Imprint

Website Operator

Leon Schurer
Eichbuschallee 40

12437 Berlin


Contact

contact@basilbytes.com

Privacy Policy


§ 1 General Information

This privacy policy provides you with detailed information about what happens to your personal data when you visit our website basilbytes.com. Any data that allows you to be personally identified is personal data. When processing your data, we strictly adhere to the legal requirements, in particular the General Data Protection Regulation (“GDPR”). It is very important to us that your visit to our website is completely secure.


§ 2 Data Controller

Responsibility for the collection and processing of personal data on this website, under data protection law, lies with:

Name: Basil Bytes Interactive

Address: Eichbuschallee 40, 12437, Berlin

Country: Germany

Email: contact@basilbytes.com

Phone: +49 15254961922


§ 3 Contacting Us

When you contact us, including by email, the data transmitted in the process, including your contact details, will be stored in order to process your inquiry and to be available for any follow-up questions. This data will not be disclosed to third parties without your explicit consent.

The processing of your personal data is carried out exclusively on the basis of your consent given pursuant to Art. 6(1)(a) GDPR. You have the right to withdraw this consent at any time and without giving reasons. An informal notification by email to us is sufficient for the withdrawal. The lawfulness of the data processing carried out prior to the withdrawal remains unaffected by the withdrawal.

The transmitted data will be stored by us until you ask us to delete it, withdraw your consent to its storage, or the purpose for storing the data no longer applies. Mandatory statutory retention periods remain unaffected.


§ 4 Newsletter

On our website, you can subscribe to our newsletter. For sending the newsletter, we use the service “Brevo,” provided by Brevo SAS, 8 rue de Londres, 75009 Paris, France (“Brevo”).

When you sign up, we share the data you enter (email address) with Brevo. Registration uses a double opt-in process: after submitting the form, you will receive an email containing a confirmation link. Only after clicking this link does your subscription become active and you are added to our newsletter list. This ensures that only you can register with your own email address.

As part of the registration process, we also store your IP address as well as the date and time of your sign-up and confirmation. This is done solely to document your consent and to allow us to investigate any potential misuse of your personal data.

The processing of your data is based on your consent (Art. 6(1)(a) GDPR). You may withdraw this consent at any time with future effect by using the unsubscribe link included in every newsletter email, or by contacting us at contact@basilbytes.com. The lawfulness of processing carried out prior to your withdrawal remains unaffected.

We have entered into a data processing agreement with Brevo in accordance with Art. 28 GDPR. For more information on how Brevo handles your data, please see Brevo’s privacy policy: https://www.brevo.com/legal/privacypolicy/


§ 5 Cloudflare Turnstile

To protect our contact and newsletter forms from automated spam and abuse, we use the "Turnstile" service provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA ("Cloudflare").

Turnstile verifies whether your website visit originates from a human or from automated, malicious use. Unlike traditional CAPTCHA services, Turnstile is designed to work largely in the background, without requiring you to solve visual puzzles. For this verification, certain technical data (such as your IP address, browser and device characteristics, and behavioral signals) is transmitted to Cloudflare and may be processed on servers located outside the European Economic Area, including in the United States.

Cloudflare participates in the EU-U.S. Data Privacy Framework, and Cloudflare has also agreed to the EU Standard Contractual Clauses (SCCs) as an additional safeguard for data transferred outside the EEA.

The use of Cloudflare Turnstile is based on our legitimate interest in protecting our website from automated spam and abuse (Art. 6(1)(f) GDPR), and, where the form is linked to a consent-based action such as a newsletter signup, on your consent (Art. 6(1)(a) GDPR).

Further information on Cloudflare Turnstile and Cloudflare's privacy policy can be found at: https://www.cloudflare.com/privacypolicy/


§ 6 Use and Disclosure of Data

We assure you that personal data you provide to us, e.g. by email (such as your name, address, or email address), will not be sold to third parties or otherwise used commercially. Your data will be processed exclusively for the purpose of corresponding with you and fulfilling the purpose for which you provided the data to us. As part of payment processing, your payment data will be forwarded to the commissioned financial institution.

Data automatically collected when you visit our website is used exclusively for the purposes mentioned above. The data is not used for any other purpose.

The protection of your personal data is important to us. We therefore generally do not disclose your data to third parties, unless there is a legal obligation to do so or you have given us your explicit consent.


§ 7 Encryption (SSL/TLS)

Our website uses SSL/TLS encryption to ensure the security and protection of the transmission of confidential content. This applies in particular to requests that you, as a website visitor, send to us as the website operator. An encrypted connection is indicated by “https://“ in your browser’s address bar as well as the lock symbol in your browser bar.

Activating SSL/TLS encryption ensures that the data you send to us cannot be read by unauthorized third parties.


§ 8 Storage Duration

Your personal data transmitted to us via our website will only be stored for as long as necessary to fulfil the respective purpose of the data processing. In accordance with commercial and tax retention obligations, storage of certain data may last up to 10 years.


§ 9 Your Data Protection Rights

As a data subject of the data processing, you have the following rights, in accordance with statutory provisions, with respect to your personal data vis-à-vis the controller:


A. Right of Withdrawal

Many data processing operations are only possible with your explicit consent. If the processing of your data is based on your consent, you have the right, pursuant to Art. 7(3) GDPR, to withdraw this consent at any time with effect for the future. The lawfulness of the data processing carried out on the basis of your consent up until the withdrawal remains unaffected. The storage of data for billing and accounting purposes is not affected by a withdrawal.


B. Right to Information

Pursuant to Art. 15 GDPR, you have the right to request confirmation from us as to whether we process your personal data. If this is the case, you are entitled to information about this data, including the purposes of processing, the categories of data processed, the recipients or categories of recipients to whom the data has been or will be disclosed, the planned storage period or the criteria for determining it, the existence of a right to rectification, erasure, restriction of processing, objection to processing, complaint to a supervisory authority, the origin of the data if it was not collected from you, the existence of automated decision-making including profiling and, where applicable, meaningful information about the logic involved as well as the significance and envisaged consequences of such processing for you, as well as your right to be informed about the safeguards pursuant to Art. 46 GDPR in the event your data is transferred to third countries.


C. Right to Rectification

You have the right, pursuant to Art. 16 GDPR, to request at any time the correction of inaccurate personal data concerning you and/or the completion of your incomplete data.


D. Right to Erasure

You have the right, pursuant to Art. 17 GDPR, to demand the erasure of your personal data if one of the following reasons applies:

a. Your personal data is no longer necessary for the purposes for which it was collected or otherwise processed. b. You withdraw your consent on which the processing was based pursuant to Art. 6(1)(a) or Art. 9(2)(a) GDPR, and there is no other legal basis for the processing. c. You object to the processing pursuant to Art. 21(1) GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Art. 21(2) GDPR. d. Your personal data has been processed unlawfully. e. We are obliged to erase the personal data under a legal obligation under Union law or the law of the Member State to which we are subject. f. The personal data was collected in relation to the offer of information society services referred to in Art. 8(1) GDPR.

This right may be restricted under the following circumstances, if the processing is necessary:

a. to comply with a legal obligation which requires processing under Union law or the law of the Member State to which we are subject, or to perform a task carried out in the public interest or in the exercise of official authority; b. to fulfil a legal obligation requiring processing under Union or Member State law to which we are subject, or to carry out a task in the public interest or in the exercise of official authority vested in us; c. for reasons of public interest in the area of public health pursuant to Art. 9(2)(h) and (i) as well as Art. 9(3) GDPR; d. for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes pursuant to Art. 89(1) GDPR, insofar as the right referred to above is likely to render impossible or seriously impair the achievement of the objectives of that processing; or e. for the establishment, exercise, or defence of legal claims.

If we have made your personal data public and are obliged, pursuant to the above provisions, to erase it, we shall take reasonable measures, including technical measures, taking into account available technology and the cost of implementation, to inform data controllers processing this data that you, as the data subject, have requested the erasure of any links to, or copies or replications of, your personal data.


E. Right to Restriction of Processing

Pursuant to Art. 18 GDPR, you have the right to request the restriction of the processing (blocking) of your personal data. To exercise this right, you may contact us at any time. Our contact details can be found in the legal notice. Restriction of processing may be requested in the following cases:

a. If you dispute the accuracy of your personal data stored by us, we generally need time to verify this. For the duration of this verification, you have the right to demand restriction of the processing of your personal data. b. If the processing of your personal data was/is unlawful, you may request the restriction of data processing instead of its erasure. c. If we no longer need your personal data, but you need it to establish, exercise, or defend legal claims, you have the right to demand restriction of the processing of your personal data instead of its erasure. d. If you have lodged an objection pursuant to Art. 21(1) GDPR, a balancing of your interests and ours must take place. As long as it is not yet clear whose interests prevail, you have the right to demand restriction of the processing of your personal data.

Following a restriction of the processing of your personal data, such data may generally only be processed with your consent. Exceptions apply in certain legally defined cases, such as for the establishment of legal claims or the protection of public interests.


F. Right to Notification

Should you exercise your right to rectification, erasure, or restriction of processing of your personal data, we are obliged, pursuant to Art. 19 GDPR, to notify all recipients to whom the data has been disclosed. This does not apply if such notification proves impossible or involves disproportionate effort. Upon request, we will inform you of these recipients.


G. Protection from Automated Decisions (Profiling)

Pursuant to Art. 22 GDPR, you have the right not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning you or similarly significantly affects you.

This does not apply if the decision

a. is necessary for entering into, or the performance of, a contract between you and us, b. is authorized by Union or Member State law to which the controller is subject and which lays down suitable measures to safeguard your rights, freedoms, and legitimate interests, or c. is based on your explicit consent.

However, decisions referred to in points (a) to (c) may not be based on special categories of personal data as referred to in Art. 9(1) GDPR, unless Art. 9(2)(a) or (g) applies and suitable measures to protect your rights, freedoms, and legitimate interests are in place.

In the cases referred to in points (a) and (c), we take reasonable measures to safeguard your rights, freedoms, and legitimate interests. These include, at a minimum, the right to obtain human intervention on our part, to express your point of view, and to contest the decision.


H. Right to Data Portability

In the event of processing of your personal data based on your consent pursuant to Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, or on a contract pursuant to Art. 6(1)(b) GDPR, and carried out by automated means, you have the right, pursuant to Art. 20 GDPR, to receive the data you provided to us in a structured, commonly used, and machine-readable format and to transmit that data to another controller, or to request that we transmit it directly to another controller, where technically feasible.


I. Right to Object

Where we process your personal data on the basis of a balancing of interests pursuant to Art. 6(1)(f) GDPR, you have the right to object to this processing at any time for reasons arising from your particular situation; this also applies to profiling based on this provision. You can find the applicable legal basis for the processing in this privacy policy.

If you object, we will no longer process your affected personal data, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defence of legal claims (objection pursuant to Art. 21(1) GDPR).

If your personal data is processed for direct marketing purposes, you have the right to object to this processing at any time; this also applies to profiling insofar as it is related to such direct marketing. In the event of an objection, your personal data will no longer be used for direct marketing purposes (objection pursuant to Art. 21(2) GDPR).

With regard to the use of information society services, and notwithstanding Directive 2002/58/EC, you have the option to exercise your right to object by automated means using technical specifications.


J. Right to Lodge a Complaint with the Competent Supervisory Authority Pursuant to Art. 77 GDPR

In the event of violations of the provisions of the GDPR, data subjects have the right to lodge a complaint with a competent supervisory authority. The complaint may in particular be lodged in the Member State of the data subject’s habitual residence, place of work, or the place of the alleged violation. The right to lodge a complaint under this provision exists without prejudice to any other administrative or judicial remedy.

Our competent supervisory authority is:

Berlin Commissioner for Data Protection and Freedom of Information

Alt-Moabit 59-61

10555 Berlin

Entrance: Alt-Moabit 60

Phone: 030/138 89-0

Email: mailbox@datenschutz-berlin.de

Website: https://www.datenschutz-berlin.de


§ 10 Validity and Amendment of this Privacy Policy

This privacy policy took effect on 21 August 2026. We reserve the right to amend this statement as needed and in compliance with applicable data protection laws. This may become necessary, for example, to meet new legal requirements or to reflect changes to our website or to new services offered via our website. The version of the privacy policy currently available on our website at the time of your visit is binding.

In the event of changes to this privacy policy, we will publish the updated version on this page in order to comprehensively inform you about which personal data we collect, how we process it, and under what conditions we may disclose it, where applicable.

For proper application, the privacy policy must be easily found and accessible online for users, e.g. in the footer of your website. If you collect personal data directly from data subjects, you are obliged under Art. 13 GDPR to inform data subjects at the time of data collection — for example, when registering for a newsletter or filling out a contact form. If you use the policy offline, printed copies should be made available to data subjects.

The privacy policy must always be individually tailored to your current data processing activities. If these processes change, you must update the policy without delay and make the updated version available.

These usage notes are for general information purposes only. We are not a law firm and therefore cannot provide legal advice or legal representation. If you have questions about the use or legal validity of this document, or need specific support, please contact a licensed attorney.