1. Data Controller
The data controller responsible for data processing on this website is:
Human-me
(Address will be added here)
Email: (Will be added)
2. Data We Collect
We collect and process the following personal data:
- Account data: Name, email address, phone number, date of birth, profile photo
- Location data: Approximate location (with your consent) to connect you with nearby service providers
- Service data: Appointment details, service descriptions, reviews, messages between users
- Payment data: Payment transactions are processed by Stripe, Inc. We store only transaction references, not card numbers
- Usage data: IP address, browser type, access times (server logs)
- Documents: Uploaded documents such as certificates or insurance documents (providers only)
3. Legal Basis (GDPR Art. 6)
- Contract performance (Art. 6(1)(b)): Processing your bookings, payments, and service delivery
- Consent (Art. 6(1)(a)): Location sharing, optional notifications, cookies
- Legitimate interest (Art. 6(1)(f)): Platform security, fraud prevention, analytics
- Legal obligation (Art. 6(1)(c)): Tax records, regulatory compliance
4. Third-Party Services
- Stripe, Inc. — Payment processing. Stripe processes payments under their own privacy policy:
stripe.com/privacy
- Google OAuth — Optional login via Google account
- Telegram Bot API — Optional notifications and account linking
- Supabase — File storage for profile photos and documents
- Brevo (SMTP) — Email delivery for confirmations and reminders
5. Data Retention
We retain your personal data for as long as your account is active. When you delete your account, all personal data is permanently removed from our systems. Financial transaction records are retained for the legally required period (10 years under German tax law, AO Section 147).
6. Your Rights (GDPR Art. 15-22)
You have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Delete your data / right to be forgotten (Art. 17)
- Restrict processing (Art. 18)
- Data portability (Art. 20)
- Object to processing (Art. 21)
- Withdraw consent at any time (Art. 7(3))
To exercise these rights, contact us at the email address listed above or use the account deletion feature in your profile settings.
7. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for complaints is the data protection authority of the German federal state where our company is registered.
8. Data Security
We use industry-standard security measures including HTTPS encryption, secure password hashing (bcrypt), and Stripe's PCI DSS certified payment infrastructure to protect your data.
9. Cookies
We use only essential cookies required for the operation of the platform (session management, language preference). We do not use tracking or advertising cookies.