Privacy Policy

PRIVACY POLICY of the Beezybee Platform Last updated: July 2026 Version 1.1 ──────────────────────────────────────────────────────────── Section 1 – Controller and Contact (1) The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection provisions is: Beezybee Owner: Dirk Bock (sole trader) Theodolindestr. 32a 76744 Wörth am Rhein Germany Email: datenschutz@beezybee-app.de (2) For questions regarding data protection, you can reach us at any time at datenschutz@beezybee-app.de. (3) A Data Protection Officer has not been appointed by law, as the conditions of Art. 37 GDPR are not currently met. Please direct data protection inquiries to the email address above. ──────────────────────────────────────────────────────────── Section 2 – Overview of Data Processing (1) Beezybee is an intermediary platform for everyday help (Beezybee) and item lending (Borrowbee). This privacy policy informs you about which personal data we collect, for what purpose we process it, and what rights you have. (2) As a rule, we process personal data only to the extent necessary to provide a functional platform as well as our content and services. (3) The processing of personal data generally takes place only with the user's consent or where the processing is permitted by statutory provisions. ──────────────────────────────────────────────────────────── Section 3 – Legal Bases for Processing The processing of your data takes place on the basis of the following legal bases: a) Art. 6(1)(a) GDPR – Consent (e.g., push notifications, location sharing, camera access) b) Art. 6(1)(b) GDPR – Performance of a Contract (e.g., registration, job processing, payment processing, reviews, support) c) Art. 6(1)(c) GDPR – Legal Obligation (e.g., tax retention obligations, DAC7/PStTG reporting, anti-money-laundering measures) d) Art. 6(1)(f) GDPR – Legitimate Interest (e.g., fraud prevention, platform security, AI-supported content moderation, price optimization) ──────────────────────────────────────────────────────────── Section 4 – Data Collected in Detail 4.1 Registration and Account Data Upon registration, we collect: • Email address (mandatory) • Password (stored exclusively as a hash) • Display name / nickname Legal basis: Art. 6(1)(b) GDPR (performance of a contract) 4.2 Profile Data In your user profile, you may voluntarily provide: • First name, last name • Date of birth • Address (street, house number, postal code, city) • Phone number • Profile picture (avatar) • "About me" text (biography) • Interests and availability • Search radius for jobs (in km) • Role preferences (helper, seeker, lender) Legal basis: Art. 6(1)(b) GDPR 4.3 Identity Verification For the use of payment functions, we store: • Status of the identity proof submitted • Reference ID of the review process • Verified name (first and last name) • Verified date of birth • Verified address The actual identity verification (identity document, photo, comparison) is carried out by our payment service provider Stripe Identity (see Section 6.2). The identity document itself (document type, document number, document photo/selfie) is NOT stored on our servers, but is processed exclusively by Stripe. The verified master data reported back to us by Stripe Identity (name, date of birth, address) is, however, stored in our database; it is write-protected in the app and serves to fulfil our KYC/AML obligations as well as our tax reporting obligation (DAC7/PStTG, see Section 14). This processing serves to fulfill our KYC/AML obligations (Know Your Customer / Anti Money Laundering) and to prevent fraud. The data stored by us is deleted upon expiry of the statutory retention periods (see Section 8.4). Legal basis: Art. 6(1)(c) GDPR (German Anti-Money Laundering Act, GwG), Art. 6(1)(f) GDPR (fraud prevention) 4.4 Location Data Upon granting your consent, we collect: • GPS coordinates (latitude, longitude) • Time of the location capture We use location data exclusively for: • Job matching within the surrounding area (matching) • Displaying relevant offers near you • Distance calculation between user and job location • Live arrival estimate during active jobs (see below) Location data is not used for advertising or profiling purposes. DATA PROTECTION MEASURE (GEO-PRIVACY): Your exact location is NEVER shown to other users. For public display, we use a deterministic location fuzzing (fuzzy location) with a jitter of 300–500 metres. Only after a binding job acceptance is the full address (street + house number) disclosed to the assigned helper. LIVE ARRIVAL ESTIMATE (ETA): During an active job, the helper can optionally share their estimated time of arrival (ETA) with the job poster. Activation takes place exclusively upon the helper's express confirmation per job. No exact GPS position is transmitted in this process, only the estimated remaining time until arrival (e.g. "approx. 12 minutes"). Location capture ends automatically upon arrival at the job location or upon revocation by the helper. No movement or location history is stored. Legal basis: Art. 6(1)(a) GDPR (consent) Revocation: You can revoke the location sharing at any time in your device settings. The live arrival estimate can be declined per job or ended at any time. The platform then remains usable with limited functionality. 4.5 Job and Transaction Data When using the platform, we process: • Job title and description • Category, price suggestions, AI-extracted parameters • Applications and offers • Job status (open, assigned, active, completed) • Timestamps of all status changes For Borrowbee additionally: • Item description, condition, photos • Rental duration, rental price, purchase price as stated by the lender (as of the date of listing) • Booking periods Legal basis: Art. 6(1)(b) GDPR 4.5a Algorithmic Matching To match suitable helpers or items, we use an algorithmic scoring system (NO AI/GPT use). The following data is processed in this context: • Distance between user and job location (Haversine distance) • Category experience (completed jobs in the same category) • Availability and role preferences • Search radius and areas of interest • Favourite assignment (seeker → preferred helpers) No profile data is transmitted to third parties. Matching takes place exclusively on our own infrastructure (Firebase, EU). Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(f) GDPR (platform optimization) 4.6 Payment and Financial Data Payment processing is carried out via Stripe, Inc. We process: • Transaction amounts (net price, service fee, late charges where applicable) • Payment status (pending, successful, failed) • Stripe Account ID (for payouts to helpers/lenders) • Payout status (held-back payout) • Transaction metadata (job ID, user IDs) IMPORTANT: Credit card numbers, bank details, and other payment instruments are NEVER stored on our servers. These are processed exclusively by Stripe (see Section 6.2). Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(c) GDPR (tax obligations) 4.7 Review Data After completion of a job, users can submit reviews: • Star rating (1–5 stars) • Item rating (for Borrowbee) • Free-text feedback • Timestamp Reviews are published under the display name of the reviewer and are visible to other users. Legal basis: Art. 6(1)(f) GDPR (trust building) 4.8 Communication Data a) In-app chat between users: For assigned jobs (Beezybee) and rental transactions (Borrowbee), a chat is enabled. We process: • Message content (text and images) • Sender and recipient ID • Timestamp and read status Chat messages are stored for 12 months after completion of the respective transaction. Within the scope of a dispute resolution procedure, support may view chat histories (see Terms of Use Section 9(3)). Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(f) GDPR (dispute resolution) b) Support inquiries: • Ticket ID and message content • Timestamp • Association with the user account Legal basis: Art. 6(1)(b) GDPR 4.9 BeeCoins (Activity-Based Reward System) BeeCoins are a free reward system – not a purchasable product, not electronic money, not a virtual currency. Users receive BeeCoins automatically for activities on the platform (e.g., completing a job, lending out an item, inviting friends). We store: • Current coin balance • Transaction history (activity, time of award, amount) • Activity type and description Legal basis: Art. 6(1)(b) GDPR Leaderboard (ranking): The app displays a leaderboard that ranks active users based on pseudonymous data that is already visible in the public profile (nickname, profile picture, number of completed jobs or rentals, BeeCoin balance, city). Real names, contact details, or precise location data are not displayed there. You can object to being displayed in the leaderboard at any time in the settings under "Data & Privacy" (opt-out); your profile will then no longer appear in the ranking, while the internal counters continue unchanged. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in promoting activity and community features); right to object under Art. 21 GDPR via the settings. 4.10 Referral Program (Referrals) When using the referral program: • Personal referral code (4 digits) • Assignment: referrer → invitee • Bonus status (paid out / pending) NO contact data of the invitee is transmitted by the referrer. The invitee enters the code independently during registration. Legal basis: Art. 6(1)(b) GDPR 4.11 Helper Disclaimer and Tax Tracking To fulfill our information obligations and tax documentation obligations, we process: a) Helper disclaimer: • Confirmation status (helperDisclaimerAccepted) • Timestamp of the confirmation (helperDisclaimerAcceptedAt) • Version of the confirmed disclaimer text (helperDisclaimerVersion) b) Tax tracking: • Cumulative annual earnings in cents (yearlyEarningsCents) • Cumulative annual transaction count (yearlyTransactionCount) • Tax notices displayed per year (taxHintsShown) • Dismissed tax banners per year (taxBannerDismissed) • Archived annual earnings from previous years (earningsArchive) c) Profile tier and proof: • Profile level (profilTier: 1 = basic status without trade registration proof on file, 2 = professional with proof on file) • Proof status (tierStatus: pending, approved, rejected) • Timestamp of the proof review (tierVerifiedAt) • Uploaded proof documents (trade licence, chamber of crafts (HWK) card, comparable official permits) Storage of the documents: The uploaded photo or scan is stored in Firebase Cloud Storage. Only the download URL of the document is stored in the user profile, not the document content itself. Scope of review: The Operator reviews uploaded documents exclusively for plausibility (visual inspection), i.e. legibility, document type, and obvious forgeries. This review does NOT constitute a substantive confirmation of the validity, currency, or professional qualification. The display "proof on file" merely confirms that a document has been uploaded and a plausibility check has been carried out. Retention: Proof documents are stored until deletion of the user account or until revocation of the Tier 2 status, and are deleted thereafter. This data serves the documented acknowledgment of tax obligations, the automated tax notices, and the licensing-requirement check. Legal basis: • Art. 6(1)(b) GDPR (performance of a contract – disclaimer) • Art. 6(1)(c) GDPR (legal obligation – tax tracking, DAC7 reporting obligation) • Art. 6(1)(f) GDPR (legitimate interest – prevention of undeclared work, enforcement of licensing requirements) 4.12 Local Data Storage on Your Device We store on your device: • Authentication token (AsyncStorage, for automatic login) • Form drafts (SecureStore, encrypted) • AI-generated recommendation texts (AsyncStorage, cache) This data does not leave your device and is deleted upon uninstallation of the app. Legal basis: Art. 6(1)(f) GDPR ──────────────────────────────────────────────────────────── Section 5 – AI-Supported Data Processing 5.1 Areas of AI Use Beezybee uses AI systems (OpenAI GPT models) for the following purposes: a) PRICE DETERMINATION The title and description of your job are transmitted to OpenAI in order to extract relevant parameters (scope, effort, distance, etc.) and to calculate a fair price suggestion. b) CONTENT MODERATION Every job and every listing is automatically checked for prohibited content (illegal activities, work requiring a licence, prohibited items). c) CATEGORY ASSIGNMENT Jobs are automatically assigned to a suitable category. d) SUPPORT ASSISTANCE Support messages may be pre-processed by AI in order to enable faster responses. 5.2 Data Transmitted The following is transmitted to OpenAI exclusively: • Job title and description • Category information • No personal data such as name, email, or address The transmitted texts are used exclusively for real-time analysis within the scope of a data processing relationship and are not stored by OpenAI or used for model training (see Section 6.3). RECOMMENDATION: Do not include any personal data (phone numbers, addresses, etc.) in job or item descriptions. 5.3 Automated Individual Decision-Making (Art. 22 GDPR) The AI-supported content moderation may result in a job or listing being automatically rejected (e.g., upon detection of activities requiring a licence or prohibited content). This constitutes a partially automated decision. There is NO solely automated decision that produces legal effects concerning you or similarly significantly affects you without a human review being possible (Art. 22(1) GDPR). YOUR RIGHTS: • You are immediately informed of the rejection • You may resubmit the job with an adjusted description • In case of objection, you may contact support@beezybee-app.de at any time – a manual review will then be carried out promptly Legal basis: Art. 6(1)(f) GDPR in conjunction with Art. 22(2)(a) GDPR (conclusion of a contract) 5.4 AI Logging For quality assurance and cost monitoring, we log: • AI model used • Number of tokens processed (input/output) • Processing duration • Calculated API costs (in USD) • User association (UID) and timestamp NO content (texts, descriptions) is stored in the logs. Legal basis: Art. 6(1)(f) GDPR (cost control, abuse detection) ──────────────────────────────────────────────────────────── Section 6 – Recipients and Processors 6.1 Google Cloud / Firebase Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland Services: • Firebase Authentication (user management) • Cloud Firestore (database) – Region: europe-west3 (Frankfurt) • Cloud Storage (image storage) • Cloud Functions (backend logic) – Region: europe-west3 • Cloud Messaging (push notifications) • Firebase Crashlytics (crash reports and stability analysis) In the event of an app crash, Firebase Crashlytics collects: • Device model, operating system version • Stack trace (technical error log) • Time of the crash • App version and build number • Installation ID (pseudonymized, no personal reference) NO personal data (name, email, location) is collected by Crashlytics. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the stability and bug fixing of the platform) Data storage location: EU (Frankfurt am Main) Safeguards: Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR, EU Data Processing Addendum Privacy notice: https://firebase.google.com/support/privacy 6.2 Stripe, Inc. Provider: Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland (EU processing) Services: • Payment processing (Payment Intents) • Holding of payments until payout (deferred payout) • Payouts to helpers/lenders (Connect) • Webhook processing (status updates) Data transmitted: • Payment amounts and breakdown • Transaction metadata (job ID, user IDs) • Stripe Account ID NOT transmitted: profile picture, location, job descriptions, reviews Safeguards: Stripe is recognized under the EU-US Data Privacy Framework. Additionally SCCs. Privacy notice: https://stripe.com/de/privacy 6.3 OpenAI, L.L.C. Provider: OpenAI, L.L.C., 3180 18th Street, San Francisco, CA 94110, USA Services: • AI-supported text analysis (price determination, moderation) • Categorization of jobs Data transmitted: • Job title and description (NO personal data such as name, email, address, phone number) API usage: Data is processed via the OpenAI API. According to the OpenAI API Data Usage Policy, API inputs and outputs are NOT used for the training of models. Safeguards: Data Processing Addendum (DPA), SCCs. We have reviewed the technical and organizational measures (TOMs) of OpenAI to the best of our knowledge and on the basis of the available information, and assessed them as adequate. Privacy notice: https://openai.com/policies/privacy-policy 6.4 Google Maps Platform Provider: Google Ireland Limited Services: • Map display (job locations, heatmap) • Geocoding (address → coordinates) Data transmitted: • Fuzzed GPS coordinates (fuzzy location, NOT exact) • Device IP address (collected by Google) Privacy notice: https://policies.google.com/privacy 6.5 Expo (Over-the-Air Updates) Provider: Expo, Inc., 140 2nd Street, 4th Floor, San Francisco, CA 94105, USA Services: • Provision of app updates without an app store update (Over-the-Air Updates / OTA) Data transmitted: • App version and runtime version • Platform (iOS/Android) and device type • Expo project ID • Device IP address (collected by Expo) NO personal user data is transmitted. Safeguards: SCCs, DPA Privacy notice: https://expo.dev/privacy 6.6 Third-Party Authentication Services (Social Login) For sign-in via third-party accounts, we use: a) Google Sign-In Provider: Google Ireland Limited Data transmitted: email address, display name, profile picture URL Legal basis: Art. 6(1)(b) GDPR b) Apple Sign-In Provider: Apple Inc., Cupertino, CA, USA Data transmitted: email address (where applicable, a relay address anonymized by Apple), display name Legal basis: Art. 6(1)(b) GDPR c) Facebook Login (Meta) Provider: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland Data transmitted: Upon sign-in via Facebook, an access token is exchanged between the app and Meta; we receive the email address and the display name of the account from Meta. Legal basis: Art. 6(1)(b) GDPR Sign-in via third-party providers is voluntary. Alternatively, registration can be carried out via email and password. 6.7 Email Dispatch (Namecheap / Private Email) Provider: Namecheap, Inc., 4600 East Washington Street, Suite 305, Phoenix, AZ 85034, USA (service "Private Email") Services: • Dispatch of transactional emails (e.g., verification, notifications, support) via our SMTP outgoing mail server Data transmitted: • Email address of the recipient, display name, subject line and content of the respective message Safeguards: Standard Contractual Clauses (SCCs) Privacy notice: https://www.namecheap.com/legal/general/privacy-policy/ 6.8 DHL (Shipping and Parcel Tracking) Provider: DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany Services (Borrowbee shipments only): • Automated retrieval of shipment status based on the DHL tracking number provided by the user, to determine delivery and return times Data transmitted: • DHL tracking number The creation of the shipping label and the disclosure of the recipient's address to DHL are carried out independently by the shipping contracting party directly with DHL, not by the platform. Privacy notice: https://www.dhl.de/de/privatkunden/datenschutz.html ──────────────────────────────────────────────────────────── Section 7 – Data Transfers to Third Countries (1) Firebase/Google Cloud: Primary data storage in the EU (europe-west3, Frankfurt). Certain administrative functions may be processed in the USA. Safeguard: EU-US Data Privacy Framework, SCCs (2) Stripe: EU payments are processed via Stripe Payments Europe (Ireland). Partial processing in the USA. Safeguard: EU-US Data Privacy Framework, SCCs (3) OpenAI: Processing in the USA. Safeguard: SCCs, DPA (4) Expo: Processing in the USA (OTA updates). Safeguard: SCCs, DPA. No personal data is transmitted. (6) Meta (Facebook Login): Processing also in the USA. Safeguard: EU-US Data Privacy Framework, SCCs (7) Namecheap (email dispatch): Processing in the USA. Safeguard: SCCs (8) For all third-country transfers, we ensure through appropriate safeguards (Art. 46 GDPR) that a level of data protection comparable to EU law is guaranteed. ──────────────────────────────────────────────────────────── Section 8 – Data Storage and Deletion Periods 8.1 Account Data Your account data is stored as long as your account exists. After deletion of your account, personal data is deleted within 30 days, unless statutory retention obligations preclude this. 8.2 Payment and Transaction Data Due to tax and commercial law retention obligations (Section 147 of the German Fiscal Code (AO), Section 257 of the German Commercial Code (HGB)), payment data is retained for 10 years. After expiry of the period, it is automatically deleted. 8.3 DAC7/PStTG Reporting Data Data required for the report under the German Platform Tax Transparency Act (PStTG) is stored for 10 years after the end of the reportable period (Section 25(2) PStTG). 8.4 Identity Verification Data on the identity proof is stored for the duration of the account's existence plus 5 years (Section 8 of the German Anti-Money Laundering Act (GwG)). 8.5 Location Data The last captured location is overwritten with each update. No location history is stored. Upon revocation of the location consent, stored coordinates are deleted within 7 days. ETA data from the live arrival estimate is cached only for the duration of the active job and deleted immediately upon completion or cancellation of the job. 8.6 AI Logs Internal AI usage logs (without text content) are stored for 12 months for billing and quality purposes. 8.7 Support Tickets Support communication is stored for 3 years after closure of the ticket (limitation period, Section 195 of the German Civil Code (BGB)). 8.8 Reviews Reviews remain visible for the duration of the existence of the reviewed user's account. Upon account deletion, reviews are anonymized (display name removed). 8.9 Local Device Data Local data (AsyncStorage, SecureStore) is automatically deleted upon uninstallation of the app. ──────────────────────────────────────────────────────────── Section 9 – Your Rights as a Data Subject (1) You have the following rights vis-à-vis the controller with regard to your personal data: a) RIGHT OF ACCESS (Art. 15 GDPR) You have the right to request information about the personal data we process. We will provide you with a free copy. b) RIGHT TO RECTIFICATION (Art. 16 GDPR) You may request the rectification of inaccurate data. You can change profile data yourself in the app at any time. c) RIGHT TO ERASURE (Art. 17 GDPR) You may request the deletion of your data, unless statutory retention obligations preclude this. You can request account deletion at: • Email: datenschutz@beezybee-app.de • Online: https://www.beezybee-app.de/konto-loeschen Deletion of individual data without account deletion is possible at: https://www.beezybee-app.de/daten-loeschen d) RIGHT TO RESTRICTION (Art. 18 GDPR) You may request the restriction of processing, e.g., where the accuracy of your data is contested. e) RIGHT TO DATA PORTABILITY (Art. 20 GDPR) You have the right to receive the data concerning you in a structured, commonly used, and machine-readable format. We provide you with this as a JSON export. f) RIGHT TO OBJECT (Art. 21 GDPR) You may object to the processing of your data at any time, insofar as the processing is based on legitimate interest. We will then no longer process your data, unless we can demonstrate compelling legitimate grounds worthy of protection. g) RIGHT TO WITHDRAW CONSENT (Art. 7(3) GDPR) You may withdraw a granted consent (e.g., location sharing) at any time. The lawfulness of the processing carried out on the basis of the consent until withdrawal is not affected thereby. (2) To exercise your rights, an informal message to datenschutz@beezybee-app.de is sufficient. We will process your request within 30 days (Art. 12(3) GDPR). For identity verification, we may ask you to confirm via the email address stored in the app. ──────────────────────────────────────────────────────────── Section 10 – Right to Lodge a Complaint with the Supervisory Authority (1) You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. (2) Competent supervisory authority: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg) Lautenschlagerstraße 20 70173 Stuttgart Phone: +49 711 615541-0 Email: poststelle@lfdi.bwl.de Web: https://www.baden-wuerttemberg.datenschutz.de ──────────────────────────────────────────────────────────── Section 11 – Data Security (1) We employ technical and organizational measures to protect your data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons: a) ENCRYPTION • All data transfers take place via TLS 1.2+ • Sensitive local data is stored in SecureStore (platform-specific encryption) • Passwords are stored by Firebase exclusively as a hash (scrypt) b) ACCESS PROTECTION • Firebase Security Rules restrict data access to the respective account holder • Admin access is logged in an audit log (type, target UID, reason, timestamp) • Cloud Functions enforce authentication c) GEO-PRIVACY • Deterministic location jitter (300–500 m) for public display • Full address only after job assignment • No location history d) DATA MINIMIZATION • Profile picture upload at reduced quality (60%) • No storage of payment instruments • AI logs without text content ──────────────────────────────────────────────────────────── Section 12 – Push Notifications (1) Upon granting your consent, we send push notifications about: • Job updates and status changes • New relevant jobs near you • Application updates • Rewards and BeeCoins • Platform news (optional) (2) You can granularly control the type and frequency of the notifications in the app's push settings: • Maximum notifications per day (0–20) • Quiet hours (start/end time) • Radius filter (1–200 km) • Minimum job value (0–10,000 €) • Toggle on/off by category (3) You can withdraw the consent at any time by: • Deactivation in the app settings • Deactivation in the device settings Legal basis: Art. 6(1)(a) GDPR ──────────────────────────────────────────────────────────── Section 13 – Profile Picture and Media (1) Profile pictures are stored in Firebase Cloud Storage at the path: users/{UID}/avatar.jpg (2) Profile pictures are visible to other logged-in users (e.g., for applications, reviews, profiles). (3) You can change or delete your profile picture at any time. The previous image is overwritten in the process. (4) Job-related photos (e.g., item images for Borrowbee) are stored under the respective job and are deleted together with the deletion of the job. Legal basis: Art. 6(1)(b) GDPR ──────────────────────────────────────────────────────────── Section 14 – Tax Reporting Obligations (DAC7 / PStTG) (1) As a platform operator, we are subject to the reporting obligations of the German Platform Tax Transparency Act (PStTG) implementing the EU Directive DAC7. (2) We are obliged to transmit the following data of reportable users to the German Federal Central Tax Office (BZSt): • First and last name • Address • Date of birth • Tax identification number (if available) • VAT identification number (if available) • Total amount of remuneration per quarter • Number of transactions per quarter • Bank account details (insofar as known) (3) The scope of the reporting obligation depends on the type of activity: • Personal services are reportable without a de minimis threshold (from the first euro); • the provision of means of transport likewise; • the threshold of fewer than 30 activities and under €2,000 applies only to the sale of goods; • the mere rental of movable property is not reportable. (4) The report is filed automatically by 31 January of the following year. We inform affected users in advance by email. Legal basis: Art. 6(1)(c) GDPR (Sections 13-18 PStTG) ──────────────────────────────────────────────────────────── Section 15 – Audit Log and Fraud Prevention (1) For fraud prevention and in dispute cases, we log administrative actions in an audit log: • Type of action (e.g., account suspension, data export) • Affected user ID • Performing administrator • Justification • Timestamp (2) In the event of justified suspicion of fraud, money laundering, or criminal offences, we may: • Freeze the affected account (including held-back payments) • Create a data export for law enforcement authorities (only upon court order or in cases of imminent danger) (3) Audit log entries are stored for 10 years (Section 147 of the German Fiscal Code (AO)). Legal basis: Art. 6(1)(c) GDPR (Section 261 of the German Criminal Code (StGB)), Art. 6(1)(f) GDPR (fraud prevention) ──────────────────────────────────────────────────────────── Section 16 – Disclosure to Third Parties (1) A transmission of your personal data to third parties does not take place as a matter of principle, except in the cases mentioned below: • You have explicitly consented (Art. 6(1)(a)) • The transmission is necessary for the performance of a contract (Art. 6(1)(b)) – e.g., to Stripe for payment processing • A legal obligation exists (Art. 6(1)(c)) – e.g., to tax authorities (DAC7) • The transmission is necessary to safeguard legitimate interests and your interests do not prevail (Art. 6(1)(f)) – e.g., to law enforcement authorities in case of suspicion of criminal offences (1a) Disclosure to the other contracting party in the event of damage or late return: If a lender reports damage, or a renter does not return an item despite a request to do so (from the 8th day of delay), the lender may, upon request, be provided with the renter's contact details (name, address) required to assert their legal claims. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in legal enforcement). The affected user is informed about the disclosure. (2) We do NOT sell your data. We do NOT use your data for third-party advertising purposes. We do NOT use any tracking or advertising SDKs for marketing purposes. The integrated SDKs (Firebase, Google Maps) serve exclusively for the operation of the platform and are described in detail in Section 6. ──────────────────────────────────────────────────────────── Section 17 – Cookies and Ad Measurement (1) The Beezybee app does NOT use cookies. (2) To measure whether our Meta ads result in installs and app starts, we use Meta App Events only after your explicit consent. The legal basis is Art. 6(1)(a) GDPR. Without consent, no Meta ad measurement takes place and the app works identically. (3) App events such as installation and app start, as well as device information, may be transmitted to Meta Platforms Ireland Limited. On iOS, the advertising identifier is used only after additional permission through Apple's App Tracking Transparency. You can withdraw consent at any time in the settings under “Ad measurement”. (4) In addition, iOS uses SKAdNetwork for anonymous, aggregated counting of installs from ad campaigns. No individual user profiles are created. (5) To improve the platform, we collect anonymized or pseudonymized internal usage statistics (e.g., which screens are accessed). This data is stored exclusively in our own database (Firestore, EU) and is NOT passed on to third parties. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in product improvement) (6) We do not create user profiles for advertising purposes outside the Meta ad measurement explicitly consented to. (7) The only locally stored data is: • Authentication token (functionally required) • Form drafts (encrypted, only on your device) • AI recommendation cache (local, not personal) ──────────────────────────────────────────────────────────── Section 18 – Minors (1) The platform is not directed at persons under 18 years of age. We do not knowingly collect any data from minors. (2) Should we become aware that data of a minor has been processed, we will delete it without undue delay and block the associated account. ──────────────────────────────────────────────────────────── Section 19 – Changes to This Privacy Policy (1) We reserve the right to adapt this privacy policy in order to adjust it to changed legal situations or in the event of changes to the service or the data processing. (2) In the case of material changes, we will inform you via the app (push notification or in-app notice). (3) The respective current version is available at any time in the app under Profile → Legal & External → Privacy Policy, as well as at https://www.beezybee-app.de/datenschutz. ──────────────────────────────────────────────────────────── Section 20 – Contact For questions, requests for access, or complaints regarding data protection, please contact: Email: datenschutz@beezybee-app.de Subject: "Data Protection – [your concern]" Postal address: Beezybee Owner: Dirk Bock (sole trader) Theodolindestr. 32a 76744 Wörth am Rhein Germany We endeavour to respond to your concern within 30 days. ──────────────────────────────────────────────────────────── The German version of this privacy policy is legally binding. An English translation is provided for informational purposes. ────────────────────────────────────────────────────────────