This Privacy Policy explains, in plain and clear language, how the InWeGo platform (hereinafter the "Platform", "we") processes and protects users' personal data: what data we collect, for which purposes and on what legal bases we process it, to whom we may disclose it, how long we retain it, and what rights you have as a data subject. This Policy has been drawn up in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, hereinafter the "GDPR") and other applicable data protection legislation. It is aligned with our Terms of Use (the /terms page) to the extent those documents have been published; in the event of any discrepancy, matters relating to the processing of personal data are governed by this Policy.
InWeGo is an information intermediary platform: we provide a catalogue of service providers and means of communication between clients and providers (the "Contact" chat), but we are not a party to the contracts between users and do not carry out settlements between them. The data controller (the person responsible) within the meaning of Article 4(7) GDPR is InWeGo. The controller's identification and contact details are set out below in the section "Data controller and scope of the Policy" and in the "Contact" section, and in full on the "Legal information" (Impressum) page at /imprint. In processing your data, we strive for transparency and minimisation: we collect only what is genuinely necessary to operate the service and to fulfil our obligations to you and under the law.
We draw your attention to several important features of the Platform, of which we honestly warn you in advance: some of your profile data and the content you create (listings, reviews) are public; your private correspondence is permanently stored on our servers and does not have end-to-end encryption, and the administration has technical access to its content for moderation and the handling of complaints; deletion of an account is by default a "soft" deletion. In addition, when listings are displayed and when address suggestions are used, functional Google components (an embedded map, address autocomplete, reCAPTCHA) loaded from Google's resources are involved. Details are set out in the relevant sections below, and we urge you to read them carefully.
We do NOT sell your personal data, do NOT use automated decision-making with legal consequences, and do NOT engage in profiling in that sense. All substantive moderation on the Platform (of listings, reviews, complaints, messages) is performed manually by administrators. Certain automated technical security measures (temporary login lockout after a series of failed attempts, rate limiting of requests, anti-bot protection) are applied solely to protect the service and do not constitute automated decisions within the meaning of Article 22 GDPR.
The Platform is by default oriented towards users from the European Union; the default geographic region is Germany (region DE). Data processing is carried out in accordance with the requirements of the GDPR regardless of the jurisdiction from which you use the Platform.
1. Data controller and scope of the Policy
The controller of personal data, that is, the person who determines the purposes and means of its processing (the controller within the meaning of Article 4(7) GDPR), is InWeGo. The current and complete identification and contact details of the controller — name, legal form, registered address, registration data and details of the person responsible for the content — are set out on the "Legal information" (Impressum) page at /imprint. We ensure that this page is completed with the controller's valid details; if for any reason you do not find the necessary information there, you may request it directly at the email address hello@inwego.com, at which the controller can also be contacted regarding all data processing matters.
This Policy applies to the processing of data carried out when using the InWeGo web platform: upon registration and maintenance of an account, completion of a profile, publication of service listings, exchange of messages, posting of reviews, requests to support, submission of complaints and other interaction with the service.
This Policy does not designate a separate appointed Data Protection Officer (DPO). For all matters relating to the processing of personal data and the exercise of your rights, you may contact the controller at the email address hello@inwego.com, as well as via the contact details specified in the "Contact" section below and on the /imprint page.
2. What data we process
Data that you provide to us yourself. Upon registration and use of the Platform, we process: email address (mandatory, must be unique), first name (mandatory, 2–60 characters) and, optionally, surname, as well as password (stored exclusively as a cryptographic hash by means of ASP.NET Identity, see the section on security) and account role.
Profile data. At your discretion, the profile may additionally contain: phone number, city and address (street, house number, region, postal code, coordinates), account type (Individual / SmallBusiness / LegalEntity — this is your self-declaration and is not verified by the platform), the "About" section (up to 2000 characters), languages of service, links to social networks and a personal website (Instagram, Facebook, Telegram, LinkedIn, Website), a profile photo (avatar), as well as visibility flags and notification settings.
User content. We process the content you create: service listings (title, description, company name, provider type, category and subcategory, including those you propose, address and coordinates of the service, indicators of willingness to travel and remote work, service radius, price and price type, help items, service photos), reviews and ratings (rating 1–5 and optional comment text), private messages and photo attachments to them, as well as support requests and complaints (text and attachments).
Data collected automatically. When using the Platform, technical data is automatically processed: IP address, browser type and version (User-Agent), access time. Every change to any data in the system is automatically recorded in the audit log (see the section on security): the audit is written for the creation, modification and deletion of any tracked entities, and not only for administrators' actions. The audit record stores the initiator of the action (identifier, email and name of the actor), their IP address, User-Agent, HTTP method and request path, as well as the old and new changed values. To control costs and protect against abuse, request rate limits are applied, where the IP address and/or user identifier is used as a key (in particular, for Google Places address suggestion requests, a limit of about 10 address detail requests per day per user/IP applies). Locally in your browser (localStorage), the choice of interface language, the cookie consent decision and the support guest token are stored; with your consent to analytics, sessionStorage additionally keeps a technical list of service views already counted, so that one view is not counted twice. In addition, EXCLUSIVELY with your consent to the "Analytics" category, we collect our own anonymised usage statistics (page opens, service views, search queries, contact clicks) — described in detail in the section "Cookies and similar technologies".
3. Mandatory nature of providing data
Some data is necessary for the conclusion and performance of the contract on the use of the Platform (Art. 13(2)(e) GDPR). To create an account, an email address, first name and password are mandatory: without providing them, registration is technically impossible and we will not be able to provide you with the service. When publishing a listing, certain fields are mandatory (for example, title, description, city, street, house number, at least one help item) — without them the listing cannot be created.
All other profile and content data you provide voluntarily, at your discretion. Failure to provide optional data does not entail any negative consequences for you, but may limit certain functions (for example, the absence of contact details in the profile will make it difficult for other users to contact you by the means you have not specified).
4. Data obtained from third parties (login via Google)
If you register or log in using a Google account (Google Sign-In), we receive from Google, on the basis of validation of the Google ID token, the following data: your email address, name and email verification indicator. If Google confirms that your email is verified, it is considered confirmed on the Platform.
In addition, when filling in address fields, autocomplete of city and street is provided by the Google Places service, as a result of which normalised address data may be received from Google: place identifier (Place ID), formatted address, region, postal code, country and geographic coordinates. Your search input and, where available, your coordinates are transmitted to Google. We do not receive from Google any data other than those listed.
5. Embedded Google Maps map on the service card
On the service card page, the provider's location may be displayed using an embedded Google Maps map. The map does NOT load automatically: by default a placeholder is shown instead. The map loads only in two cases — if you have consented to the "External content (Google Maps)" category in the cookie banner, or if you have clicked the "Show map" button on the specific page (one-off consent by action). When the map loads, your browser directly contacts Google's servers, as a result of which Google may obtain, at a minimum, your IP address and information about the page being viewed (referrer), and may also set its own cookies in accordance with Google's policies.
The embedded map is a functional component for displaying the listing, and not an analytical or advertising tracker. Nevertheless, this is a separate flow of data transmission to a third party (Google), which is why without your consent or explicit action the map does not load and no data is transmitted to Google. Google's processing of the data obtained in this way is governed by Google's privacy policy. You can withdraw your consent to automatic map loading at any time via "Cookie settings" in the site footer; after withdrawal the map will again be shown only on request.
6. Purposes and legal bases of processing (Art. 6(1) GDPR)
Provision and operation of the service, performance of the contract with you — Art. 6(1)(b) GDPR. On this basis we process the data necessary to provide the functionality of the Platform under the Terms of Use: creation and maintenance of an account and profile, publication of listings, provision of the catalogue of providers and communication between users (chat), as well as the sending of transactional emails related to servicing the account. Optional profile data that you decide to specify at your discretion is processed on the basis of your consent (Art. 6(1)(a) GDPR).
Consent — Art. 6(1)(a) GDPR. On this basis, the optional categories of cookies and similar technologies are processed — anonymised usage analytics and automatic loading of external content (the Google Maps map) — applied only after your explicit consent via the banner, as well as, where applicable, the obtaining of address suggestions via Google Places. You have the right to withdraw consent at any time, including via the "Cookie settings" link in the site footer, which does not affect the lawfulness of processing carried out before the withdrawal.
Legitimate interests — Art. 6(1)(f) GDPR. On this basis, data is processed for the purposes of ensuring the security and integrity of the Platform, preventing fraud and abuse, maintaining the audit log, moderating content and handling complaints (pre-moderation of listings and reviews, blocking of violators, anti-bot protection), as well as improving and developing the service. On this same basis, when moderating reviews, the administrator processes the personal data of their authors (including performing a search by the review author's email in the administrative panel). In each case, we balance our interests against your rights and freedoms.
Legal obligations — Art. 6(1)(c) GDPR. On this basis, processing is carried out when it is necessary to comply with the obligations imposed on the controller by law — for example, when responding to lawful requests from authorised bodies or retaining data for statutory periods.
We do not use your data for purposes incompatible with those specified above. In particular, the Platform does not carry out automated decision-making entailing legal or other significant consequences, and does not carry out profiling in that sense (see the relevant section below).
7. Account and authentication
To create an account, an email address, first name and password are required. The password is stored exclusively as a cryptographic hash by means of ASP.NET Identity and is not accessible to us in plain text: we cannot recover or view it. Complexity requirements apply to the password — a minimum length of 8 characters and the mandatory presence of an uppercase letter, a lowercase letter, a digit and a special character. The email must be unique: upon registration, an already existing address is rejected.
Registration and login are free. Login via a Google account is possible. On the registration form, Google reCAPTCHA anti-bot protection is applied. For security purposes, automatic temporary login lockout after 5 failed attempts (for 15 minutes) and invalidation of active sessions upon change or reset of the password, as well as upon blocking of the account, are provided.
Email confirmation is carried out via a link from an email. However, email confirmation is not a mandatory condition for logging in: login is not technically blocked until confirmation, and after registration you can use the account immediately. The email confirmation flag is used to mark the status of the account and certain functions. When logging in via Google, the email is considered confirmed if Google returned the corresponding verification indicator. The account role (the system provides for only two roles — "User" and "Admin"), status flags (email confirmation, blocking, deletion indicator) and internal session tokens are processed as part of the authentication mechanism.
8. User profile and public availability of data
Some of your profile data is public and is always displayed to other users, regardless of settings: first name and surname, avatar, account type, the "About" section, languages of service, average rating, number of reviews and number of published services. Your published listings and approved reviews are also publicly available. By publishing this information, you make it available to an indefinite range of persons.
You regulate the visibility of contact details via toggles in the privacy settings: email address, phone, city, as well as links to social networks and website are shown to other users only when the corresponding flag is enabled. By default, the visibility settings are enabled. We are obliged to honestly warn about a technical peculiarity: the exact address fields (street, house number, region, postal code) in the current implementation may be present in the response of the public application programming interface (API) regardless of the visibility settings, although they are not displayed in the profile interface itself. We regard this as a defect that does not comply with the principles of data protection "by default" and "by design" (Art. 25 GDPR), and we intend to remedy it by limiting the disclosure of the exact address according to the visibility settings. Until the defect is remedied, we recommend not specifying the exact address if you are not prepared for its potential disclosure.
The public profile is unavailable if the account is deleted or blocked. The profile completeness indicator is purely informational in nature, is not mandatory and does not block functionality.
9. Service catalogue and listings
When publishing a listing, the following are processed: title, description, company name, provider type (Individual / SmallBusiness / LegalEntity), category and subcategory, address and coordinates (city is mandatory; region, postal code and coordinates are automatically determined via Google Places from the specified address), indicators of willingness to travel and remote work, service radius, price and price type (fixed, "from", hourly, upon consultation, negotiable), help items, as well as service photos.
When viewing a service card, the location may be displayed using an embedded Google Maps map, which involves the transmission of data to Google (see the section "Embedded Google Maps map on the service card").
The price in the listing is an exclusively informational field for display and does not initiate any payment transactions. The currency is not stored in the data and is implied at the interface level. The Platform does not carry out settlements and does not act as a payment intermediary: money does not pass through InWeGo, and any arrangements for payment take place directly between the client and the provider outside the Platform.
All listings undergo prior moderation: a new or edited listing receives the status "under moderation", is not visible in public search and becomes visible only after approval by an administrator. A listing may be rejected or blocked with a mandatory indication of the reason; the provider is sent a notification of publication or rejection. The owner cannot edit a blocked listing. In public search, only active (approved) listings are displayed by default.
10. Categories and subcategories
The taxonomy of services has a two-level structure: category → subcategory. Names are stored as multilingual translations (Ukrainian, Russian, English, Slovak). When publishing a listing, you may propose your own category or subcategory by entering its name as free text.
Categories and subcategories proposed by users undergo mandatory moderation by an administrator: until approval, they exist in the status "proposed" and are not displayed in the public catalogue. The administrator has the right to approve the proposal, map it to an existing category, rename or reject it. A service may be published (approved) only after its category and subcategory are permitted. Thus, entering a proposed name is merely an application; users cannot rely on the fact that the category they proposed will be created or retained in the proposed form.
11. Reviews and rating
When posting a review, the following are processed: your identifier and author name, rating (1–5), optional comment text (up to 500 characters), timestamps and an internal verification flag. In a public review, the author's name is displayed. During moderation, the administrator additionally has access to information about the service and the provider, and searching reviews in the administrative panel involves the author's email — that is, during moderation the administrator processes the personal data of review authors on the basis of legitimate interests (Art. 6(1)(f) GDPR) for the purposes of moderation and maintaining the quality and safety of the Platform.
All new and edited reviews undergo mandatory prior moderation and are not published until approved by an administrator. When a review is edited, its status is forcibly reset to "under moderation", and the review temporarily disappears from public display until re-approval. Rejected reviews are not displayed publicly and do not affect the rating, but are retained in the system.
The "verified review" flag is set by an administrator upon approval of the review and does NOT signify confirmation of the fact of a transaction or payment: when a review is created, no verification is performed that the user actually ordered or paid for the service.
12. Private messages, chat and moderation of correspondence
The chat is intended for communication between the client and the provider; the dialogue is strictly limited to two participants. When exchanging messages, the following are processed: message text, time of sending and reading, identifiers and names of participants, profile photos, as well as image attachments. Push notifications may contain a preview of the message text (up to 100 characters) and the sender's name.
All messages, dialogue metadata and attachments are permanently stored on the Platform's servers. The correspondence is NOT protected by end-to-end encryption. Users cannot independently delete or edit sent messages. Access to the dialogue at the level of an ordinary user is strictly limited to its two participants. Real-time exchange is provided by SignalR technology; photo attachments are stored in external object storage and are loaded directly via temporary signed links. Sending messages is impossible if the sender's or recipient's account is blocked by the Platform.
We draw particular attention: the administration of the Platform has technical access to the full content of dialogues and attachments, but uses it exclusively for the purposes of moderation and the handling of complaints. Thus, the correspondence is not absolutely private and may be read by authorised employees where there are grounds. Please take this into account and do not transmit in the correspondence data that you would not wish to entrust to the Platform.
13. Support requests and complaints
Communication with the administration is implemented as a single support chat. When making a request, the following are processed: the text of the request (up to 2000 characters), image attachments (jpeg/png/webp, up to 10 MB), and, for authorised users, the name and email automatically linked to the conversation. A request is possible anonymously, without registration: a guest is identified by a token (UUID) stored locally in the browser; the IP address is indirectly used to limit the rate of guest requests. Administrators have full access to support conversations, including attachments.
When submitting a complaint, the following are processed: the identifier of the applicant (or the value "anonymous"), data about the object of the complaint (profile, service, message or correspondence), the reason and text of the comment (up to 2000 characters), as well as internal decision data (note, administrator identifier, date). For complaints about messages and correspondence, the administrator has access to their full content, including attachments. Complaints about a profile and a service may be submitted, among others, by anonymous users, whereas complaints about messages and correspondence require authorisation and confirmation that the applicant is a participant in that correspondence.
The handling of complaints is carried out exclusively manually by an administrator, who makes a decision to uphold or reject the complaint. No automatic sanctions following the handling of complaints are provided; blocking of a violator or removal of a listing is applied only manually as a result of the handling. (Automatic technical security measures — for example, temporary login lockout upon password guessing or rate limiting of requests — do not relate to content moderation based on complaints and are described in the section on security.)
14. Notifications and emails
In-app notifications inform you of Platform events (a new review, publication or rejection of a service) and are stored as a limited list (up to the 100 most recent). Notifications of new messages are delivered in real time via SignalR. The notification settings in the profile are informational in nature.
Transactional (service) emails are sent via the external service SendGrid, to which your email address and name are transmitted for delivery. In fact, only four types of emails are sent: email confirmation (upon registration and resending), a welcome email (after email confirmation), a password reset email and a notification of a password change. These emails are necessary for the operation of the account and are sent on the basis of performance of the contract. Marketing mailings are not currently carried out; the notification toggles in the interface do not control the actual delivery of emails.
15. Data recipients and processors
For the functioning of the Platform, we engage carefully selected third-party service providers acting as processors on our instructions or providing functional components loaded in your browser. Google Sign-In / Google Identity — validation of login and registration via a Google account (email, name, email verification indicator are processed). Google reCAPTCHA — anti-bot check on the registration form (loaded from Google's resources and may set Google cookies). Google Places API — autocomplete and normalisation of addresses and cities (default region DE); the entered text and, where available, your coordinates are transmitted with your request. Google Maps embed — an embedded map on the service card, upon loading of which your browser contacts Google's servers (at least IP and referrer are transmitted).
Google Cloud Storage — cloud storage of all uploaded photos (profile, services, correspondence, support); the images themselves are stored in Google's cloud, and in our database only metadata and the path to the object. Access to files is provided via temporary signed links of limited validity. SendGrid — delivery of transactional emails (the recipient's email and name are transmitted).
The internal real-time infrastructure (SignalR) is used for the delivery of messages and notifications and is proprietary. In addition, access to personal data within the scope of their functions is held by the Platform's administrators — exclusively for manual moderation and the handling of complaints. We do not sell personal data to third parties and do not transfer it for their own marketing purposes or other purposes incompatible with this Policy. The transfer of data to processors is carried out on the basis of the relevant data processing agreements.
16. International data transfers
The engagement of third-party providers (in particular, companies of the Google group — including Google Sign-In, Google Places, Google Maps, reCAPTCHA and Google Cloud Storage — as well as SendGrid) may entail the processing and transfer of personal data to third countries outside the European Economic Area, including to the United States of America. This means that the use of the service may involve the international transfer of personal data within the meaning of Chapter V of the GDPR. Such transfer may occur, in particular, when functional Google components (embedded map, reCAPTCHA) are loaded in your browser.
For such transfers, we rely on the mechanisms provided for by the GDPR to ensure an adequate level of protection — primarily on the Standard Contractual Clauses approved by the European Commission, as well as, where applicable, on adequacy decisions and additional measures. Upon request, you may obtain additional information about the safeguards applied by contacting the controller via the specified contact details.
17. Data retention periods and account deletion
We retain personal data for exactly as long as is necessary to achieve the purposes for which it was collected, or for the periods established by applicable legislation (for example, to comply with retention periods, resolve disputes and defend legal claims). Once no longer necessary, the data is deleted or anonymised. Certain categories have their own indicative periods: temporary signed links to photos are valid for a limited time (on the order of a few minutes); place details from Google Places are cached for a period of about 30 days; audit log records are retained for security and accountability purposes for the time necessary for those purposes (on the order of 12 months); anonymised analytics events (collected only with your consent) are retained for no longer than approximately 14 months and are then deleted automatically; the data of "soft-deleted" accounts is retained in the database (see below) until a decision is made on its final deletion or anonymisation, taking into account our legal obligations.
Important warning about account deletion. By default, account deletion is implemented as a "soft delete": your profile ceases to be publicly available and is excluded from search, however the records (email, profile data, services and other content) are physically retained in the database — the standard function does not carry out complete irreversible eradication of data. Photos, upon deletion, are removed from cloud storage, however metadata may be retained. Rejected reviews and messages are also retained. Audit log records are retained for security and accountability purposes.
If you wish to achieve the complete deletion of your data to the extent provided for by the GDPR, beyond the standard mechanism, you may send the relevant request to the controller via the specified contact details. Such a request will be considered taking into account our legal obligations and legitimate grounds for the further retention of certain data (see the section on data subject rights).
18. Data security measures
We apply technical and organisational measures to protect personal data. Passwords are stored exclusively as a cryptographic hash (ASP.NET Identity) and are not accessible in plain text; password complexity requirements, automatic lockout after a series of failed login attempts and invalidation of sessions upon change or reset of the password are provided.
Uploaded photos are stored in external cloud storage (Google Cloud Storage) and are served only via temporary signed links of limited validity, and not via direct public addresses. All data changes are automatically recorded in the audit log with an indication of the action, the initiator, their IP address and browser information; sensitive fields (passwords, tokens, secrets, hashes, as well as internal security and concurrency markers) are masked in the process. Measures against abuse are provided: anti-bot check, rate limiting of requests, automatic lockout upon password guessing and invalidation of sessions. All these automatic measures are technical security measures and do not relate to automated decision-making within the meaning of Article 22 GDPR.
At the same time, we draw attention to the fact that authorised administrators, by virtue of their functions, have access to users' personal data, including the content of correspondence and attachments — exclusively for the purposes of moderation and the handling of complaints. No method of data transmission and storage is absolutely secure, and we cannot guarantee its absolute protection.
19. Cookies and similar technologies
The Platform uses cookies and browser local storage and divides them into three categories: necessary (ensure the basic operation of the service — sign-in, security including reCAPTCHA, remembering the language, saving the cookie choice itself, the support guest token — and cannot be disabled), analytical, and "external content (Google Maps)". Necessary cookies are applied on the basis of our legitimate interests and/or for the performance of the contract. The optional categories (analytics, external content) are applied EXCLUSIVELY after your explicit consent, expressed via the consent banner (opt-in model). There are no "marketing" or "personalisation" categories on the Platform, as no such technologies are used.
The "Analytics" category is our OWN (first-party) anonymised usage statistics. With your consent, the following events are recorded: page opens (only the generalised page path, without parameters), service card views, catalogue search queries (query text, selected category and city), opening of the contact window, clicks on the phone number and on the "Write in chat" button, and adding a service to favorites. Together with an event, only its type, the moment in time and the interface language are stored. We deliberately do NOT store in analytics your user identifier, IP address, browser data (User-Agent) or any other information allowing events to be linked to a specific person; events are not combined into profiles. These events are retained for no longer than approximately 14 months and are deleted automatically. Without consent to the "Analytics" category, such events are not collected at all — including that the service view counter is not incremented.
Consent is voluntary and may be withdrawn at any time; the withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. Your choice regarding cookie categories, together with the consent version and timestamp, is stored locally in your browser (localStorage) and is not transmitted to the server; you may change or withdraw your consent at any time via the "Cookie settings" link in the site footer. In the event of a substantial change to the consent categories, we ask for it again.
We draw attention to the fact that we do not connect third-party web analytics systems, advertising networks or tracking pixels (for example, Google Analytics, Facebook Pixel and the like): all analytics is implemented by us ourselves and is described above. At the same time, functional third-party Google components are present on the Platform — reCAPTCHA on the registration form (necessary for bot protection) and an embedded Google Maps map on the service card (loaded only with your consent or via the "Show map" button) — which, when loading, contact Google's resources and may technically set Google cookies. These components are described in the sections on data recipients and on the Google Maps map.
20. Automated decisions, profiling and sale of data
The Platform does not carry out automated decision-making producing legal consequences concerning you or otherwise significantly affecting you, within the meaning of Article 22 GDPR, nor does it carry out profiling in that sense. All substantive moderation of content (listings, reviews, complaints, messages) is performed manually by authorised employees. Automatic technical measures (temporary login lockout after 5 failed attempts for 15 minutes, invalidation of sessions, rate limiting of requests) are security measures and do not constitute automated decisions under Art. 22 GDPR.
We do not sell your personal data to third parties and do not transfer it for the purposes of their own marketing. The transfer of data is limited to the engagement of processors and functional components specified in this Policy, in order to ensure the operation of the service.
21. Your rights as a data subject
In accordance with the GDPR, you have the following rights in respect of your personal data: the right of access (Art. 15), the right to rectification (Art. 16), the right to erasure, the "right to be forgotten" (Art. 17), the right to restriction of processing (Art. 18), the right to data portability (Art. 20), as well as the right to object to processing based on legitimate interests (Art. 21).
If processing is based on your consent, you have the right to withdraw it at any time, which does not affect the lawfulness of processing carried out before the withdrawal. The exercise of the right to erasure is carried out taking into account the technical peculiarity of "soft deletion" and our legal obligations to retain certain data, of which we will inform you.
To exercise any of the specified rights, contact the controller at hello@inwego.com or via the contact details specified on the "Legal information" page (/imprint). We will consider your request without undue delay and in any case within one month of its receipt; this period may be extended by a further two months taking into account the complexity and number of requests, of which we will notify you (Art. 12 GDPR). You also have the right to lodge a complaint with a data protection supervisory authority — in particular, at your place of habitual residence, work or the alleged infringement within the EU — in accordance with Article 77 GDPR.
22. Children and minimum age
The Platform is not intended for children. Only persons who have reached the age at which, under applicable national legislation, it is possible to independently give consent to the processing of personal data in respect of information society services may use the service and provide personal data. In Germany, which is the Platform's default region, this age is 16 years; in other EU countries it may be different (as a general rule — 16 years, unless national law establishes a lower age, but not below 13 years). The applicable threshold depends on your country of habitual residence.
We do not knowingly collect the personal data of children. If we become aware that a child's data has been provided without proper consent, we will take reasonable measures to delete it. If you believe that we may have processed a child's data, please inform the controller of this.
23. Changes to this Policy
We have the right to update this Privacy Policy from time to time in connection with changes in the operation of the Platform, the composition of processors, legislation or data processing practices. The current version is always available on the relevant page of the Platform; the date of the last update is indicated in the text of the document.
We strive to inform users of material changes by available means. Continued use of the Platform after the changes take effect signifies your familiarisation with the updated Policy. We recommend that you periodically review this document.
24. Contact
For all matters relating to the processing of personal data, as well as to exercise your rights as a data subject, you may contact the controller at the email address hello@inwego.com.
The complete contact and identification details of the controller, as well as the details of the responsible person, are set out on the "Legal information" (Impressum) page at /imprint. This Privacy Policy applies alongside the Terms of Use (/terms) to the extent the latter have been published. We will make reasonable efforts to consider your request in a timely manner in accordance with the requirements of the GDPR.