Last updated: 10 September 2026
This notice explains which personal data is processed when you use Sendequelle, the purposes of that processing and your rights. It covers sendequelle.com, its web application and the functions described below. It also addresses business contacts, invited team members, people submitting reports and individuals whose data appears in technical material submitted to us. Separate services on other domains have their own privacy notices.
1. Controller and contact details
Norbert Sehm, trading as Sendequelle
Von-Möller-Str. 23a
33649 Bielefeld, Germany
Email: emailn@emailn.de
Telephone: +49 521 5462877
You can send privacy requests to datenschutz@emailn.eu or to the general contact address above. No particular subject line or special form is required. No data protection officer is currently appointed; the controller handles your requests.
2. Our own responsibilities and processing for customers
We determine the purposes and means of processing for operating our website, managing accounts and business relationships, our own security measures and enquiries addressed directly to us.
Where a customer organisation provides personal data in email headers, email files, delivery failure messages, server logs or technical reports solely for analysis determined by that organisation, we generally process that data on its behalf. The organisation determines, in particular, the lawful purpose, the data to submit, authorised users and instructions. This requires a separate data processing agreement under Article 28 GDPR, including a description of processing, subprocessors and safeguards. Service providers acting for their own customers may involve subprocessing. This privacy notice does not replace those agreements.
Agreeing to an upload does not allow the submitting person to dispose of all other individuals' privacy rights. Registration or acceptance of our terms is likewise not blanket consent to every processing activity.
For rights concerning personal data that we process on behalf of a customer, the relevant customer organisation is generally your contact. If we receive such a request, we assist the responsible organisation in accordance with statutory and contractual requirements. We remain responsible for our own processing.
3. Legal bases and necessary information
The legal basis depends on the purpose:
- Article 6(1)(b) GDPR applies to taking steps towards, or performing, a contract with you as a natural person.
- Article 6(1)(f) GDPR applies particularly to secure and reliable operation, preventing misuse, communication with business contacts and providing accounts for people designated by business customers. The interests concerned are described in the following sections.
- Article 6(1)(c) GDPR applies where a specific legal obligation is relevant, for example retaining certain business records or handling data protection requests.
- Article 6(1)(a) GDPR applies where we obtain your voluntary consent for a specific optional purpose. You may withdraw it with effect for the future.
For processing on a customer's behalf, the customer determines the applicable lawful basis. The Article 28 GDPR agreement additionally governs our instructions and does not replace that basis.
Required form fields are marked accordingly. The requested function cannot be provided without necessary account, contract or analysis information. Other information is voluntary. Declining optional advertising or measurement does not prevent use of the basic functions that are independent of them.
4. Website access, hosting and technical logs
When you visit the website, the servers involved process your IP address and technical request data. This may include the time, requested page or file, HTTP status, amount of data transferred, browser and operating system information, and any referring address transmitted by your browser. This information enables delivery and supports error diagnosis, availability and protection against attacks.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to provide a functioning service and detect unauthorised access or abusive load. Security-relevant extracts may be needed separately to investigate a specific incident or pursue legal claims. Retention follows the purposes and criteria described in section 16.
We use servers provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, for hosting. The server location for Sendequelle is Falkenstein, Germany. This infrastructure processes the account, contact, analysis and operational data needed for the website and platform. Further provider information is available in Hetzner's privacy policy. The application server's location does not mean that every external system reached through a chosen function is also in Germany.
For certain security and contact activities, our application stores a value cryptographically derived from the IP address. Such a value is pseudonymised; deriving it does not by itself make it anonymous. Active sessions and technically necessary connections may process the IP address directly.
5. Cookies, session storage and preferences
Sendequelle uses cookies and similar browser storage for sessions, login protection and preferences. Access to information on your device is legally separate from subsequent processing of personal data. Strictly necessary access for a service you expressly request is governed by section 25(2)(2) of Germany's Telecommunications and Digital Services Data Protection Act (TDDDG). Non-essential access generally requires prior consent under section 25(1) TDDDG; subsequent processing of personal data additionally requires the relevant GDPR basis.
The storage used has the following functions:
- Session and, where applicable, CSRF cookies associate requests with a session and protect forms. They do not contain a plaintext password. Their usability depends on session expiry, logout and the selected sign-in function; the specific session name depends on configuration.
- A device you expressly approve as trusted may be recognised through
sendequelle_trusted_device. Approval lasts until expiry or revocation. sq_public_consentstores the choice concerning optional services, including version and time information. Its configured storage period is displayed in the information about optional services.- Display and colour preferences may be held in cookies with names such as
admin-mode,front-mode,admin-colorPreforfront-colorPrefand in local storage undertemplateCustomizer-…--Theme. Local storage persists until changed or until the browser's site data is deleted; cookie expiry can be viewed in the browser's site data. - When setting up a passkey, its intended name may temporarily be held in session storage. It is removed after being read; that storage ends no later than the associated browser session.
You can change or withdraw your choice concerning optional services in the privacy settings. You may also restrict or delete cookies and site data in your browser. This can remove sign-ins, trusted device approvals and saved preferences.
An earlier public forensic access mechanism could use the sq_forensic_guest cookie. New guest analyses are no longer offered. Section 16 and the original association apply to any remaining historical data; such an identifier does not make the data anonymous.
6. Accounts, organisations and access security
During registration and use, we process, in particular, names, business email addresses, password hashes, language, time zone, verification status, organisation memberships and roles. Organisation data may include the business designation, legal name, domain assignments, contacts and billing information.
The purposes are account provision, access control and teamwork. Article 6(1)(b) GDPR applies to direct contractual partners, and Article 6(1)(f) GDPR to designated users of a business customer. Our legitimate interest is to provide the agreed service to authorised people.
For active sessions, IP address, browser identifier and last activity may be stored and shown to help users review signed-in devices. Security and administrative events may include the actor, organisation, time, function concerned, technical metadata and pseudonymised IP identifiers. The legal basis is Article 6(1)(f) GDPR for protection against unauthorised access and traceability of permission changes.
For two-factor authentication, we process the necessary configuration and recovery data. For passkeys, we receive a credential identifier and public cryptographic key material. Biometric unlocking, if used, takes place in your authenticator; the passkey process does not transmit a fingerprint or facial template to us. A passkey synchronisation provider you use is a separate service.
Authorised organisation managers can see the information needed to manage members and roles. Membership of several organisations does not create shared access to their private reports.
Signing in with Microsoft or Google
Where offered on the sign-in page, you may expressly start sign-in with your chosen identity provider. The provider receives the technical sign-in request and the connection data needed for that request. Sendequelle receives a verified provider identifier and, where supplied, your name and email address to complete the account. The requested permissions cover only identity, profile and email address; no mailbox access, messages or contacts are requested. Provider profiles do not confer organisation membership or domain verification. A matching email address does not automatically link to an existing account.
The provider identifier is encrypted at rest and linked to an account using a derived lookup value. Short-lived sign-in data is encrypted, removed on completion and deleted by the regular cleanup after the ten-minute flow expires. Links can be removed in your profile after a fresh security confirmation, provided another sign-in method remains. Processing serves your chosen account access under the legal bases described in section 3. The provider’s processing is also subject to the Microsoft privacy statement or Google privacy policy.
7. Contact, support and email delivery
When you contact us, we process the contact details, subject, content and necessary case information you provide. The contact form also uses a derived IP value to prevent misuse. The name, email address and message fields are stored encrypted in the contact form model; this specific measure does not automatically cover every other data type.
Contract-related enquiries from natural persons who are contractual partners are handled under Article 6(1)(b) GDPR. Article 6(1)(f) GDPR applies to business contacts and other substantive enquiries; our interest is to answer and manage your request in a traceable way. Business correspondence subject to statutory retention additionally falls under Article 6(1)(c) GDPR.
We operate email for Sendequelle through our own service skymail.de. This involves sender and recipient addresses, necessary message content, sending time and technical delivery information. Skymail is a service name of the same operator. When mail is delivered to your address, its responsible email provider also receives the necessary transmission data.
Please provide only information needed to handle your request and do not send passwords or private keys. Use the protected account functions intended for confidential diagnostic material.
The extended contact form allows you to provide your enquiry type, company, role, website or affected mail domain, mail environment, requirements and callback request. A company is required for sales enquiries; privacy enquiries can be submitted without a company. Names, email, subject, message, company and other free-form contact details are encrypted in the contact model. Form proofs, temporary session bindings and derived sender values help limit and detect repeated submissions. Authorised staff handle enquiries, and notifications go to the configured support address; visitors cannot select another delivery recipient. The regular application cleanup deletes contact cases after 90 days. Any specifically required separate retention must be arranged as described in section 16.
Where the optional Cloudflare Turnstile check is offered, it loads only after its labelled button is selected. Technical browser and connection data then reaches Cloudflare. Sendequelle verifies the returned proof on its server; when the function is enabled, no notification is sent without successful verification. The check serves abuse prevention. Further information: Cloudflare Turnstile Privacy Addendum. If this function is neither offered nor started, the contact form does not initiate a Turnstile connection.
8. Public domain checks and result overviews
A public domain check processes the entered and normalised domain, time, status, and publicly available DNS and limited HTTPS information. This may include IP addresses, server names, certificate information and published technical contacts. These details can also relate to natural persons.
The purpose is the requested technical snapshot. Where personal data is involved, the necessary processing is based on Article 6(1)(f) GDPR. Our legitimate interest is transparent information about publicly reachable email infrastructure and its configuration. Private mailboxes or submitted account messages are not sources for these public results.
Result views can be shared. Qualifying results from the current week may appear in the homepage overview with the domain name, technical assessment and check time; the check form explains this before the check starts. This does not publish the requester, their IP address or private organisation reports. Public pages are accessible worldwide and may be indexed by search engines.
For complaints, we process the result reference, domain, reason and an abuse prevention identifier derived from the IP address and browser identifier with a daily reference. Verified domain managers can use the available exclusion functions. Complaint and exclusion procedures supplement your statutory rights and do not replace, in particular, your right to object.
Public landscape reports use selected aggregated results with minimum group sizes. Private customer messages and organisation reports are not published for these public landscape reports. Aggregation is anonymous only where people can no longer be identified, taking account of additional information reasonably likely to be used.
If you expressly transfer a public check into your account, a time-limited transfer context links the chosen check to registration, the organisation and setup progress. This may include completion of domain adoption, monitoring activation and plan subscription. Daily counters by tool, result group and completed step support internal assessment of whether this process works and is used. The requested transfer is based on Article 6(1)(b) or (f) GDPR according to your contractual role; the limited operational process assessment is based on Article 6(1)(f) GDPR. Our interest is to improve this setup process. The individual linkable transfer context is not an anonymous record.
To report an inaccurate result, you may select specific findings from the displayed scan, “Other”, and provide an explanation. The scan reference, selection, explanation and internal case notes are processed to investigate the report. Selections and free text are encrypted at rest and do not appear in the public result. Please include only necessary information. A new report does not automatically hide a public result. The regular cleanup deletes these reports after 90 days, including explanations and internal notes. Historical explicitly blocked cases are treated separately.
The public email score and technical provider compliance check use stored email findings. Website, security headers and reputation are marked as additional information and do not contribute to the email rating. Compliance profiles are technical assessments rather than legal certifications.
9. Domain monitoring, DMARC, TLS-RPT and incidents
Within the protected account, we process configured domains, verification data, technical measurements for DNS, TLS, SMTP and other expressly activated services, check times, errors and status changes. Incoming technical reports may contain reporting organisations, report identifiers, source IP addresses, authentication results and aggregated message counts. Aggregated reports can also contain confidential infrastructure information or information relating to people.
Raw reports, normalised individual values and historical aggregates are handled separately. Active monitoring requires the designated domain verification and activation. Standard technical checks do not use mailbox credentials or read customer mailboxes. They do not archive ordinary correspondence.
Personal data in these customer-requested analyses is processed on the organisation's behalf. Our own security and billing data has the separate purposes described in this notice.
DNS queries and technical connections reach the resolvers used, authoritative nameservers and target systems being checked. These receive the necessary DNS names or technical target details, time and connection address of our checking system. Complete private email messages are not transmitted to a DNS resolver for this purpose.
10. Email forensics and comparison within an account
Forensics analyses deliberately submitted headers or supported email files. These may contain From, Sender, Reply-To, Return-Path, recipients, Message-ID, timestamps, Received hops, public and internal IP addresses, server names, authentication information, and technical MIME or attachment metadata.
When full email source is pasted into the header field, the body is separated on the server before the header is further processed and stored as analysis input. A body submitted with it is initially transmitted to our server. Uploading a complete file instead retains the full original in private storage during its retention period. Body bytes may be needed for technical signature and MIME checks; general semantic analysis of ordinary correspondence is not part of this function.
The originals and corresponding report fields for email forensics and delivery diagnostics are encrypted at application level. Original files are held in private storage. Authorised members can compare expressly selected message versions with approved reference versions from the same organisation. Such references may also contain selected personal header information. There is no public search of private headers or comparison across organisations.
Personal customer data is processed for this purpose on behalf of the submitting organisation. Private messages in this analysis process are not used to sell address data, create external advertising profiles or train general-purpose AI models.
Separately selected DNS and registry queries
Where a DNS recheck is operationally enabled and separately selected, DNS names derived from message information, such as domains or DKIM selector hostnames, are queried through the configured resolver. The complete message is not transmitted. A later result describes the DNS information available at that time and does not prove the earlier configuration when the message was sent.
If you choose the IP registration lookup, the selected public IP address is queried through RDAP at the responsible registry. The registry is determined using the IANA directory. Depending on the address, the responsible registry is, in particular, RIPE NCC, ARIN, APNIC, LACNIC or AFRINIC. The additional domain registry lookup queries no more than three distinct registrable domains from the sender, return address and sending server at the responsible domain registry.
The necessary IP address or domain and technical connection data are transmitted. Complete headers, bodies and complete sender or recipient addresses are not sent to those registries. Registry responses may contain published network operator, registrar, registrant and abuse contacts. Unpublished registrant information is not supplemented. The source identified in the result indicates the registry actually queried; its information does not prove the email sender's personal identity or legal responsibility.
Registries may be outside the European Economic Area. Choosing a lookup requests that technical function and is not consent by all people mentioned in a message to international transfers. The privacy requirements in section 17 apply independently.
11. Delivery failure and delivery diagnostics
Authorised account users may submit a supported complete delivery failure message (DSN) or a limited Postfix log extract. It may contain senders and recipients, domains, servers, queue and message identifiers, timestamps, delivery status, SMTP codes, error diagnostics and returned parts of an original message.
The machine-readable DSN part may be in the body and is specifically analysed. The original is stored privately. You should remove unnecessary original correspondence before submitting it, provided the analysable DSN structure is preserved. Processing takes place on behalf of the customer organisation for technical troubleshooting.
Passive diagnostics do not start DNS or registry queries, access third-party mailboxes or send a message. Submitted information is not our own measurement of delivery, inbox placement or reading. Redacted JSON and text outputs remove certain details, but may still contain domains and technical information relating to people; they are not automatically anonymous.
12. Optional test reception and recurring test profiles
Test reception and return reports are available only after separate operational enablement and activation by an authorised organisation. An ordinary upload does not open this reception path or trigger a return message.
When test reception is activated, the organisation's own test messages are received at unique, revocable test addresses. Processing includes the message, SMTP connection and reception data, sender and recipient details, our own authentication checks, timestamps and processing status. Recurring profiles associate expected test messages and document detected changes or failures. The customer's system sends the test messages.
Return reports require express activation and a previously confirmed destination. An address mentioned in a header is not sufficient authorisation. Test message data is processed on behalf of the customer organisation; our own connection and security data has the separate purposes described in this notice. Our own reception confirms only arrival at Sendequelle, not delivery to other recipients or their reading behaviour.
13. Notifications, interfaces, status pages and abuse
For activated notifications, we process destinations, event filters, channel assignments, delivery status and limited technical error information. Depending on the function actually offered and chosen, an email address, telephone number, device token or webhook address may be necessary. A chosen destination receives the message content intended for it. Configuring a destination requires the customer organisation to be authorised to make that transfer; further processing by the recipient depends on its role and privacy information.
API access uses organisation-specific tokens and permissions. Necessary administrative and security events are logged. If a token is compromised, you should revoke its access promptly.
An expressly published status page shows the technical information approved for it. Publication does not simultaneously make the underlying private reports, internal users, invoices or customer messages public. Visible information is accessible worldwide.
Abuse and threat reports may contain reporter contacts, domain and IP references, evidence, classifications and processing notes. A report is treated as information requiring review, not as established proof of wrongdoing. Cases handled on a customer's behalf are separate from Sendequelle's own abuse prevention. Article 6(1)(f) GDPR applies to our own protective measures and handling legitimate complaints.
If an external reputation check is activated for login protection, the public login IP is transmitted to the reputation service configured for that purpose to query known attack indicators. Assessment may result in stronger limits on login attempts or an additional security check. The purpose and legitimate interest under Article 6(1)(f) GDPR are to prevent account attacks. A registry match does not establish that the person signing in is acting unlawfully. You can contact us for review of an incorrect restriction.
14. Plans, billing and legal records
For subscribed services, we process the contract and organisation association, plan, billing periods, usage counters and necessary commercial information. Complete diagnostic content is not needed solely for billing. Article 6(1)(b) or (f) GDPR applies according to your contractual role, and Article 6(1)(c) GDPR to statutory obligations.
For new registrations, including newly created invited accounts, acceptance of the terms is recorded with the user association, version, language, document checksum, acceptance time and confirmation of business use. This acceptance record contains no additional IP address or browser identifier. It provides evidence of contract formation under Article 6(1)(b) or (f) GDPR according to your contractual role and is retained according to the criteria applicable to the contract, its settlement and necessary evidence for claims. Providing this privacy notice is separate and is not treated as blanket privacy consent.
Displaying a plan or preparing a payment adapter does not by itself transmit data to a payment service. If an external payment method is offered, that payment process identifies the provider, required information and separate privacy notice; this processing cannot be inferred from registration alone.
Retention obligations concern the specific business and accounting records covered by law. Their starting point, duration and any extension depend on the type of document and applicable commercial and tax rules, particularly section 257 of the German Commercial Code (HGB) and section 147 of the German Fiscal Code (AO). These do not justify general long-term retention of complete diagnostic emails.
Necessary evidence may be kept separately to establish, exercise or defend specific legal claims. The basis is Article 6(1)(f) GDPR or a relevant legal obligation. Further use is restricted to that purpose; a possible limitation period alone does not justify retaining all customer data.
When you expressly start an online order, we store organisation and billing details, the selected plan, amounts, tax breakdown, contract version, timestamps and payment or subscription references. These order and customer snapshots are encrypted at rest. The selected payment method may lead to Stripe or PayPal, which process the information needed for the payment. Full card details or bank account credentials are not entered in our order form. For a bank transfer, you receive the approved bank details and payment reference; received funds are matched internally. Authorised organisation members can retrieve stored order records and available invoices. Original invoices come from the responsible invoicing system and are stored privately. Invoice and payment records follow separate retention requirements and are not automatically deleted together with routine technical scan data.
15. Fonts and optional services on public pages
The public pages use system fonts and assets served from our own website for their typography. No Google Fonts connections are made there to display fonts.
The configured status of optional third-party advertising and marketing measurement, and information about the configured consent management system, are available under Optional services. You can manage your choice in the privacy settings. This choice is separate from signing in and entering into a contract.
Purposes requiring consent are governed by Article 6(1)(a) GDPR and, for relevant device access, section 25(1) TDDDG. Withdrawal takes effect for the future and does not affect the lawfulness of processing previously based on valid consent. The existence of a settings page does not mean that every service technically prepared there is activated.
Private account reports and submitted email content are not transmitted to advertising services as marketing parameters. Consent to advertising does not replace a necessary legal basis for other processing or international transfers.
16. Retention and deletion
Storage duration depends on the purpose of the data, the requested service, contractually agreed retention limits and applicable statutory duties. We distinguish originals, analyses, administrative records and backup copies. Different criteria apply to these categories:
- Forensics and delivery diagnostics: Retention depends on the chosen account plan or an individual agreement. Originals and reports have separate expiry times displayed in the module. Reopening a report or making a comparison does not extend the original's retention period. Expired originals are no longer available for new checks. Technical content cleanup uses the designated deletion jobs; reduced administrative and quota records are separate from message content.
- DMARC/TLS-RPT data and monitoring: Raw data is needed for rechecks and technical troubleshooting, normalised details for the agreed analysis history, and aggregated values for the subscribed long-term comparison. The retention limits agreed or configured for the account and the continuing need for the relevant level of detail determine retention. Keeping an aggregate does not automatically justify retaining the underlying original.
- Account and organisation: Master data and permissions are needed for the account and existing organisation memberships. Termination or a deletion request requires consideration of remaining memberships, necessary settlement, export or switching rights, and business records that must be retained separately. Removing a team member is not the same as deleting the entire organisation.
- Public checks and transfer contexts: Results are needed for time-limited result availability and complaint handling. The weekly overview uses only suitable results from the current week. A transfer context linkable to a person serves the setup process that was started and loses that purpose when it expires. Separate daily counters contain no individual user or organisation reference.
- Contact, support and abuse: The criteria are handling and completing the request, necessary follow-up and any specifically applicable retention or evidential obligation. Evidence needed for an ongoing dispute is considered separately from correspondence or diagnostic details no longer required.
- Operational and security logs: Duration depends on necessary error diagnosis, attack detection and investigation of a specific incident. Evidential extracts may be needed until the investigation and necessary legal proceedings are complete. These reasons do not justify unlimited storage of all ordinary access records.
- Notifications, devices, tokens and exports: Relevant factors are the chosen function, expiry or revocation of authorisation, necessary delivery or error investigation and, for exports, the availability period. Access no longer needed should be revoked; a delivery log does not permanently require the full content of the report that triggered it.
- Contract and business records: The respective retention obligations in section 14 apply to the parts covered by law. Message content outside that scope does not thereby become a record subject to statutory retention.
Deletion from the active system and removal from any existing backup are different operations. Any further need to retain a backup is limited to necessary recoverability; backups are not an additional analysis dataset. Immediate selective deletion from every backup is not promised. Previously effective deletions and restrictions must be taken into account during restoration.
Earlier guest forensics used one hour for originals and 24 hours for reports. Associated hashed usage markers may have a different technical expiry; they are not anonymous content data. New guest analyses are no longer created. A subsequent authorised transfer to an account does not extend the original content retention periods.
You may contact us about privacy to obtain information about the retention limits applied to your case and request deletion or restriction. Statutory rights are not conditional on a plan's retention period expiring. The absence of a delete button does not remove these rights.
17. Recipients, data sources and international processing
Access within our operations is limited to data needed for the relevant tasks. Recipients arise particularly from hosting, email delivery, chosen notification destinations, technical target systems and public registry queries. An external integration actually chosen adds the service providers identified for it. Providers acting on instructions must be engaged in accordance with data processing requirements. Legal or tax advisers and competent authorities may receive data necessary for their specific assignment or a statutory obligation.
Data is not collected only from the individuals concerned. Accounts may be prepared through organisation invitations. Email, log and report data comes from customer organisations or technical report senders. Technical contacts and registrant details may come from public DNS and RDAP directories or server responses. Where we are the controller, Article 14 GDPR information duties also apply; a source being public does not by itself remove those duties.
Technical systems and registries are contacted according to the target being checked and may be outside the EU or EEA. An email recipient you choose or a published result may also be reached outside that area. German hosting therefore does not mean that all processing takes place exclusively in Germany.
Transfers of personal data to third countries must also meet the requirements of Articles 44 onwards GDPR. Possible grounds include an adequacy decision applicable to the specific recipient or appropriate safeguards, such as relevant standard contractual clauses with the necessary assessment and, where appropriate, additional measures. The name of a country or programme alone does not demonstrate those requirements. Agreeing to a technical function does not replace them either.
You may use the privacy contact to request information about the recipient in a specific case, the applicable transfer conditions and, where relevant, a copy of safeguards used. Any redactions needed to protect others' rights or confidential information will be explained.
18. Your data protection rights
Subject to the applicable statutory conditions, you may exercise the following rights:
- Information and access to your personal data under Article 15 GDPR;
- Rectification or completion under Article 16 GDPR;
- Erasure under Article 17 GDPR;
- Restriction of processing under Article 18 GDPR;
- Data portability for the data and processing covered by Article 20 GDPR;
- Withdrawal of consent with effect for the future;
- Complaint to a data protection supervisory authority under Article 77 GDPR.
Where processing relies on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. The data concerned may then be processed further only if compelling legitimate grounds override your interests, rights and freedoms, or if processing serves to establish, exercise or defend legal claims.
You may object to direct marketing, including profiling related to it, at any time without giving a particular reason. The data must then no longer be used for those purposes. This information about your rights does not mean that a particular advertising service is currently activated.
A message to the contact in section 1 is sufficient. Where there are reasonable doubts about identity, proportionate additional information may be necessary; a copy of an identity document is not routinely required. We generally answer requests within one month. Any legally permitted extension due to complexity or number of requests will be explained within that period. Other individuals' rights and other organisations' confidential data remain protected.
For our registered location, the competent authority is, in particular, the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, Postfach 20 04 44, 40102 Düsseldorf, Germany. Contact details and complaint options are available from LDI NRW. You may also contact the competent authority where you usually live, work or where the suspected infringement occurred. You do not have to complain to us first.
19. Automated assessments and safeguards
Sendequelle produces technical analyses and uses rules to derive states, notices, usage limits or security responses. Assessments concern technical evidence and its limitations. They do not assess personal creditworthiness and are not conclusive proof of unlawful conduct. Missing evidence, third-party header statements, our own measurements and later rechecks must be distinguished.
Automated login protection may trigger additional security requirements or restrictions, as described in section 13. You may request a review of an incorrect measure. Where a procedure falls within Article 22 GDPR in an individual case, its conditions and safeguards, including any required human review, remain applicable. Customers are responsible for their own decisions based on technical results.
The application uses, among other measures, organisation and permission checks, credential protection, bounded file processing and private storage. Specific safeguards agreed for processing on behalf of a customer belong in the corresponding contractual documents. Absolute protection against every security incident is not promised; statutory security, assistance and notification duties remain in place.
20. Changes to this notice
We update this notice when relevant processing, available functions, providers or legal requirements change. We provide suitable information about material changes. An updated notice alone does not authorise new processing requiring consent or silently change your contract. The date above identifies this version of the text.