Privacy
1. Who is responsible for your data
RestoreTrust UG (haftungsbeschränkt)
Franz-Joseph-Straße 11
80801 Munich, Germany
Represented by managing director David Huber. For questions about data protection, contact us at info@restoretrust.io.
This notice covers the restoretrust.io website and enquiries you send through the contact form or by email. Use of the RestoreTrust Console is covered by the separate product privacy notice.
2. Hosting and website security
We use Cloudflare to host and deliver this website. The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare processes the connection data your browser sends when you open a page. This includes your IP address, the time and destination of the request, technical details about your browser and operating system, and, where available, the referring page.
This processing allows us to deliver content, identify technical errors, and protect the website against attacks and abusive requests. It may involve access and security logs. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to provide a secure and reliable website.
Cloudflare operates a global network. Data may be processed outside the European Union and European Economic Area. Further information is available in Cloudflare’s privacy policy and in section 6 below.
3. Language preferences, cookies, and embedded content
We do not use Google Analytics, Matomo, or advertising pixels on this website.
When you change the language, the website remembers your choice for the current tab session in your browser’s session storage. The entry, named restoretrust.locale, contains only the chosen language. It contains no personal identifier and is not used for visitor analytics. You can remove it by clearing the website’s stored data; storage normally ends with the tab session. If you have not selected a language, the website uses your browser’s language preference.
The purpose of this storage is to display the website in your chosen language during your visit. Access to browser storage is based on section 25(2), no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG). Where personal data is involved, processing is based on Art. 6(1)(f) GDPR and our legitimate interest in applying your language choice.
Cloudflare may also use security cookies, depending on the protection features in use. For example, __cf_bm helps detect automated requests and expires after 30 minutes of inactivity. cf_clearance can record that a security check has been passed; its lifetime depends on the feature and configuration. These cookies help protect access to the website. The exemption from consent under section 25(2), no. 2 TDDDG applies only insofar as storage or access is strictly necessary to provide the website securely. Cloudflare explains the functions in its cookie documentation.
Fonts and images are served with the website, without embedding external font or image services. When you open an external link, the linked website’s own privacy notice applies.
4. Contact form and email
When you contact us, we process your contact details and message to handle your enquiry and reply. For enquiries about a contract with you, the legal basis is Art. 6(1)(b) GDPR. For other enquiries, including those from a company’s contact person, the basis is Art. 6(1)(f) GDPR. Our legitimate interest is to respond to business and general enquiries.
Contact form: The form uses Formspree, Inc., USA. Your name, email address, selected topic, message, and optional company name are sent to Formspree only when you submit the form. Technical connection data, such as your IP address, time of submission, and browser information, is also processed. Formspree receives the message, processes it for spam protection, stores it for handling, and forwards it to our email inbox. See Formspree’s privacy policy for more information.
Email: We use Microsoft 365 / Exchange Online for business email. Microsoft processes messages, sender and recipient addresses, and the technical data needed for delivery, storage, and security. This also applies to enquiries forwarded by Formspree. Details of data processing are available in the Microsoft Products and Services Data Protection Addendum.
You choose whether to contact us. We need the fields marked as required to identify and handle your enquiry. The form cannot be submitted without them. You can also email us directly. Please do not send passwords, backup files, or other credentials.
5. How long we keep data
We keep personal data for as long as it is needed for the relevant purpose. We then delete it unless a legal retention obligation or another lawful reason requires further storage.
- Access and security data: Retention depends on the need to deliver the website, diagnose errors, and prevent or investigate security incidents, as well as the Cloudflare features used for these purposes. Where an incident occurs, relevant logs may be needed until it has been resolved.
- Enquiries: We keep messages for as long as they are needed to handle the enquiry and any related follow-up questions. This includes submissions stored by Formspree and copies in our email inbox. Messages that constitute commercial or business correspondence are generally subject to a six-year retention period from the end of the relevant calendar year (section 257 of the German Commercial Code and section 147 of the German Fiscal Code). Retention required by law is based on Art. 6(1)(c) GDPR. Longer storage to establish, exercise, or defend legal claims may be based on Art. 6(1)(f) GDPR.
- Language choice: This is stored for the current tab session, as described in section 3.
6. Recipients and processing outside Europe
For the purposes described above, Cloudflare, Formspree, and Microsoft receive the data they need to provide their services. Their subprocessors may also be involved. We disclose data to authorities or other recipients where required by law or where necessary to establish, exercise, or defend legitimate legal claims.
Cloudflare and Formspree process data in the USA, among other locations. Microsoft may also process data through affiliates or service providers outside the European Economic Area.
For transfers to countries not covered by an applicable adequacy decision, Cloudflare’s and Microsoft’s data protection terms provide for safeguards including EU Standard Contractual Clauses. Formspree also states that it uses Standard Contractual Clauses in its role as a processor. These clauses require recipients to protect the transferred data. Further information is available in the Cloudflare Data Processing Addendum, the Microsoft terms linked above, and Formspree’s privacy and security information. You can request information about the safeguards applicable to your data and a copy by emailing info@restoretrust.io.
7. Your rights
Subject to the conditions set out in law, you have the right to access, rectification, erasure, restriction of processing, and data portability (Arts. 15–18 and 20 GDPR). Where processing is based on your consent, you may withdraw it at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before it.
Right to object: You may object to processing based on Art. 6(1)(f) GDPR on grounds relating to your particular situation (Art. 21 GDPR). Send your request to info@restoretrust.io.
You may also lodge a complaint with a data protection supervisory authority, particularly in the place of your habitual residence, workplace, or the alleged infringement. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Postfach 1349, 91504 Ansbach, Germany.
8. Automated decisions
We do not make decisions based solely on automated processing that have legal or similarly significant effects on you when you use this website. We do not carry out profiling of this kind either.
9. Changes to this notice
We update this notice when the website’s data processing or the applicable requirements change.
Last updated: 7 October 2026.