user agent and no cookie identifier — just a slug, a timestamp, a coarse device and browser class and a country code. We do not sell data, do not run advertising, and do not train models on your content. The one place third parties do receive visitor data is when a customer switches on their own marketing pixel — and since version 2.0 those pixels do not load until the visitor agrees.

1. Controller and contact

Eray Yilmaz, sole proprietor, trading as plugwith.me
Europaring 90, 53757 Sankt Augustin, Germany
Email: info@ponyagcy.com · Phone: +49 156 79 729 585
VAT ID: DE320911103

For privacy matters write to info@ponyagcy.com with "Privacy" in the subject line. We answer within one month (Article 12(3) GDPR).

Data protection officer. We are not required to designate one: we do not meet the thresholds of Article 37(1) GDPR or § 38 BDSG. Requests go to the address above.

Representatives. We are established in the European Union, so no representative under Article 27 GDPR is required.

On the United Kingdom: Article 27 of the UK GDPR requires a UK representative from a controller outside the UK that offers goods or services to data subjects in the UK. We have assessed this and consider that we do not: the Service is offered globally in English only, priced in US dollars, with no UK-specific marketing, domain, currency, language or payment method, and no UK-targeted advertising — the factors the test actually turns on. A UK resident can sign up, but mere accessibility of a website is not an offer directed at a territory. We keep this under review and will appoint and name a UK representative here if we begin targeting the UK or if UK users become a material part of our customer base. If you are in the UK and want to exercise a right, write to the address above — nothing about this assessment reduces your rights or our response times.

2. What the Service does, and the two roles we play

plugwith.me is a multi-tenant SaaS platform. Customers create short URLs of the form plugwith.me/<slug> that either redirect straight to a destination they choose, or show a page of buttons. When such a page is opened inside a social-media app's in-app browser, it can hand the visitor out to the device's real browser or to a native app.

That produces two clearly separated data flows, with different responsibilities:

FlowWhose dataOur roleGoverned by
Marketing site, signup, dashboard, billing, support Our customers Controller Sections 4–8 of this policy
Someone opens a customer's slug page End visitors Processor for that customer Section 9 and the DPA

If you are an end visitor and want to exercise your rights over data collected on a slug page, the controller is the customer who owns that slug. Contact us anyway — we will forward your request to them without undue delay and help them answer it.

3. Categories at a glance

DataPurposeLegal basisKept for
Server access logs (IP, time, URL, user agent, referrer, status)Delivery, security, rate limitingArt. 6(1)(f) — secure operationUp to 30 days at Netlify; not copied into our database
Account (display name, email, password hash)Running your accountArt. 6(1)(b)Contract term + 30 days
Link and page configurationProviding the link functionArt. 6(1)(b)Contract term + 30 days
Uploaded imagesAvatars and share previewsArt. 6(1)(b)Until you delete them
Billing data at Stripe, invoicesPayment, tax, accountingArt. 6(1)(b) and (c)10 years (§ 147 AO, § 257 HGB)
Legal acceptance record (Terms, AUP, 18+, withdrawal acknowledgement)Evidence that the contract was validly formedArt. 6(1)(c) and (f) — accountabilityContract term + 3 years
Support correspondenceAnswering youArt. 6(1)(b) and (f)3 years from the end of the year of the last message
Click events on slug pagesStatistics for the customerArt. 6(1)(f) of the customer — see 9.190 days raw
Abuse and moderation recordsEnforcing the AUP, DSA dutiesArt. 6(1)(c) and (f)6 months, longer if a case is open

4. Visiting the marketing site

4.1 Server logs

Every request reaches an edge node of our hosting provider, Netlify, which records the IP address, date and time, the URL and HTTP method, the user agent and referrer where sent, the status code and the number of bytes transferred. Purpose: delivering the site, defending against abuse, and enforcing the rate limit of 60 requests per IP per minute. Legal basis: Article 6(1)(f) GDPR — our legitimate interest in operating the Service securely; there is no less intrusive way to serve a web page or to stop an attack. Netlify retains these logs under its own policy, as a rule for no longer than 30 days. We do not copy them into our application database.

4.2 Fonts

The "Inter" typeface (SIL Open Font License 1.1) is served from our own domain as two WOFF2 files under /assets/fonts/. Google Fonts is not embedded anywhere on this site and no font request leaves our domain. (An earlier version of this policy listed Google as a recipient for fonts. That was wrong and has been corrected.)

4.3 No tracking on our own pages

The marketing site, the legal pages, the blog and the signup and login pages run no analytics, no advertising tags, no heatmaps, no A/B tooling and no third-party embeds. There is no consent banner on those pages because there is nothing to consent to. The only storage we place is listed in section 6.

5. Registration, dashboard and support

5.1 Signing up

We collect a display name, an email address and a password. The password is only ever stored as a bcrypt hash by our processor Supabase; we never see it in clear text and cannot recover it. Legal basis: Article 6(1)(b) GDPR. Providing these three items is necessary to conclude the contract — without them we cannot create an account (Article 13(2)(e) GDPR).

At signup we also record that you accepted the Terms, the Acceptable Use Policy and this policy, and that you confirmed you are 18 or older, together with the timestamp and the version of each document. We need this to demonstrate that the contract was validly concluded and that we meet our age and content obligations. Legal basis: Article 6(1)(c) and (f) GDPR.

5.2 Email confirmation and password reset

Confirmation and password-reset emails are sent by Supabase Auth using its built-in mail delivery. We do not operate a separate email marketing tool and do not send newsletters. (An earlier version of this policy named Resend, Inc. as a processor. No such integration exists; the entry has been removed.)

5.3 Your link configuration

Slugs, buttons, uploaded images, geo-block lists, pixel identifiers, model and profile names and all other settings are stored in your tenant row in our Postgres database at Supabase. Legal basis: Article 6(1)(b) GDPR. Kept for the term of the contract; deleted from production within 30 days of termination and from backups within a further 90 days (section 12).

Images you upload go into a publicly readable storage bucket, because they are used as avatars and as Open Graph preview images on public pages. Do not upload anything you are not willing to make public.

5.4 Payments and invoices

When you take a paid plan, Stripe Payments Europe, Ltd. (Ireland) and its affiliates collect your name, billing address, VAT ID where given, and payment-instrument data directly, as their own controller. We never see full card or bank details; Stripe passes us a customer ID, a subscription ID, a status and invoice metadata. Legal basis: Article 6(1)(b) GDPR for performing the contract, and Article 6(1)(c) GDPR for the invoice content required by § 14 UStG.

We mirror the invoice PDFs Stripe issues into a private storage bucket so that we can meet German record-keeping duties (GoBD) and so that you can download them from the dashboard. Those PDFs are kept for 10 years and are outside the scope of an erasure request (Article 17(3)(b) GDPR).

Stripe's own privacy notice: stripe.com/privacy.

5.5 Support

If you email us we process the content of your message, your address and any information you choose to include, to answer you. Legal basis: Article 6(1)(b) GDPR where it concerns the contract, otherwise Article 6(1)(f). Our mailbox is hosted by our email provider; correspondence is kept for three years from the end of the year of the last message.

6. Cookies and storage on your device

Full inventory, including what customers' pixels place on visitors' devices, is on the Cookie Policy page. In summary, on our own pages we use only what is strictly necessary within the meaning of § 25(2) no. 2 TDDDG and Article 5(3) of Directive 2002/58/EC, so no consent is required:

NameTypePurposeLifetime
sb-*-auth-tokenLocal storageKeeps you signed in (Supabase Auth session)Until sign-out or expiry
admin_sessionCookie, HttpOnlyOperator login at /admin only — never set for customer accountsSession
deeplinker_themeLocal storageRemembers your chosen colour schemeUntil cleared
plugwith.intent.plan, plugwith.intent.intervalLocal storageCarries the plan you picked on the pricing page into checkoutUntil cleared
plugwith.last_login_bounceSession storagePrevents a redirect loop when a session has expiredUntil the tab closes
age_verifiedSession storageOn a slug page with the 18+ gate: stops re-asking on every clickUntil the tab closes
pw_consentLocal storageOn a slug page with a marketing pixel: records the visitor's consent decision so it is not asked again. Set only after an actual choice.6 months

Every one of these is first-party. Since version 2.2 no third-party script is loaded on any page of this service — the Supabase client the customer area needs is served from our own domain. The pw_consent entry is itself strictly necessary — it exists solely to give effect to the choice you made and to avoid asking again — but it is only ever written once you have made that choice.

7. Recipients and processors

We disclose personal data only to the processors below, each under a contract meeting Article 28(3) GDPR, and to public authorities where we are legally obliged to. We do not sell personal data, do not share it for cross-context behavioural advertising, and do not use it to train machine-learning models.

ProviderFunctionWhere processedTransfer safeguard
Netlify, Inc. (US) Hosting, CDN, edge functions, rate limiting, access logs Global edge network; EU points of presence serve EU visitors EU–US Data Privacy Framework and EU Standard Contractual Clauses
Supabase, Inc. (US) Postgres database, authentication, file storage, auth email United States — AWS us-east-2 (Ohio) EU Standard Contractual Clauses (Module 3) plus the measures in 7.1. Supabase is not certified under the EU–US Data Privacy Framework, so the Framework's adequacy decision does not apply to this transfer.
Stripe Payments Europe, Ltd. (Ireland) with Stripe, Inc. (US) Payment, subscription management, invoicing, Stripe Tax Ireland and the United States EU–US Data Privacy Framework and Standard Contractual Clauses; Stripe is a separate controller for payment data

The authoritative, dated list — which we update before any change takes effect — is at plugwith.me/subprocessors. Customers on paid plans can subscribe there to be notified 30 days before a subprocessor changes, and may object under section 6 of the DPA.

7.1 International transfers — including where your account data actually lives

Be clear about this: our production database, authentication store and file storage run in the United States, in the AWS region us-east-2 (Ohio). Your account data, your link configuration, your uploaded images and the click events for your links are stored there, not in the EU. We are a German controller and this is a transfer to a third country under Chapter V GDPR.

Netlify and Stripe are certified under the EU–US Data Privacy Framework, so transfers to them are covered by the European Commission's adequacy decision of 10 July 2023 and need no further instrument.

Supabase is not DPF-certified. That transfer therefore rests on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 3, processor to processor), supplemented by the UK Addendum and the Swiss annex where those regimes apply. The clauses are incorporated into the DPA, which also passes them through to you.

Our transfer impact assessment, in short

The Court of Justice requires that the SCCs actually deliver essentially equivalent protection in practice. We assessed this and record the result here rather than asserting a conclusion:

  • What is exposed. Account data (display name, email, bcrypt password hash), link configuration, uploaded images, and click events. No special-category data, no content of communications, no payment credentials, no government identifiers.
  • The click events are the bulk of the data and carry no identifier at all — no IP, no raw user agent, no cookie or device ID, nothing linking two events by the same visitor (section 9.1). A US authority compelling that table would obtain records that identify nobody. This is the single most effective safeguard we have, and it is a design decision rather than a contractual promise.
  • The residual risk is the account layer — a customer's name and email address. That is real and we do not minimise it.
  • Legal exposure. Supabase is a US cloud provider and is in principle within reach of the CLOUD Act and, if it qualifies as an electronic communications service provider, of FISA § 702. We are not aware of any request having been made. Under section 9.6 of the DPA we require notice of any binding request where notice is lawful, a challenge to any request that appears unlawful or excessive, and disclosure of the minimum permissible.
  • Technical measures. Encryption in transit (TLS 1.2+) and at rest (AES-256); passwords stored only as bcrypt hashes and never recoverable; row-level security with no public policies, so the data is reachable only through our own server-side functions; the service-role key never leaves the server.
  • Conclusion. We consider the safeguards adequate for the data actually involved. We keep this under review and are evaluating a move of the production project to Supabase's Frankfurt region (eu-central-1), which would remove the transfer for stored data entirely. If we move, this section changes and we will announce it under section 15.

You can request a copy of the relevant clauses from us; commercially sensitive commercial terms may be redacted. If you object to this transfer, tell us — for account data we can discuss options, and you can exercise the rights in section 10 at any time.

7.2 Other disclosures

We disclose data to courts, law-enforcement or supervisory authorities where a valid legal obligation requires it, and to our tax adviser and, if it ever becomes necessary, to legal counsel or a debt-collection service — in each case limited to what is needed. In the event of a sale or reorganisation of the business, data may pass to the acquirer; we would inform you in advance and you could terminate (section 16.1 of the Terms).

8. Automated decisions and profiling

We do not carry out automated decision-making producing legal effects or similarly significant effects within the meaning of Article 22(1) GDPR, and we do not build profiles of individuals.

Bot detection and geo-blocking evaluate a single request as it happens and either serve or do not serve a public page. Nothing is stored about the individual and no profile is built. Abuse detection may flag content automatically, but no account is suspended and no appeal is decided by automated means alone — a person always decides (section 6.4 of the AUP).

Artificial intelligence. plugwith.me contains no AI system. We neither provide nor deploy one within the meaning of Regulation (EU) 2024/1689, we do not use AI to make or prepare decisions about you, and we do not use customer data or visitor data to train any model.

9. When someone opens a customer's link

For everything in this section we act as processor on behalf of the customer who owns the slug. That customer is the controller. The DPA governs it and applies to every plan, including the free plan.

9.1 Click statistics

One event row is written per page open and per button click, containing:

  • the slug that was opened;
  • a timestamp;
  • a coarse device class — ios, android, desktop or other — derived from the user agent;
  • a coarse browser class — for example safari, chrome, or instagram for a visit from the Instagram in-app browser;
  • an ISO country code, which Netlify derives from the IP address at the edge;
  • flags recording whether bot protection or the geo-block filtered the request, and why;
  • for a button click, the button's label and destination URL.

No IP address, no raw user agent, no cookie identifier, no device fingerprint and no account identifier is stored on these rows, and nothing links two events by the same visitor. We consider the result anonymous within the meaning of recital 26 GDPR. We say so having applied the reasonable-means test, and we are aware that a supervisory authority might take a different view of a rare combination such as a single visit from a very small country; the design is deliberately kept coarse so that this stays theoretical. Legal basis, in so far as personal data is involved at all: Article 6(1)(f) GDPR — the customer's legitimate interest in knowing whether their links work, with a very low impact on the visitor. Raw events are kept for 90 days; the aggregates derived from them are anonymous and are kept indefinitely.

9.2 Bot protection and geo-block

The user agent and the country code derived from the IP address are evaluated in the request itself, to reject automated traffic or to redirect visitors from countries the customer has excluded. Nothing persistent is created. Legal basis: Article 6(1)(f) GDPR.

9.3 The in-app browser escape

The hand-off from an in-app browser to the system browser is executed entirely on the device by a script that attempts a sequence of URL schemes. It sends no data to us or to anyone else. It reads nothing from the device beyond the user agent string already present in the request.

9.4 A customer's own marketing pixels

A customer can add their own Meta (Facebook), Google Analytics, TikTok or Snap pixel to a page. Where one is configured, the third party receives the visitor's IP address, browser identifiers, the URL and page-view events, and may set or read its own cookies for its own purposes.

These pixels do not load until the visitor agrees. A page carrying a pixel shows a consent notice with a genuine reject option. Nothing is loaded, and no third-party request is made, unless "Accept" is chosen. The decision is stored locally as pw_consent for six months and can be changed at any time from the "Privacy choices" link in the page footer. Choosing to reject leaves the page fully usable.

Who is responsible. The controller for the processing carried out by these third parties is the customer who enabled the pixel — in some configurations jointly with the pixel provider. It is not plugwith.me: we neither determine the purposes nor receive the data. Our customers are contractually required to have a valid legal basis for it (section 7.3 of the Terms). To exercise your rights against a pixel provider, use their own channels: Meta, Google, TikTok, Snap.

9.5 What we do not do

We set no cookie of our own on slug pages, run no advertising network, operate no cross-site identifier, and do not combine data from different customers' links.

10. Your rights

You have the right, free of charge, to:

  • access your data and the details of its processing (Article 15 GDPR);
  • rectify inaccurate data and complete incomplete data (Article 16);
  • erase your data (Article 17), unless a retention duty applies — see section 12;
  • restrict processing (Article 18);
  • receive the data you gave us in a structured, commonly used, machine-readable format and have it transmitted to another controller (Article 20). The dashboard offers a self-service export;
  • object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) (Article 21). Where we cannot show compelling legitimate grounds that override your interests, we stop;
  • withdraw consent at any time with effect for the future, without affecting the lawfulness of processing before withdrawal (Article 7(3));
  • complain to a supervisory authority (Article 77).

Write to info@ponyagcy.com. We may ask for information to confirm your identity — only where we have genuine doubts, and only as much as is needed. We answer within one month, extendable by two months for complex requests, in which case we tell you why.

Complaining to a supervisory authority. You may lodge a complaint with a data protection supervisory authority — in particular the authority of the member state where you live, where you work, or where you believe the infringement took place (Article 77(1) GDPR). Any of them will take your complaint and forward it to the competent authority if it is not itself competent, so you do not have to work out which one that is. If you would rather write to the authority responsible for us, ask us at info@ponyagcy.com and we will name it and pass on its contact details.

11. Additional rights in other jurisdictions

11.1 United Kingdom

Where UK GDPR applies, the rights in section 10 apply equivalently and you may complain to the Information Commissioner's Office (ico.org.uk). Transfers into the UK are covered by the UK adequacy regulations; transfers out are covered by the International Data Transfer Addendum to the EU SCCs.

11.2 Switzerland

Where the Swiss FADP applies, references to the GDPR are read as references to the corresponding FADP provisions and the supervisory authority is the FDPIC (edoeb.admin.ch).

11.3 United States — notice at collection and state rights

This section is the notice at collection required by § 1798.100(a) CCPA and serves the equivalent notices under the comprehensive privacy laws of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware and the other states that have adopted them.

Categories collected, why, and for how long

Statutory categoryWhat that is herePurposeRetention
IdentifiersDisplay name, email address, account and tenant IDCreating and running your account; supportContract term + 30 days
Commercial informationPlan, subscription status, invoicesBilling, tax and accounting10 years (statutory)
Internet or network activityServer access logs; the coarse click events described in section 9.1Delivering the Service, security, statistics for our customerLogs up to 30 days; events 90 days
Geolocation dataA two-letter country code derived at the edge. No precise location, ever.Geo-blocking and country statistics90 days
Visual informationImages you upload as avatars or preview cardsDisplaying your pagesUntil you delete them
InferencesNone. We build no profiles and draw no inferences about individuals.——
Sensitive personal informationNone collected. No government ID, no precise geolocation, no account credentials of other services, no health, biometric, racial, religious, union or sexual-orientation data.——

Sources: you, directly; your browser and device, automatically; and Stripe, for payment status. We disclose these categories only to the service providers in section 7, and only for the business purposes named there.

No sale, no sharing, no targeted advertising

We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding 12 months — and we do not intend to. This includes the personal information of minors, whom we do not knowingly serve at all. We do not process personal information for targeted advertising, and we do not use or disclose sensitive personal information for any purpose that would trigger a right to limit. Because there is no sale or sharing, there is no "Do Not Sell or Share My Personal Information" link to provide.

Your rights

  • Know and access — what we collect, use and disclose, and a copy in a portable format.
  • Correct inaccurate personal information.
  • Delete, subject to the statutory retention duties in section 12.
  • Opt out of sale, sharing, targeted advertising and profiling — nothing to opt out of, but the request will be honoured and confirmed.
  • Non-discrimination. We will not deny you the Service, charge you a different price, give you a lower quality of service, or penalise you in any way for exercising a privacy right. We operate no financial-incentive or loyalty programme.

How to exercise them

Email info@ponyagcy.com with "Privacy request" in the subject. We confirm receipt within 10 business days and respond substantively within 45 days, extendable once by a further 45 days where reasonably necessary, in which case we tell you why before the first period ends.

Verification. We verify a request by matching it against the email address on the account. For a deletion or a copy of your data we may ask you to confirm from that address or, where the account is inactive, to confirm two additional data points we already hold. We ask for the minimum needed and never for a copy of an identity document.

Authorised agents. An agent may act for you if they provide written permission signed by you, and we may still contact you to confirm it and to verify your own identity. An agent acting under a valid power of attorney does not need the separate confirmation.

Appeal. If we refuse a request, we tell you why and how to appeal. To appeal, reply to our refusal with "Appeal" in the subject within 60 days. A person reviews it and we answer in writing within 45 days, explaining the reasons. If the appeal is denied, you may contact your state Attorney General — the address is given in our decision. This appeal process is offered to residents of every state, not only those whose law requires one.

Opt-out preference signals and Do Not Track

We honour the Global Privacy Control signal. On a customer link page carrying a marketing pixel, a GPC signal is treated as a refusal and the pixel is never loaded — no banner is shown, because you have already answered. On our own pages there is nothing a signal would need to switch off. There is no industry consensus on the older "Do Not Track" header, so we do not respond to it separately; GPC covers the same ground.

California Shine the Light

California Civil Code § 1798.83 lets California residents ask, once a year and free of charge, for a list of the personal information disclosed to third parties for those parties' own direct marketing. We make no such disclosures. Requests may still be sent to info@ponyagcy.com and we will confirm this in writing.

Who is responsible for a customer's pixel

Where a customer's marketing pixel is involved, the business under US state law is that customer, not us. We act as their service provider and process the data only on their documented instructions, on the terms in section 13 of the DPA.

11.4 Brazil, Canada and elsewhere

Where the LGPD, PIPEDA or a comparable law applies, we honour the equivalent rights on the same terms and through the same contact address.

12. How long we keep things

DataRetentionWhy
Netlify access logsUp to 30 daysProvider policy; security
Account and link configurationContract term, then 30 days in production and a further 90 days in backupsLets you reactivate; backup rotation cannot delete selectively
Uploaded imagesDeleted with the account, on the same schedule—
Raw click events90 daysAnalytics window; longer history is served from anonymous aggregates
Anonymous aggregatesIndefiniteNo longer personal data
Invoices and accounting records10 years§ 147 AO, § 257 HGB, GoBD — overrides erasure requests (Art. 17(3)(b) GDPR)
Legal acceptance recordsContract term + 3 yearsLimitation period for contractual claims
Support correspondence3 years from the end of the year of the last messageLimitation period
Moderation and abuse records6 months, longer while a case is openDSA duties, defence of claims

Deleting your account in the dashboard starts this schedule immediately. Data that must be retained is blocked from all other use.

13. Security

We apply technical and organisational measures appropriate to the risk (Article 32 GDPR). In particular:

  • TLS 1.2 or higher enforced on every connection, with HSTS including subdomains and preload;
  • a Content Security Policy that enumerates every permitted script and connection host, plus X-Frame-Options: DENY, X-Content-Type-Options: nosniff and a restrictive Permissions-Policy;
  • passwords stored only as bcrypt hashes, by Supabase Auth;
  • rate limiting of 60 requests per IP per minute at the edge;
  • tenant isolation enforced in every query by tenant_id, on tables with row-level security enabled and no public policies — all access runs through server-side edge functions;
  • the invoice bucket is private with no public read and time-limited signed URLs;
  • uploads restricted to JPEG, PNG and WebP up to 2 MB;
  • production access limited to authorised persons with multi-factor authentication;
  • secrets held only in the hosting provider's encrypted environment store, never in the repository.

The full list is Annex II to the DPA. Our security overview and responsible-disclosure policy are at plugwith.me/security.

Breaches. If a personal data breach occurs we notify the competent supervisory authority within 72 hours where the breach is likely to result in a risk to individuals (Article 33), and we inform affected individuals without undue delay where the risk is high (Article 34). Where we act as processor, we notify the customer without undue delay so that they can meet their own deadline.

14. Children

The Service is for adults. You must be 18 or older to hold an account (section 4.1 of the Terms), and we do not knowingly collect data from anyone under 18. If you believe a minor has given us data, tell us at info@ponyagcy.com and we will delete it and close the account.

15. Changes to this policy

We update this policy when the processing changes. The version and effective date at the top always identify the applicable text. Where a change materially affects you, we notify you by email and in the dashboard at least 30 days in advance. Previous versions are available on request.


Hinweis für deutschsprachige Nutzerinnen und Nutzer

Diese Datenschutzerklärung ist in englischer Sprache verfasst, weil der Dienst ausschließlich auf Englisch angeboten wird. Sie enthält sämtliche Pflichtangaben nach Art. 13 und 14 DSGVO. Verantwortlicher ist Eray Yilmaz, Europaring 90, 53757 Sankt Augustin. Eine Beschwerde können Sie bei jeder Datenschutz-Aufsichtsbehörde einreichen, insbesondere bei der Ihres Wohnorts, Arbeitsplatzes oder des Orts des mutmaßlichen Verstoßes (Art. 77 Abs. 1 DSGVO); ist sie nicht zuständig, leitet sie Ihre Beschwerde weiter. Ihre Rechte auf Auskunft, Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit, Widerspruch und Widerruf einer Einwilligung sowie das Beschwerderecht ergeben sich aus Art. 15 bis 21 und Art. 77 DSGVO und sind in Abschnitt 10 beschrieben. Auf Anfrage an info@ponyagcy.com stellen wir Ihnen eine deutschsprachige Zusammenfassung dieser Erklärung zur Verfügung.

Legal

  • Imprint
  • Terms
  • Privacy
  • Cookies
  • DPA
  • Subprocessors
  • Acceptable use
  • Withdrawal
  • Report content
  • Security
  • Accessibility

© 2026 plugwith.me · Eray Yilmaz · Sankt Augustin, Germany