Data protection declaration
for Scriptfabrik.info and the associated services
This data protection declaration informs how the Scriptfabrik B.V. Personal data when used The website www.scriptfabrik.info, from customer accounts, orders, digital products, software and licensing offers, Hosting, domain, server and IT services, individual programming, web design and communication services, Evaluation and support functions are processed.
The processing of personal data takes place in particular on the basis of the General Data Protection Regulation (EU) 2016/679 (GDPR / AVG), which Dutch Uitvoeringswet Algemene verordening gegevensbescherming (UAVG) as well as to the extent electronic communication, cookies or comparable technologies are affected, the Dutch Telecommunicatiewet.
In addition, the relevant provisions of Dutch law apply. and the law of the European Union.
Insofar as an offer is aimed specifically at persons in another state, In addition, mandatory applicable data protection and telecommunications regulations of this state are taken into account.
1. Accountable person
Responsible persons in the sense of the GDPR for those in this data protection declaration The processing described is:
Scriptfabrik B.V.
Pastoor Jacobsweg 27
6226 VV Maastricht
Netherlands
KvK number: 42137687
VAT identification number (BTW-ID):NL869888316B01
E-mail:
welcome@scriptfabrik.info
Website: https://www.scriptfabrik.info
Data protection requests can be sent to the above at any time e-mail address.
As far as Scriptfabrik should be legally obliged, a to appoint data protection officers, whose contact details published in accordance with legal requirements.
2. Definitions and scope
Personal data is any information relating to a an identified or identifiable natural person.
For this purpose, in particular name, contact details, address, account and contract data, payment information, IP addresses, equipment information, usage data, licence information and communication data.
Processing means any operation related to: personal data, in particular their collection, collection, organisation, storage, adaptation, evaluation, use, Transmission, restriction or deletion.
This data protection declaration applies to processing operations, is responsible for Scriptfabrik B.V. within the meaning of the GDPR.
Service providers such as payment providers, registrars or other companies For certain own processing purposes be responsible for data protection law. For their own separate Processing applies in addition to their data protection notices.
3. Principles of data processing
Scriptfabrik processes personal data according to the principles legality, good faith processing, transparency, purpose limitation, data minimisation, accuracy, memory limitation, and Integrity and confidentiality in accordance with art. 5 GDPR.
Personal data will be used exclusively for specified, Processed for clear and legitimate purposes.
Scriptfabrik processes only those personal data, which are necessary and appropriate for the respective purpose.
4. Legal basis of processing
Personal data will only be processed if a There is a legal basis.
Depending on the processing, the following legal bases are in particular: in accordance with Art. 6 par. 1 GDPR under consideration:
- Article 6(3) 1 lit. a GDPR – Consent:in particular for unnecessary cookies, tracking technologies, optional personalizations, newsletters or certain Marketing measures.
- Article 6(3) 1 lit. b GDPR – Contract and pre-contractual measures:in particular for registration, ordering, payment, provision of digital products, licenses, hosting, Programming, web design, support and other contractual benefits.
- Article 6(3) 1 lit. c GDPR – legal obligation:in particular for accounting, invoicing, tax retention obligations, administrative requests and other legal obligations of proof or documentation.
- Article 6(3) 1 lit. d GDPR – vital interests:insofar as processing is carried out exceptionally in order to protect vital The interests of a person are required.
- Article 6(3) 1 lit. e GDPR – public interest:as far as Scriptfabrik exceptionally due to a legal Basis performs a corresponding task.
When processing on the basis of legitimate interests, the interests of Scriptfabrik or a third party against the interests, fundamental rights and freedoms of the data subject.
If a processing is based on a consent, this can be done at any time. with effect for the future.
The lawfulness of the processing carried out until the revocation remains without prejudice to this.
5. Provision of personal data
Certain personal data are required to create a customer account set up, conclude a contract, process payments, to provide digital content or other services.
Without the necessary data, Scriptfabrik can or may not offer or perform the desired service.
Voluntary information shall be treated accordingly as voluntary information.
A refusal of consent in unnecessary analysis, Personalization or marketing technologies are generally prevented not the use of the essential functions of the website.
6. Visit to the website and server logs
When accessing the website, technically necessary information is processed.
These may include, in particular:
- IP address;
- the date and time of access;
Processing takes place in particular for technical provision the website, ensuring system security, error analysis, Attack detection, abuse prevention and ensuring a stable operation.
The legal basis is in particular Art. 6 par. 1 lit. f GDPR.
Insofar as the website is accessed directly at the initiation of the contract or Contract implementation, can additionally art. 6 par. 1 lit. b GDPR Relevant.
Server and security protocols are stored only as long as such as for operation, error analysis, attack detection or demonstration purposes are required.
Longer storage takes place in particular when a concrete Security incident, litigation or legal obligation This makes it necessary.
7. Customer account and registration
When registering and using a customer account, in particular, the following data are processed:
- name;
- user name;
- e-mail address;
- telephone number, if provided or required;
- invoice address;
- where applicable, delivery address;
- encrypted password value;
- security features;
- login and session data;
- order history;
- download history;
- licensing information;
- communication and support data;
Processing takes place for the purpose of setting up, managing and securing of the customer account as well as for contract processing and provision of the offered functions.
The legal basis is in particular Art. 6 par. 1 lit. b GDPR.
Safety-relevant processing can additionally be Art. 6 para 1 lit. f DSGVO.
Passwords are not stored in plain text.
Security-relevant logins and account changes can be logged.
8. Orders, contracts and invoices
For orders and other contractual relationships, in particular the following personal data are processed:
- name and contact details;
- invoice address;
- where applicable, delivery address;
- shopping cart and order data;
- product and performance data;
- contract duration and tariff;
- performance status;
- accounting data;
- payment status;
- booking and transaction data;
- communication data;
- Revocation, complaint and warranty data.
The processing serves in particular the contract initiation, contract implementation, digital provision or delivery; billing, payment allocation, customer support and asserting, exercising or defending legal claims.
The legal basis is in particular Art. 6 par. 1 lit. b GDPR.
As far as statutory accounting, tax or storage obligations In addition, the processing takes place on the basis of Art. 6 para 1 lit. c GDPR.
9. Digital content, downloads and software
Scriptfabrik can in particular software, scripts, plugins, web applications, templates, digital templates, graphics, offer files or other digital content.
When providing such products, additional processing may be carried out:
- time of download;
- download status;
- IP address;
- technical equipment information;
- product and version information;
- update information;
- compatibility data;
- security and misuse features.
The processing serves in particular to provide the product, documentation of contract performance, technical support, Updating and preventing misuse.
The legal basis is in particular Art. 6 par. 1 lit. b GDPR.
Measures for the prevention of abuse and fraud can additionally Article 6(3) 1 lit. f DSGVO.
10. License management and activation
Where digital products are subject to licensing or activation, in particular, the following data may be processed:
- licence key;
- Customer number or user identification;
- product identification;
- activation status;
- time of activation;
- domain or installation identifier as required for the license;
- technical equipment or server information;
- version information;
- IP address;
- blocking or abusive features.
The processing serves to provide and control the acquired license, enforcement of the agreed license scope, Provision of updates and support and prevention unauthorised multiple use.
A device, installation or domain license control shall be carried out only to the necessary and proportionate extent.
API and technical access
As far as Scriptfabrik API accesses or other technical interfaces In particular, access keys, API identifiers, retrieval times, IP addresses, called functions, Transmission volumes, status codes and security information processed.
The processing is used for authentication, provision, Billing, error analysis, limiting misuse ensuring IT security.
The legal basis is in particular Art. 6 par. 1 lit. b GDPR and with regard to security measures Art. 6 para. 1 lit. f GDPR.
Hosting, domain, server and email services
Processed for hosting, domain, server, cloud or email services Scriptfabrik depending on the respective order in particular Customer master data, contract and billing data and technical Operational information.
As far as customers have their own personal data on von Scriptfabrik stored or processed systems provided and even via Purpose and means of this processing decide, is in principle the customer responsible in the sense of the GDPR.
In these cases, Scriptfabrik may, in the sense of Art. 28 GDPR.
Where necessary, a separate agreement for Order processing completed.
For domain registrations, the necessary for registration Information to the respective registrar, the responsible registry or other competent contracting entities.
The information required shall in particular address: according to the respective domain extension and the specifications of the respective Registration body.
For misuse reports, security incidents or lawful Requests by authorities can provide technical usage and allocation data Processed to the extent required and permitted by law or be disclosed.
13. Individual programming and web design
For individual programming, contract development, Processed software adaptation, web development or web design Scriptfabrik in particular those provided by the customer Contact, project, contract, content and access data.
These may include, for example:
- name and contact details;
- Project description;
- technical requirements;
- website and server access;
- database access;
- API accesses;
- files and content provided;
- communication data;
- Test data.
Customers should, as far as possible, only such access and provide personal data necessary to carry out the respective orders are required.
As far as Scriptfabrik has access to personal data within the framework of a project receives data for the processing of which the customer is responsible, it is checked whether an agreement for order processing in accordance with Art. 28 GDPR is required.
14. Support and error analysis
For support requests, in particular contact information, account data, contract information, error messages, technical information, log files, screenshots, provided files and communication content are processed.
Remote access to systems occurs only if this is necessary for processing required and agreed upon or released accordingly.
Temporary logs, screenshots or backup copies are deleted after completion of the error analysis, unless there are legal or legitimate reasons for further storage.
15. Payment processing
For the processing of payments, the necessary personal Data to the payment service provider selected during the ordering process and, where applicable, to participating banks, card companies; or other payment agencies.
In particular, the following can be processed:
- name;
- invoice address;
- e-mail address;
- order or invoice number;
- the amount;
- currency;
- type of payment;
- transaction identification code;
- payment status;
- the date of payment;
- technical or fraudulent test characteristics.
Full card or online banking access data will be Generally processed by the respective payment service provider and not stored by Scriptfabrik, if during the payment process is not expressly stated otherwise.
Payment service providers may: Fraud prevention and legal audits themselves be responsible for data protection law.
The payment service provider actually used shall: especially in the checkout or immediately when selecting the payment method indicated.
16. Revocation, refund and complaints
For revocations, refunds, complaints, complaints or In particular, the following data can be processed in warranty cases:
- name and contact details;
- order and contract data;
- product data;
- payment information;
- communication content;
- evidence;
- refund information;
- where applicable, images or technical files.
The processing takes place for processing the respective operation, Contract performance, fulfilment of statutory consumer rights and asserting, exercising or defending legal claims.
17. Contact by e-mail and contact form
When contacted by e-mail, contact form or via another the contact function provided by Scriptfabrik will be processed the information transmitted.
For this purpose, in particular name, e-mail address, subject, message content, time of contact and, where applicable, Customer, order or contract information.
Legal basis depends on the content of the request in particular Art. 6 para 1 lit. b GDPR or art. 6 par. 1 lit. f GDPR.
As far as a legal obligation is concerned, the processing may Article 6(3) 1 lit. c GDPR is based.
18. Contact via WhatsApp
Scriptfabrik offers users the opportunity to volunteer via WhatsApp Get in touch.
The provider of the WhatsApp service for users in the European Region is:
WhatsApp Ireland Limited
Merrion Road
Dublin 4
D04 X2K5
Ireland
When contacting via WhatsApp, in particular telephone number, profile information, message content, files transmitted, time of communication and other technically processed by WhatsApp communication and connection information is processed.
Communication via WhatsApp is voluntary. Users can alternatively in particular by e-mail with Scriptfabrik Make contact.
Legal basis for processing by Scriptfabrik depends on of the request in particular Art. 6 para. 1 lit. b GDPR or Art. 6 para 1 lit. f GDPR.
WhatsApp processes personal data within its services partly under own data protection responsibility.
WhatsApp is part of the meta group of companies. As part of the service can provide data according to the data protection information of WhatsApp are also processed by other meta-companies or service providers.
For independent data processing by WhatsApp, the Data protection information from WhatsApp.
19 Support and communication processes
Communication and support processes are stored only for as long as such as for processing, follow-up questions, quality assurance, Contract implementation, purposes of proof or legal obligations is necessary.
Communication content is not without a corresponding legal basis used for non-material purposes.
20. Reviews, comments and public content
As far as Scriptfabrik on the website rating, commentary, offers product question or comparable public functions, in particular, the following information may be processed:
- username or public profile;
Publicly marked content can be used for other users of The website is visible.
Technical metadata and order information can be used internally to verify the authenticity of a review.
This information shall not be displayed to the public to the extent that: is not expressly communicated.
Users should not include confidential information in public contributions, special categories of personal data or personal data publish data of uninvolved third parties.
21. Moderation and abuse of public functions
As far as public content or reviews are offered, Scriptfabrik may review and moderate content, in particular to: spam, manipulation, illegal content, malware, Insults, fake reviews or other abuse to prevent.
Here, content, account, order, security and technical metadata are processed.
The legal basis is in particular Art. 6 par. 1 lit. f GDPR due to legitimate interest in secure and trustworthy Platform functions and, where applicable, type. 6 par. 1 lit. c GDPR for legal obligations.
22. Wish Lists and Favorites
As far as users include products, services or content in wish lists or Favorites can be saved, Scriptfabrik processes the stored Content and the contents required to provide the function Account information.
The legal basis is in particular Art. 6 par. 1 lit. b GDPR, as far as the function is part of the offered customer account.
23. Product recommendations and personalization
Scriptfabrik can make functional recommendations within the website for example on the basis of products considered or purchased, Show categories or account settings.
A cross-device or promotional Profile formation only takes place if there is a suitable legal basis for this exists and – as far as legally necessary – prior consent has been obtained.
Optional personalization functions can be provided via the respective account or data protection settings are deactivated, as far as a corresponding function is offered.
24. Search and sorting
When using the search or filter functions, in particular Search terms, filters, language, product information, Availability, reviews, clicks and technical session data processed.
The processing serves to provide the requested Search and sorting functions.
The legal basis is in particular Art. 6 par. 1 lit. b GDPR or Art. 6 para 1 lit. f GDPR based on the legitimate interest in User-friendly and relevant search results.
25. Newsletter and electronic direct mail
Newsletters and other electronic advertising are generally only if there is an effective consent or A legal exception applies.
In particular, the following data can be processed for the application:
- e-mail address;
- date of notification;
- time of confirmation;
Scriptfabrik can use a double opt-in process, to prevent abusive registrations and the registration to be able to prove.
Electronic contact data, the script factory in connection with has received the sale of a product or service; within the legally permitted limits for advertising used for own similar products or services.
Insofar as such a legal exception is used, the Customer both when collecting his contact data and in each Advertising a simple and free way, to object to the advertising use.
Each electronic advertising message contains a simple Option to cancel or object.
Consent can be given at any time with effect for the future revoked.
After unsubscribing, the relevant e-mail address can be blocked lists are stored, if necessary, to take the advertising objection permanently into account.
26. Telephone advertising
Telephone advertising to consumers only takes place, insofar as applicable to the Netherlands and European regulations have a sufficient legal basis.
If prior consent is required, no telephone advertising without such consent.
A revocation or objection against telephone advertising will considered for the future.
27. Vouchers and promotions
For vouchers, discount codes, sweepstakes or other promotions in particular account, order, code, redemption, Participation and abuse test data are processed.
The processing takes place to carry out the respective action, Contract processing and prevention of misuse.
As far as additional personal data for a specific action or processing operations are required, shall be supplemented by: Data protection information provided.
28. Cookies and similar technologies
Scriptfabrik uses cookies, local memory, pixels, Scripts, device identifiers and similar technologies.
These technologies can provide information on the terminal of a Store users or information already stored there access.
The use takes place in compliance with the GDPR and the relevant Regulations of the Dutch Telecommunicatiewet.
Technically essential technologies can be used without Consent is used to transfer a Communication or for a user expressly desired service is required.
These may include, in particular:
- shopping cart functions;
- Login and authentication;
- meeting management;
- safety functions;
- load distribution;
- language selection;
- storage of data protection settings;
- Storage of cookie consent.
Data protection-friendly analysis technologies can be used in individual cases They are used without consent, provided that they Applicable Dutch regulations, little or no have an impact on privacy and all legal Conditions are met.
analytics, personalization, affiliate, advertising and Tracking technologies requiring consent, are activated only after the user has voluntarily has given informed and clear consent.
Technologies requiring consent are not already activated before giving the required consent.
Not necessary cookie or tracking categories are not Preselected.
The possibility of rejecting unnecessary technologies is made clear and easily accessible.
The use of the essential functions of the website shall not made dependent that users are not required Tracking technologies to the extent that no voluntary There would be more consent.
The specifically used cookies and comparable technologies, their providers, purposes, storage period and possible Third country transfers shall be made in the current Cookie overview or consent management.
29 Consent management
Through the consent management, users can use optional Accept and reject cookie and processing categories and their Change the selection later.
In particular, the following information can be processed:
- consent status;
- selected categories;
- the date of the decision;
- version of consent information;
The processing serves to implement the user decision as well as the necessary proof of consent given or refused.
A given consent can at any time with effect for the future revoked.
For this purpose, a permanently accessible link such as “Cookie settings” or an equivalent function is provided.
The withdrawal of a consent is basically just as simple Possible as their grant.
30. Analysis and range measurement
Where Scriptfabrik uses analysis or range measurement services, in particular, the following information may be processed:
- page views;
- meetings;
- clicks and interactions;
- source of origin;
- approximate region;
- browsers;
- operating system;
- type of equipment;
- technical identifiers;
- Conversion events.
Analysis and tracking services subject to consent are used exclusively after prior consent.
If an own or particularly data protection-friendly analysis service used for which under the applicable Dutch law no consent is required, this will be in the Cookie overview shown accordingly.
IP addresses and technical identifiers shall be abbreviated as far as possible; pseudonymized or deleted early.
Evaluations shall, where possible, be carried out in aggregated form.
31. Affiliate marketing and partner offers
Scriptfabrik may include affiliate links, banners, comparison offers or contain other references to external partners.
With an ordinary external link, when clicking, technical transmit the required information to the target page.
Are cookies, pixels, scripts or similar technologies for Commission allocation, marketing or tracking used, technologies subject to consent are only Consent activated.
Depending on the specific offer, partners can in particular Click information, pseudonymous assignments, transactional or Process commission data and technical retrieval information.
The specific providers and technologies used will be: where necessary, in the consent administration, Cookie overview or immediately indicated in the respective offer.
32. External content, videos, maps, widgets and iFrames
The website may contain external videos, maps, widgets, social media content, Comparison offers or other embedded content.
When loading such content, technically a connection to respective third parties are established.
In particular, IP address, browser, device and usage information is transmitted to the third party provider.
External content subject to consent will only be processed after prior Consent loaded.
For example, Scriptfabrik can provide a two-click solution for this purpose. Or use a placeholder.
With the activation of such content, a data transmission can to the respective third party.
For independent processing by the third party apply its data protection information.
33. IT security, abuse and fraud prevention
To protect customer accounts, payments, digital products, Infrastructure and users may in particular: processed:
- login data;
- IP addresses;
- equipment information;
- transaction data;
- licensing information;
- security events;
- blocking information;
- Risk and fraud indicators.
Security measures may include in particular:
- rate limitation;
- detection of unusual notifications;
- multi-factor authentication;
- Spam and malware filters;
- detection of attacks;
- transaction checks;
- licence abuse detection;
- automated or manual security checks.
The legal basis is in particular Art. 6 par. 1 lit. f GDPR the legitimate interest in IT security; Fraud prevention and protection of the offered systems.
34. Authorities, courts and legal enquiries
As far as Scriptfabrik is legally obliged or legally obliged to do so If requested, personal data may be sent to courts, law enforcement agencies, tax authorities, Data protection supervisory authorities or other legally authorized bodies are transmitted.
Scriptfabrik examines a corresponding request regarding Jurisdiction, legal basis and scope, insofar as this is legal permissible and possible.
A transmission shall be made only to the extent necessary.
35. Automated testing and profiling
Scriptfabrik can use automated systems in particular for detection of spam, malware, fraud, license abuse, use unusual notifications or other security risks.
Automated procedures for product recommendations can also be used. or technical prioritization.
Unless an exclusively automated decision with legal or similar significant effect, the processing takes place depending on the respective purpose, in particular on the basis of a contract, Consent or legitimate interests.
Decisions based solely on automated processing are based and have legal effect on a person; or they are affected in a similarly significant way, only in Within the framework of the requirements of Art. 22 GDPR.
As far as Art. 22 GDPR is applicable, data subjects are informs the essential logic, meaning and possible consequences and receive the rights provided for by law.
36. Hosting, cloud, CDN and technical service providers
Scriptfabrik can provide external service providers for hosting, cloud infrastructure, content delivery networks, email delivery, Use backups, security, support and other IT services.
Depending on the respective service, in particular server logs, IP addresses, databases, files, Communication data, backups and technical usage information processed.
Service providers providing personal data as processors are processed according to art. 28 GDPR contractually bound.
Scriptfabrik selects processors carefully and undertakes they are generally used for the processing of personal data exclusively in accordance with documented instructions and under appropriate security measures.
A service provider acts in relation to certain processing operations independently as responsible, in addition to Data protection information.
37. Recipients and categories of recipients
Depending on the respective processing operation, personal Data in particular to the following recipients or categories of recipients transmitted:
- payment service providers;
- banks and card companies;
- hosting and cloud providers;
- server and data centre providers;
- Content delivery and security providers;
- e-mail and communication service providers;
- Support and ticketing system providers;
- registrars and domain registries;
- certificate providers;
- backup and IT service providers;
- Analysis and consent management providers;
- Advertising or affiliate providers subject to the necessary consent;
- Tax consultants, lawyers and business consultants;
- debt collection service providers for eligible claims;
- insurers, where necessary;
- Courts and authorities with appropriate legal basis.
A transmission shall take place only if it is There is a corresponding legal basis.
Employees and employed service providers only receive access to those personal data which they provide for their respective need work.
38. International data transfers
Scriptfabrik basically prefers processing personal data within the European Union and European Economic Area.
A transfer of personal data to recipients outside of the European Economic Area is carried out only in compliance with the Requirements of Art. 44 ff. DSGVO.
In particular, the following may serve as a basis:
- an adequacy decision by the European Commission;
- European Commission standard contractual clauses;
- binding internal data protection rules;
- other appropriate guarantees by type. 46 GDPR;
- in exceptional cases, a legally permissible exception by type. 49 GDPR.
Where necessary, additional technical, organisational or contractual protective measures are taken.
Also the possibility of remote access from a third country is taken into account when assessing an international processing.
Information on the relevant transmission basis can be requested via the data protection contact address.
39. Storage time
Personal data are generally stored only for as long as: as is necessary for the respective processing purpose.
Subsequently, the data are deleted or anonymized, unless there are statutory storage obligations, legitimate interests of proof or other admissible grounds for further storage.
The storage period depends in particular on:
- the duration of a customer account;
- the duration of the contract;
- statutory retention periods;
- limitation periods;
- open payments or chargebacks;
business and tax relevant documents, in particular parts of the basic corporate administration, invoices, accounting data and debtors, creditors, Purchasing and sales documents, according to the Dutch tax regulations in principle at least 7 years kept.
For certain tax-relevant data, 10-year-old retention periods apply, in particular as far as specific VAT legislation is concerned or records of the one-stop-shop procedure provide for this.
If there is no legal fixed storage period, Scriptfabrik checks periodically, whether further storage is necessary.
Data in backup copies shall be used within the framework of the Deleted backup and overwrite cycles unless Restoration is necessary for a compelling reason.
Concrete running times of cookies and similar technologies specified in the cookie overview.
40. Deletion of the customer account
Users may request the closure of their customer account or, if offered, use a corresponding function in the customer account.
After account closure, personal data will be deleted or anonymized, insofar as no statutory storage obligations, open contracts, rights of third parties or legitimate conflict with documentation and legal defence interests.
In particular, immediate complete deletion cannot take place, as long as:
- orders or contracts are open;
- outstanding payments or chargebacks;
- Complaints or complaints are open;
- legal rights exist;
- invoice or tax data must be kept;
- security data are required temporarily to prevent abuse.
Data that is exclusively based on a legal Retention obligation must continue, as far as possible blocked for other processing purposes.
41. Rights of data subjects
In accordance with the GDPR, data subjects have in particular the following rights:
- Information in accordance with Art. 15 GDPRthe personal data processed;
- Correction according to art. 16 GDPRinaccurate personal data;
- Deletion according to art. 17 GDPR, insofar as there are no overriding legal reasons;
- Restriction of processing in accordance with art. 18 GDPR;
- Data portability according to art. 20 GDPR, as far as the legal requirements are met;
- Objection in accordance with art. 21 GDPRagainst certain processing operations;
- Withdrawal of consent in accordance with art. 7 par. 3 GDPRwith effect for the future;
- Rights relating to: automated decisions in accordance with art. 22 GDPR;
In order to process an application, Scriptfabrik may Require information if there is reasonable doubt as to identity the applicant.
A copy of the identity document is only required if milder possibilities for Identity verification is not enough.
Unnecessary data should be transmitted before The copy of the identity document is blackened.
Applications for data subjects are generally submitted within one month answered upon receipt.
In case of particular complexity or a high number of applications This period may be extended to the extent permitted by the GDPR. The affected person will in this regard within the legal Notified deadline.
42. Specific reference to the right of appeal
If personal data are collected on the basis of Art. 6 para 1 lit. e or lit. f GDPR, the person concerned may, for reasons arising from his result in particular situation, at any time objection against the processing.
Scriptfabrik processes the relevant personal data data subsequently no longer, unless it can compelling legitimate grounds for processing evidence of the interests, rights and freedoms outweigh the data subject or the processing is for the assertion, exercise or defence of legal claims.
If personal data are processed for direct marketing, can at any time without giving reasons object to this Processing including related profiling are placed.
After an objection, personal data will no longer processed for direct marketing purposes.
43. Right of complaint and competent data protection supervisory authority
Data subjects have the right to contact a the data protection supervisory authority.
A complaint may in particular be lodged with a supervisory authority in Member State of habitual residence, place of work or the location of the suspected data protection infringement.
For Scriptfabrik B.V. is based in the Netherlands In principle, the following Dutch data protection supervisory authority responsible for:
Autoriteit Persoonsgegevens
Postbus 93374
2509 AJ The Hague
Netherlands
Website:
https://autoriteitpersoonsgegevens.nl
Data protection concerns can previously voluntarily be addressed directly to Scriptfabrik are addressed:
E-mail: welcome@scriptfabrik.info
Prior contact with Scriptfabrik is not a requirement for a complaint to a data protection supervisory authority.
44. Technical and organisational security measures
Scriptfabrik makes appropriate technical and organizational Measures in accordance with Art. 32 GDPR to take a risk ensure an adequate level of protection.
In the selection of the measures, the prior art, Implementation costs, nature, scope, circumstances and purposes of processing Likelihood and severity of possible risks taken into account.
Protective measures may include in particular:
- encryption;
- secure TLS/HTTPS connections;
- access controls;
- Authorisation and role concepts;
- secure password storage;
- multi-factor authentication;
- logging of security-related processes;
- backups;
- system and network segmentation;
- firewall and security systems;
- security updates and patch management;
- recovery and security tests;
- Restriction of administrative access;
- Obligation of authorised persons to maintain confidentiality.
No technical or organizational procedure can be absolutely Ensure safety.
Scriptfabrik regularly reviews the protective measures taken And adjust them as needed.
45. Data breaches
Data breaches are made in accordance with the law Requirements documented, investigated and with regard to possible Risks to affected persons assessed.
As far as the legal requirements are met, reports Scriptfabrik a data breach of the responsible Data protection supervisory authority in accordance with art. 33 GDPR.
To the extent that there is a high risk to personal rights and freedoms data subjects exist and no legal exception applies, the persons concerned shall be made in accordance with art. 34 GDPR informed.
46. Minors
The platform and the paid services of Scriptfabrik are generally aimed at persons of legal age, as far as a specific offer is not expressly indicated otherwise.
Scriptfabrik does not knowingly collect personal data from Children for services not intended for children.
Scriptfabrik becomes aware that personal data a child is processed without a sufficient legal basis, appropriate measures shall be taken.
This may in particular include the deletion of the data concerned or the Examination of a required consent of legal representatives include.
47. No purposeless disclosure and no sale of personal data
Scriptfabrik does not sell personal data as a separate commercial good.
Personal data will only be transmitted to third parties, if there is a valid legal basis for this and the Transmission for the purposes of this data protection declaration required or otherwise transparently communicated purpose; or is legally permissible.
Advertising or affiliate partners receive personal or Device-related information only if it is legally permitted and – if necessary – a prior consent is given.
48. Changes to this data protection declaration
Scriptfabrik may update this privacy policy, if processing operations, service providers used, technical functions or change the legal situation.
The current version shall be displayed on: www.scriptfabrik.info published.
About material changes, existing customer accounts, materially affect current contracts or ongoing processing; can additionally inform Scriptfabrik in a suitable form, for example by e-mail, note in the customer account or clearly visible communication on the website.
A change to this data protection declaration does not justify retroactive consent.
Is for a new or substantially changed processing operation a consent is required, this is obtained separately.
49. Data protection contact
questions on data protection and requests for access, rectification, deletion, limitation, data portability, revocation or Objections may be addressed to:
Scriptfabrik B.V.
Pastoor Jacobsweg 27
6226 VV Maastricht
Netherlands
KvK number: 42137687
VAT identification number (BTW-ID):NL869888316B01
E-mail:
welcome@scriptfabrik.info
Website:
https://www.scriptfabrik.info
Please do not submit passwords, API keys, private key, full payment details or other confidential access data unsolicited by e-mail.
Please do not send an ID copy unsolicited. Should, exceptionally, for the processing of a data subject application: additional proof of identity is required; informs Scriptfabrik about an appropriate procedure.
Scriptfabrik B.V.
Pastoor Jacobsweg 27
6226 VV Maastricht
Netherlands
KvK number: 42137687
BTW ID: NL869888316B01
E-mail:
welcome@scriptfabrik.info
Website:
www.scriptfabrik.info
Status of the data protection declaration: 1 September 2026