This Privacy Policy governs the collection, processing, and storage of personal data by M-T-D Innenausbau GmbH operating under the brand name Ceilingrepairly (“we”, “our”, or “us”), via our website www.ceilingrepairly.com (the “Website”). We are committed to safeguarding personal data in strict compliance with the Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation – GDPR) and applicable German federal data protection laws (Bundesdatenschutzgesetz – BDSG).
- Data Controller Identity
The data controller responsible for the processing of personal data collected through the Website within the meaning of the GDPR is:
M-T-D Innenausbau GmbH
Feldkirchener Str. 25, 85622 Vaterstetten-Weißenfeld, Germany
Registration Number: HRB 267953
Email: beauty@ceilingrepairly.com
- Nature of Services and Booking Workflow
Our Website facilitates professional on-site ceiling repair services. Our operational workflow involves:
Initial Inquiry: Customers submit project details and requirements via our online inquiry form.
Consultation and Quotation: We review the requirements, communicate project specifics, and establish a customized service quotation.
Deposit Booking: Upon agreeing to the service proposal, customers pay an initial service deposit via our online payment gateway.
On-Site Execution: Our technicians perform the scheduled on-site installation and repair work, followed by final project completion and settlement.
- Categories of Personal Data Collected
We collect and process personal data strictly necessary for fulfilling inquiries, processing online deposit payments, and coordinating scheduled service appointments. The data collected includes:
Identification and Contact Data: Full name, postal address, telephone number, and email address provided during inquiries or booking submissions.
Project Specifications: Details regarding the ceiling repair requirements, photographs or descriptions of the project site submitted voluntarily by the user.
Transaction and Payment Data: Details concerning deposit payments. Please note that payment card details are processed directly by our third-party payment processor; we do not store full credit card numbers on our servers.
Technical Log Data: IP address, browser type, operating system, access timestamps, and referring URLs collected automatically when visiting the Website.
- Legal Basis and Purposes of Processing
We process personal data only when permitted by law under the GDPR, specifically based on the following legal grounds:
Performance of a Contract (Article 6(1)(b) GDPR): Processing is necessary for taking steps prior to entering into a service contract, handling booking deposits, managing communications, and executing scheduled on-site repair services.
Compliance with Legal Obligations (Article 6(1)(c) GDPR): Processing is required to satisfy statutory commercial, tax, and accounting record-keeping obligations under German law (such as the Handelsgesetzbuch – HGB and Abgabenordnung – AO).
Legitimate Interests (Article 6(1)(f) GDPR): Processing is necessary for ensuring network and information security, preventing fraudulent transactions, and maintaining the operational integrity of the Website.
- Payment Processing via Stripe
To process online deposit payments securely, we utilize the payment gateway services provided by Stripe (Stripe Payments Europe, Ltd. / Stripe, Inc.). When you make a deposit payment on our Website, your payment details (such as card number, expiration date, and CVC code) are transmitted directly to Stripe.
Stripe processes your transaction data in compliance with PCI-DSS Level 1 security standards and applicable data protection regulations. We do not store or retain complete payment card credentials on our systems. For further information regarding Stripe’s data privacy practices and data retention policies, please consult Stripe’s official privacy policy on their website.
- Data Retention Periods
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements:
Inquiry and Communication Data: Personal data submitted via contact forms without subsequent contract formation is retained for a maximum period of 12 months, unless statutory retention obligations require longer storage.
Contractual and Transaction Records: Data relating to service agreements, project bookings, and deposit transactions is retained for 10 years in accordance with commercial and tax retention mandates stipulated by German tax law (Abgabenordnung – AO) and the German Commercial Code (Handelsgesetzbuch – HGB).
Technical Log Data: Server log files and technical access data are automatically deleted or anonymized within 30 days of collection, unless required for investigating security incidents.
- Data Disclosure and Recipients
We maintain strict confidentiality regarding your personal data. Data is disclosed only to third parties where strictly necessary for operational execution:
Payment Service Providers: Transaction data is transmitted to Stripe for secure deposit processing.
IT and Hosting Service Providers: Technical infrastructure providers supporting Website hosting and database administration under strict data processing agreements.
Legal and Regulatory Authorities: Competent public authorities, courts, or tax offices when mandated by applicable European or German law.
We do not sell, trade, or rent personal data to unauthorized external parties.
- Data Subject Rights
Under Chapter III of the GDPR, data subjects located in the European Union enjoy comprehensive rights regarding their personal data, including:
Right of Access (Article 15 GDPR): The right to obtain confirmation as to whether personal data concerning you is being processed and to access such data.
Right to Rectification (Article 16 GDPR): The right to demand the correction of inaccurate personal data or the completion of incomplete data.
Right to Erasure (Article 17 GDPR): The right to request the deletion of personal data, subject to statutory retention exceptions.
Right to Restriction of Processing (Article 18 GDPR): The right to restrict the processing of personal data under specific statutory conditions.
Right to Data Portability (Article 20 GDPR): The right to receive personal data provided to us in a structured, commonly used format.
Right to Object (Article 21 GDPR): The right to object to processing based on legitimate interests.
To exercise any of these rights, please contact us at: beauty@ceilingrepairly.com.
You also have the right to lodge a complaint with a competent supervisory data protection authority, in particular in the EU Member State of your habitual residence or workplace (e.g., the Landesbeauftragte für den Datenschutz in Bayern).
- Updates to This Privacy Policy
We reserve the right to amend this Privacy Policy periodically to reflect operational modifications, regulatory updates, or changes in legal requirements. The current version published on our Website shall apply.