Privacy Policy
Privacy Policy
# Privacy Policy
## 1. Controller
The controller responsible for the processing of personal data on this portal within the meaning of the General Data Protection Regulation (GDPR) is:
**WR-EXCLUSIVE**
Inh. Klaus- Steven Winter
Im Gewerbegebiet 2F
55120 Mainz
Deutschland
Email: **admin@mytuningserver.de**
Further information about the operator can be found in the legal notice / imprint.
---
## 2. General Information on Data Processing
The protection of personal data is important to us. Personal data is processed only to the extent necessary for the operation of the portal, the provision of its functions, the administration of user accounts, the processing of uploaded files, IT security, and the handling of enquiries.
No personal data is processed for advertising, profiling, or marketing purposes.
No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.
---
## 3. Legal Bases for Processing
Where personal data is required for the creation and provision of a user account or for carrying out functions and file processing requested by the user, processing is based on **Art. 6(1)(b) GDPR**.
Where personal data is processed to ensure the security and stability of the portal, for error analysis, or for the prevention and investigation of misuse, processing is based on **Art. 6(1)(f) GDPR**. The operator's legitimate interest lies in the secure, stable, and misuse-free operation of the portal and the underlying IT systems.
Where processing is required in order to comply with a legal obligation, processing is based on **Art. 6(1)(c) GDPR**.
---
## 4. Registration and User Account
A user account is generally required in order to use the functions of the portal.
The following data may in particular be processed and stored:
* email address and/or username
* internal user ID
* password in the form of a cryptographic password hash
* account status
* time of registration
* time and/or status of email verification
* technically required timestamps relating to email dispatch
* time of the most recent login, where technically recorded
* technical log data required for secure operation
Passwords are not stored in plain text.
This data is processed in order to provide and administer the user account, authenticate the user, and protect the user account and portal against unauthorised access and misuse.
---
## 5. Processing of Uploaded Files
Users may voluntarily upload files to the portal in order to use the available editing, processing, and conversion functions.
The following information may in particular be processed and stored in connection with an upload:
* file name
* file type
* file size
* category selected by the user
* job ID or internal process ID
* creation and processing timestamps
* IP address at the time of upload
* uploaded original file
* files generated, converted, or edited by the portal
* technical information relating to the processing status
Processing takes place solely for the purpose of carrying out the file processing requested by the user, providing the resulting files, and ensuring secure and technically reliable operation.
---
## 6. Rights and Responsibility for Uploaded Files
The user remains responsible for the files and content uploaded by them.
**Uploading a file does not transfer any ownership rights, copyrights, usage rights, or other rights in the uploaded file to the operator of the portal.**
By uploading a file, the user confirms that they possess the rights or authorisations required to upload the relevant file and to have it stored, processed, edited, or converted using the functions offered by the portal.
The user does not necessarily have to be the owner or copyright holder of the file. However, the user must have sufficient permission from the respective rights holder or another legal basis authorising them to use the file for the relevant purpose and to have it processed.
### No General Verification by the Operator
The operator generally performs **no advance legal or content-related review of uploaded files**.
In particular, the operator does not verify whether the user:
* owns the file or the data contained in it,
* is the copyright holder or other rights holder,
* has been authorised by the rights holder to have the file processed, or
* is otherwise legally entitled to use and process the file.
The operator is generally entitled to assume that the user possesses the necessary rights and permissions.
The operator receives only the technical rights required to perform the service requested by the user, including the right to store, copy, process, modify, or convert the file and to make the resulting file available to the user.
No additional usage or exploitation rights are transferred to the operator.
In particular, uploaded files will not, without an appropriate legal basis, be:
* published,
* sold,
* used for advertising purposes,
* made available to third parties for their own purposes, or
* otherwise exploited commercially by the operator for purposes unrelated to the requested service.
This does not affect the operator's right or legal obligation to block or delete files or user accounts, or to take other necessary measures, where there are concrete indications of unlawful use or where the operator is required to do so by law, court order, or administrative authority.
---
## 7. Personal Data of Third Parties Contained in Uploaded Files
Uploaded files may contain personal data or other information relating to third parties.
The operator does not generally inspect uploaded files to determine whether they contain personal data relating to third parties.
The user is responsible for ensuring that they are entitled to transmit and process such data and that the upload and requested processing do not violate legal requirements or the rights of third parties.
The operator processes such content only to the extent technically required to provide the functions requested by the user.
---
## 8. Storage and Deletion of Uploaded Files
Uploaded files, as well as files generated or edited from them, are generally stored only for a limited period.
### Active Storage
Files are generally removed from the active user history **three months after their creation**.
After this period, the files can no longer be accessed by the user through their user account.
### Backups
The server or virtual machine is additionally backed up on a regular basis for technical purposes.
These backups are created solely for data backup and recovery in the event of technical faults, data loss, or system failures.
**Backups are retained for a maximum of 14 days. Older backups are automatically deleted or overwritten as part of the backup rotation.**
Data that has been deleted from the active system may therefore remain contained in a previously created backup for up to an additional 14 days.
Backups are not used for regular access, analysis, or other processing of user files.
Individual personal data is generally not restored from backups unless this is technically or legally required.
---
## 9. Deletion of the User Account
Users may request deletion of their user account or use an account deletion function provided by the portal.
When an account is deleted, the personal data and files associated with the user are deleted from the active systems, unless statutory retention obligations or other legal grounds require continued storage.
Existing backups may technically continue to contain the previously stored data for a maximum period of **14 days**.
Once the relevant backup rotation period has expired, those backup copies are automatically deleted or overwritten.
Statutory retention obligations remain unaffected.
---
## 10. Server Location and Hosting
The web and application server used for the portal is operated directly by the operator.
**The server is located in Germany.**
No external web hosting provider is used for hosting the web and application server.
The server's internet connection is provided by **Deutsche Telekom**. The telecommunications provider supplies the technical internet connection and is not commissioned to process files uploaded through the portal for its own purposes.
User account data and uploaded files are generally processed and stored on systems controlled by the operator in Germany.
---
## 11. Server Log Files and IP Addresses
When the portal is accessed and used, technically required information is processed.
This may include in particular:
* IP address
* date and time of access
* page or resource accessed
* HTTP status code
* amount of data transferred
* browser or user agent
* referrer, where transmitted by the browser
* technical error and security information
This data is processed for the technical provision of the portal, error analysis, and the detection and prevention of attacks and misuse.
The legal basis is **Art. 6(1)(f) GDPR**. The legitimate interest lies in the secure and reliable operation of the IT systems.
Server log files are stored only for as long as necessary for the stated purposes. Longer storage may take place where there are concrete indications of a security incident, misuse, unlawful use, or where continued storage is required by law.
---
## 12. Contact Form and Support
When the contact form or support function is used, the following data may in particular be processed:
* username
* internal user ID
* IP address
* subject
* content of the message
* time of the enquiry
* any additional information voluntarily provided by the user
The data is used exclusively to process the relevant enquiry, error report, or support request.
For enquiries relating to the existing user relationship, processing is based in particular on **Art. 6(1)(b) GDPR**.
For other enquiries, processing is based on **Art. 6(1)(f) GDPR**, with the legitimate interest consisting of the proper processing and response to the enquiry.
---
## 13. Email Communication and 1blu
An email service or mail server provided by **1blu AG** is used for email communication.
The following types of email may in particular be sent or processed through this service:
* email verification messages
* registration information
* password reset messages
* security-related system notifications
* support enquiries and replies
* other messages necessary for the operation of the user account
In connection with email communication, the recipient's email address, technical transmission information, and the content of the relevant message are processed.
Where processing is required for the provision of the user account or requested functions, the legal basis is **Art. 6(1)(b) GDPR**. Where communication is required for security purposes or the reliable operation of the portal, processing may be based on **Art. 6(1)(f) GDPR**.
No advertising or marketing emails are sent unless a separate legal basis exists for doing so.
---
## 14. Cookies
The portal uses only cookies or comparable storage mechanisms that are required for the operation of the portal and the functions expressly requested by the user.
No tracking, marketing, or analytics cookies are used.
### PHPSESSID
PHP may set a session cookie named **`PHPSESSID`** for the purpose of managing the user's session.
This cookie is used in particular to:
* recognise an authenticated user during their session,
* maintain the user's login status,
* assign requests to the correct user session, and
* ensure the security of the session.
The cookie contains only a randomly generated session ID and does not contain an email address, uploaded files, or comparable content.
The session ID may nevertheless be indirectly associated with an authenticated user.
The cookie is generally a session cookie and becomes invalid at the end of the session or after expiry of the server-side session, depending on the session configuration.
Its use is technically necessary in order to provide the login and user account functions.
---
## 15. No Tracking or Analytics
No external tracking, analytics, or advertising services are used.
In particular, the portal does not use services such as:
* Google Analytics
* Google Ads
* Meta Pixel
* Matomo
* comparable tracking or profiling systems
No user-specific tracking takes place for advertising purposes.
No user profiles are created for marketing or advertising purposes.
---
## 16. External Services and Recipients
Personal data is not sold or disclosed to third parties for advertising, analytics, or marketing purposes.
The following external technical service providers or recipients may in particular be involved:
**1blu AG**
Provision of the email infrastructure used by the portal.
**Deutsche Telekom**
Provision of the internet connection for the server operated directly by the controller.
Personal data may also be transmitted to public authorities, courts, or other authorised recipients where this is required by law or necessary for the establishment, exercise, or defence of legal claims.
Where a service provider processes personal data on behalf of the operator and the statutory requirements apply, processing is carried out on the basis of a data processing agreement pursuant to **Art. 28 GDPR**.
---
## 17. Transfers to Third Countries
There is no intentional transfer of user account data or uploaded files stored within the portal to countries outside the European Union or the European Economic Area.
The web and application server is located in Germany.
Should a transfer of personal data to a third country become necessary in the future, such transfer will only take place in compliance with the requirements of **Art. 44 et seq. GDPR**. This Privacy Policy will be updated accordingly.
---
## 18. Data Security
The operator implements appropriate technical and organisational measures to protect personal data and uploaded files against loss, manipulation, unauthorised access, and other security risks.
These measures include in particular:
* access restrictions,
* user authentication,
* storage of passwords exclusively in the form of cryptographic hashes,
* encrypted data transmission via HTTPS/TLS,
* regular technical backups, and
* measures designed to detect and prevent unauthorised access.
Absolute protection of data during electronic transmission and storage cannot be technically guaranteed.
---
## 19. Rights of Data Subjects
Subject to the applicable statutory requirements, data subjects have in particular the following rights:
* **Right of access** pursuant to Art. 15 GDPR
* **Right to rectification** pursuant to Art. 16 GDPR
* **Right to erasure** pursuant to Art. 17 GDPR
* **Right to restriction of processing** pursuant to Art. 18 GDPR
* **Right to data portability** pursuant to Art. 20 GDPR
* **Right to object** pursuant to Art. 21 GDPR
Where processing is based on consent, consent may be withdrawn at any time with effect for the future. The lawfulness of processing carried out prior to the withdrawal remains unaffected.
To exercise these rights, it is sufficient to contact:
**admin@mytuningserver.de**
Where there are justified doubts regarding the identity of the requesting person, an appropriate form of identification may be requested in order to prevent unauthorised disclosure, modification, or deletion of personal data.
---
## 20. Right to Object to Processing Based on Legitimate Interests
Where personal data is processed on the basis of **Art. 6(1)(f) GDPR**, the data subject has the right, pursuant to Art. 21 GDPR, to object at any time to such processing on grounds relating to their particular situation.
Where an objection is justified, processing will be discontinued unless compelling legitimate grounds for the processing exist which override the interests, rights, and freedoms of the data subject, or where processing is necessary for the establishment, exercise, or defence of legal claims.
---
## 21. Right to Lodge a Complaint with a Supervisory Authority
Pursuant to Art. 77 GDPR, data subjects have the right to lodge a complaint with a data protection supervisory authority if they believe that the processing of their personal data infringes the GDPR.
The supervisory authority responsible for the controller is in particular:
**The State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate**
Hintere Bleiche 34
55116 Mainz
Germany
Telephone: +49 (0) 6131 8920-0
Email: [poststelle@datenschutz.rlp.de](mailto:poststelle@datenschutz.rlp.de)
A complaint may also be lodged with any other supervisory authority competent pursuant to Art. 77 GDPR.
---
## 22. Requirement to Provide Personal Data
The provision of certain personal data is necessary in order to create a user account and use the functions of the portal.
Without the required information, the user account or relevant function may not be made available.
Uploading files and providing the information contained within them is generally voluntary. However, without providing a file to be processed, the respective file-processing function cannot be performed.
---
## 23. Changes to this Privacy Policy
This Privacy Policy may be amended if the technical functions of the portal, the systems or service providers used, or the applicable legal requirements change.
The current version published on the portal applies.
**Last updated: August 2026**
## 1. Controller
The controller responsible for the processing of personal data on this portal within the meaning of the General Data Protection Regulation (GDPR) is:
**WR-EXCLUSIVE**
Inh. Klaus- Steven Winter
Im Gewerbegebiet 2F
55120 Mainz
Deutschland
Email: **admin@mytuningserver.de**
Further information about the operator can be found in the legal notice / imprint.
---
## 2. General Information on Data Processing
The protection of personal data is important to us. Personal data is processed only to the extent necessary for the operation of the portal, the provision of its functions, the administration of user accounts, the processing of uploaded files, IT security, and the handling of enquiries.
No personal data is processed for advertising, profiling, or marketing purposes.
No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.
---
## 3. Legal Bases for Processing
Where personal data is required for the creation and provision of a user account or for carrying out functions and file processing requested by the user, processing is based on **Art. 6(1)(b) GDPR**.
Where personal data is processed to ensure the security and stability of the portal, for error analysis, or for the prevention and investigation of misuse, processing is based on **Art. 6(1)(f) GDPR**. The operator's legitimate interest lies in the secure, stable, and misuse-free operation of the portal and the underlying IT systems.
Where processing is required in order to comply with a legal obligation, processing is based on **Art. 6(1)(c) GDPR**.
---
## 4. Registration and User Account
A user account is generally required in order to use the functions of the portal.
The following data may in particular be processed and stored:
* email address and/or username
* internal user ID
* password in the form of a cryptographic password hash
* account status
* time of registration
* time and/or status of email verification
* technically required timestamps relating to email dispatch
* time of the most recent login, where technically recorded
* technical log data required for secure operation
Passwords are not stored in plain text.
This data is processed in order to provide and administer the user account, authenticate the user, and protect the user account and portal against unauthorised access and misuse.
---
## 5. Processing of Uploaded Files
Users may voluntarily upload files to the portal in order to use the available editing, processing, and conversion functions.
The following information may in particular be processed and stored in connection with an upload:
* file name
* file type
* file size
* category selected by the user
* job ID or internal process ID
* creation and processing timestamps
* IP address at the time of upload
* uploaded original file
* files generated, converted, or edited by the portal
* technical information relating to the processing status
Processing takes place solely for the purpose of carrying out the file processing requested by the user, providing the resulting files, and ensuring secure and technically reliable operation.
---
## 6. Rights and Responsibility for Uploaded Files
The user remains responsible for the files and content uploaded by them.
**Uploading a file does not transfer any ownership rights, copyrights, usage rights, or other rights in the uploaded file to the operator of the portal.**
By uploading a file, the user confirms that they possess the rights or authorisations required to upload the relevant file and to have it stored, processed, edited, or converted using the functions offered by the portal.
The user does not necessarily have to be the owner or copyright holder of the file. However, the user must have sufficient permission from the respective rights holder or another legal basis authorising them to use the file for the relevant purpose and to have it processed.
### No General Verification by the Operator
The operator generally performs **no advance legal or content-related review of uploaded files**.
In particular, the operator does not verify whether the user:
* owns the file or the data contained in it,
* is the copyright holder or other rights holder,
* has been authorised by the rights holder to have the file processed, or
* is otherwise legally entitled to use and process the file.
The operator is generally entitled to assume that the user possesses the necessary rights and permissions.
The operator receives only the technical rights required to perform the service requested by the user, including the right to store, copy, process, modify, or convert the file and to make the resulting file available to the user.
No additional usage or exploitation rights are transferred to the operator.
In particular, uploaded files will not, without an appropriate legal basis, be:
* published,
* sold,
* used for advertising purposes,
* made available to third parties for their own purposes, or
* otherwise exploited commercially by the operator for purposes unrelated to the requested service.
This does not affect the operator's right or legal obligation to block or delete files or user accounts, or to take other necessary measures, where there are concrete indications of unlawful use or where the operator is required to do so by law, court order, or administrative authority.
---
## 7. Personal Data of Third Parties Contained in Uploaded Files
Uploaded files may contain personal data or other information relating to third parties.
The operator does not generally inspect uploaded files to determine whether they contain personal data relating to third parties.
The user is responsible for ensuring that they are entitled to transmit and process such data and that the upload and requested processing do not violate legal requirements or the rights of third parties.
The operator processes such content only to the extent technically required to provide the functions requested by the user.
---
## 8. Storage and Deletion of Uploaded Files
Uploaded files, as well as files generated or edited from them, are generally stored only for a limited period.
### Active Storage
Files are generally removed from the active user history **three months after their creation**.
After this period, the files can no longer be accessed by the user through their user account.
### Backups
The server or virtual machine is additionally backed up on a regular basis for technical purposes.
These backups are created solely for data backup and recovery in the event of technical faults, data loss, or system failures.
**Backups are retained for a maximum of 14 days. Older backups are automatically deleted or overwritten as part of the backup rotation.**
Data that has been deleted from the active system may therefore remain contained in a previously created backup for up to an additional 14 days.
Backups are not used for regular access, analysis, or other processing of user files.
Individual personal data is generally not restored from backups unless this is technically or legally required.
---
## 9. Deletion of the User Account
Users may request deletion of their user account or use an account deletion function provided by the portal.
When an account is deleted, the personal data and files associated with the user are deleted from the active systems, unless statutory retention obligations or other legal grounds require continued storage.
Existing backups may technically continue to contain the previously stored data for a maximum period of **14 days**.
Once the relevant backup rotation period has expired, those backup copies are automatically deleted or overwritten.
Statutory retention obligations remain unaffected.
---
## 10. Server Location and Hosting
The web and application server used for the portal is operated directly by the operator.
**The server is located in Germany.**
No external web hosting provider is used for hosting the web and application server.
The server's internet connection is provided by **Deutsche Telekom**. The telecommunications provider supplies the technical internet connection and is not commissioned to process files uploaded through the portal for its own purposes.
User account data and uploaded files are generally processed and stored on systems controlled by the operator in Germany.
---
## 11. Server Log Files and IP Addresses
When the portal is accessed and used, technically required information is processed.
This may include in particular:
* IP address
* date and time of access
* page or resource accessed
* HTTP status code
* amount of data transferred
* browser or user agent
* referrer, where transmitted by the browser
* technical error and security information
This data is processed for the technical provision of the portal, error analysis, and the detection and prevention of attacks and misuse.
The legal basis is **Art. 6(1)(f) GDPR**. The legitimate interest lies in the secure and reliable operation of the IT systems.
Server log files are stored only for as long as necessary for the stated purposes. Longer storage may take place where there are concrete indications of a security incident, misuse, unlawful use, or where continued storage is required by law.
---
## 12. Contact Form and Support
When the contact form or support function is used, the following data may in particular be processed:
* username
* internal user ID
* IP address
* subject
* content of the message
* time of the enquiry
* any additional information voluntarily provided by the user
The data is used exclusively to process the relevant enquiry, error report, or support request.
For enquiries relating to the existing user relationship, processing is based in particular on **Art. 6(1)(b) GDPR**.
For other enquiries, processing is based on **Art. 6(1)(f) GDPR**, with the legitimate interest consisting of the proper processing and response to the enquiry.
---
## 13. Email Communication and 1blu
An email service or mail server provided by **1blu AG** is used for email communication.
The following types of email may in particular be sent or processed through this service:
* email verification messages
* registration information
* password reset messages
* security-related system notifications
* support enquiries and replies
* other messages necessary for the operation of the user account
In connection with email communication, the recipient's email address, technical transmission information, and the content of the relevant message are processed.
Where processing is required for the provision of the user account or requested functions, the legal basis is **Art. 6(1)(b) GDPR**. Where communication is required for security purposes or the reliable operation of the portal, processing may be based on **Art. 6(1)(f) GDPR**.
No advertising or marketing emails are sent unless a separate legal basis exists for doing so.
---
## 14. Cookies
The portal uses only cookies or comparable storage mechanisms that are required for the operation of the portal and the functions expressly requested by the user.
No tracking, marketing, or analytics cookies are used.
### PHPSESSID
PHP may set a session cookie named **`PHPSESSID`** for the purpose of managing the user's session.
This cookie is used in particular to:
* recognise an authenticated user during their session,
* maintain the user's login status,
* assign requests to the correct user session, and
* ensure the security of the session.
The cookie contains only a randomly generated session ID and does not contain an email address, uploaded files, or comparable content.
The session ID may nevertheless be indirectly associated with an authenticated user.
The cookie is generally a session cookie and becomes invalid at the end of the session or after expiry of the server-side session, depending on the session configuration.
Its use is technically necessary in order to provide the login and user account functions.
---
## 15. No Tracking or Analytics
No external tracking, analytics, or advertising services are used.
In particular, the portal does not use services such as:
* Google Analytics
* Google Ads
* Meta Pixel
* Matomo
* comparable tracking or profiling systems
No user-specific tracking takes place for advertising purposes.
No user profiles are created for marketing or advertising purposes.
---
## 16. External Services and Recipients
Personal data is not sold or disclosed to third parties for advertising, analytics, or marketing purposes.
The following external technical service providers or recipients may in particular be involved:
**1blu AG**
Provision of the email infrastructure used by the portal.
**Deutsche Telekom**
Provision of the internet connection for the server operated directly by the controller.
Personal data may also be transmitted to public authorities, courts, or other authorised recipients where this is required by law or necessary for the establishment, exercise, or defence of legal claims.
Where a service provider processes personal data on behalf of the operator and the statutory requirements apply, processing is carried out on the basis of a data processing agreement pursuant to **Art. 28 GDPR**.
---
## 17. Transfers to Third Countries
There is no intentional transfer of user account data or uploaded files stored within the portal to countries outside the European Union or the European Economic Area.
The web and application server is located in Germany.
Should a transfer of personal data to a third country become necessary in the future, such transfer will only take place in compliance with the requirements of **Art. 44 et seq. GDPR**. This Privacy Policy will be updated accordingly.
---
## 18. Data Security
The operator implements appropriate technical and organisational measures to protect personal data and uploaded files against loss, manipulation, unauthorised access, and other security risks.
These measures include in particular:
* access restrictions,
* user authentication,
* storage of passwords exclusively in the form of cryptographic hashes,
* encrypted data transmission via HTTPS/TLS,
* regular technical backups, and
* measures designed to detect and prevent unauthorised access.
Absolute protection of data during electronic transmission and storage cannot be technically guaranteed.
---
## 19. Rights of Data Subjects
Subject to the applicable statutory requirements, data subjects have in particular the following rights:
* **Right of access** pursuant to Art. 15 GDPR
* **Right to rectification** pursuant to Art. 16 GDPR
* **Right to erasure** pursuant to Art. 17 GDPR
* **Right to restriction of processing** pursuant to Art. 18 GDPR
* **Right to data portability** pursuant to Art. 20 GDPR
* **Right to object** pursuant to Art. 21 GDPR
Where processing is based on consent, consent may be withdrawn at any time with effect for the future. The lawfulness of processing carried out prior to the withdrawal remains unaffected.
To exercise these rights, it is sufficient to contact:
**admin@mytuningserver.de**
Where there are justified doubts regarding the identity of the requesting person, an appropriate form of identification may be requested in order to prevent unauthorised disclosure, modification, or deletion of personal data.
---
## 20. Right to Object to Processing Based on Legitimate Interests
Where personal data is processed on the basis of **Art. 6(1)(f) GDPR**, the data subject has the right, pursuant to Art. 21 GDPR, to object at any time to such processing on grounds relating to their particular situation.
Where an objection is justified, processing will be discontinued unless compelling legitimate grounds for the processing exist which override the interests, rights, and freedoms of the data subject, or where processing is necessary for the establishment, exercise, or defence of legal claims.
---
## 21. Right to Lodge a Complaint with a Supervisory Authority
Pursuant to Art. 77 GDPR, data subjects have the right to lodge a complaint with a data protection supervisory authority if they believe that the processing of their personal data infringes the GDPR.
The supervisory authority responsible for the controller is in particular:
**The State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate**
Hintere Bleiche 34
55116 Mainz
Germany
Telephone: +49 (0) 6131 8920-0
Email: [poststelle@datenschutz.rlp.de](mailto:poststelle@datenschutz.rlp.de)
A complaint may also be lodged with any other supervisory authority competent pursuant to Art. 77 GDPR.
---
## 22. Requirement to Provide Personal Data
The provision of certain personal data is necessary in order to create a user account and use the functions of the portal.
Without the required information, the user account or relevant function may not be made available.
Uploading files and providing the information contained within them is generally voluntary. However, without providing a file to be processed, the respective file-processing function cannot be performed.
---
## 23. Changes to this Privacy Policy
This Privacy Policy may be amended if the technical functions of the portal, the systems or service providers used, or the applicable legal requirements change.
The current version published on the portal applies.
**Last updated: August 2026**