‹ Back to home

Privacy Policy

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

hardt.industries GmbH
Schopenhauerstr. 14
14712 Rathenow
Germany

Managing Director: Thilo Hardt
Email: [email protected]

2. Principles of Data Processing

We process personal data only to the extent necessary and on the basis of applicable data protection law, in particular the GDPR. Data is only shared with third parties where permitted by law or explicitly described in this policy.

3. Server Log Files

When you visit Lemvista, our hosting provider automatically collects and stores information in server log files that your browser transmits:

This data is not merged with other data sources and is not used to identify individuals. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the technical provision and security of the website). Data is typically deleted after seven days.

4. Google User Data

You sign in to Lemvista with your Google Account. This section describes, in full, how Lemvista accesses, uses, stores, shares, retains, and deletes data obtained through Google. The Google sign-in is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).

4.1 Data Accessed

With your permission, Lemvista accesses the following Google user data:

Lemvista does not read the content, attendees, or details of your existing calendar events beyond their times, does not access any calendar other than your primary calendar, and never edits or deletes events it did not create.

4.2 Data Usage

4.3 Data Sharing

We do not sell Google user data and do not share it with third parties for advertising or any unrelated purpose. Google Calendar data and your Google profile data are not transferred to any third party. We disclose Google user data only: (a) to Google itself, as required to provide the booking functionality; or (b) where we are legally compelled to do so by a valid legal request. Lemvista's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements, and we do not use Google user data to train generalised artificial-intelligence or machine-learning models.

4.4 Data Storage & Protection

All data is transmitted over encrypted connections (HTTPS/TLS). Your basic Google profile data and OAuth tokens are stored in an access-controlled database; the tokens are used only by our server and are never exposed to the browser or to third parties. Calendar event times read to compute your availability are processed transiently in memory to generate the list of free slots and are not stored in our database. Access to our systems is restricted to authorised personnel.

4.5 Data Retention & Deletion

We retain your basic Google profile data and OAuth tokens for as long as your account is active. You can withdraw Lemvista's access to your Google Calendar at any time in your Google Account settings. You may request deletion of your account and all associated Google user data at any time by emailing [email protected]; we will delete your account, stored profile data, and OAuth tokens without undue delay and within 30 days, except where retention is required by law.

5. Bookings

When a booking is made through a calendar hosted on Lemvista, we process the booking details and the contact information provided by the person making the booking (such as name and email address) so that the booking can be created, managed, and communicated to the calendar owner. The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and, where applicable, Art. 6(1)(f) GDPR (legitimate interest in operating the booking service).

6. Payments (Stripe)

Where a booking requires payment, payment processing is handled by Stripe. The information needed to complete the payment (including card details) is collected and processed by Stripe on its own infrastructure; Lemvista does not receive or store full card details. We retain a record of the transaction (such as amount, status, and a Stripe reference) to fulfil and account for the booking.

Provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). Please see Stripe's Privacy Policy for details of its processing.

7. Your Rights

With regard to your personal data, you have the following rights:

Where processing is based on your consent, you may withdraw that consent at any time with effect for the future.

8. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data. The authority responsible for us is:

Landesbeauftragter für den Datenschutz und
für das Recht auf Akteneinsicht Brandenburg (LDA)
Stahnsdorfer Damm 77
14532 Kleinmachnow, Germany
www.lda.brandenburg.de