Privacy Policy

SaaS platform “ReviewBird” · reviewbird.io and dashboard.reviewbird.io

Version 1.0.0, dated July 27, 2026.

Non-binding English translation. The German version prevails.

1. Controller and contact

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Schild Roth SEO Agentur GmbH, Bismarckstr. 1–3, 50672 Cologne, Germany. Represented by its Managing Director Timothy Scherman.

For data protection matters you can reach us at [email protected]. No data protection officer has been appointed; the statutory obligation to appoint one is kept under continuous review.

2. Scope and allocation of roles

This privacy policy applies to the processing of personal data in which we decide as the controller – in particular when you visit our website, register and use a customer account, and in connection with contract initiation, billing and communication.

Insofar as our customers use the platform to process data of their own end customers (e.g. patients, clients, guests, customers), the respective customer is the controller under data protection law and we act as a processor pursuant to Article 28 GDPR. The Data Processing Agreement concluded between us and the customer applies to such processing; informing the affected end customers is the customer’s responsibility.

3. Legal bases

We process personal data on the basis of Article 6(1) GDPR, in particular for the performance of a contract and pre-contractual measures (point (b)), to comply with legal obligations (point (c)), on the basis of legitimate interests (point (f)) and – where required – on the basis of your consent (point (a)), for example for analytics cookies and the newsletter.

4. Provision of the website and server log files

When you access our website and the dashboard, our system automatically processes data from the accessing device in order to ensure delivery, stability and security. This includes in particular the IP address, date and time of access, the resource accessed, the volume of data transferred, the referrer and browser and operating system information.

The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in secure and trouble-free operation. Hosting takes place with Hetzner Online GmbH (Germany); we use Cloudflare, Inc. (USA) for delivery and protection. Log files are deleted or anonymized after 30 days at the latest, unless they are required to investigate a specific security incident.

5. Cookies and consent (Section 25 TDDDG)

We use cookies and comparable technologies. Technically necessary cookies that are required for operation, login and security are used on the basis of Section 25(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG) and Article 6(1)(f) GDPR without consent.

All non-essential cookies and technologies – in particular for analytics and reach measurement – are used only with your prior consent pursuant to Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR. You give consent via our cookie banner; you can withdraw it at any time with effect for the future via the settings in the banner.

6. Web analytics with Google Analytics

On the basis of your consent (Article 6(1)(a) GDPR, Section 25(1) TDDDG) we use Google Analytics, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies and similar identifiers to evaluate the use of our website statistically (e.g. pages accessed, time spent, approximate origin, devices used). The IP address is truncated (IP anonymization).

A transfer to Google LLC in the USA cannot be ruled out; such transfer is safeguarded by the EU-US Data Privacy Framework, under which Google is certified, and additionally by standard contractual clauses. You can withdraw your consent at any time via the cookie banner. Further information can be found in Google’s privacy policy.

7. Registration and customer account

For registration and the maintenance of a customer account we process the data you provide, in particular company name, first and last name of the contact person, email address, telephone number and a password. The password is stored exclusively as a non-reversible hash and is not known to us in plain text.

The legal basis is Article 6(1)(b) GDPR (establishment and performance of the usage relationship). When our contractual documents are accepted (Licence and Usage Terms, Data Processing Agreement and, where applicable, the Confidentiality Agreement), we log the applicable version, date, time, user account and IP address for evidentiary purposes; the legal basis for this is Article 6(1)(c) and (f) GDPR.

8. Performance of the contract and payment processing

In order to provide the services booked and for billing purposes, we process the necessary inventory, contract and billing data on the basis of Article 6(1)(b) GDPR. Payment is processed via Stripe Payments Europe, Limited (Ireland); the payment data processed in this context is processed in accordance with Stripe’s requirements. Tax and commercial law retention obligations (Article 6(1)(c) GDPR) remain unaffected.

9. Communication and support

If you contact us by email, via the support or ticket system or by other means, we process your details in order to handle the request. The legal basis is Article 6(1)(b) GDPR insofar as the request serves the performance of the contract, and otherwise Article 6(1)(f) GDPR (efficient handling of enquiries).

10. Newsletter and advertising by email

If you subscribe to our newsletter, we process your email address and the data required for registration in order to send you information about our products and offers. Registration takes place using the double opt-in procedure; we log registration and confirmation for evidentiary purposes.

The legal basis is your consent pursuant to Article 6(1)(a) GDPR in conjunction with Section 7(2) of the German Act Against Unfair Competition (UWG). You can unsubscribe from the newsletter at any time via the unsubscribe link in every email or by sending us a message; withdrawal does not affect the lawfulness of processing carried out up to that point. Insofar as we have obtained your email address in connection with a contract, we may send you information about our own similar services within the scope permitted by Section 7(3) UWG; you may object to this at any time.

11. Recipients and processors

Within our company, only those departments that require your data to perform their tasks are given access to it. In addition, we engage carefully selected service providers as processors pursuant to Article 28 GDPR, in particular for hosting, infrastructure, message dispatch, payment processing and analytics.

  • Hetzner Online GmbH (Germany) – hosting and infrastructure
  • Cloudflare, Inc. (USA) – web infrastructure, security and delivery
  • seven communications GmbH & Co. KG (Germany) – sending of SMS
  • AC PM LLC / Postmark (USA) – sending of transactional emails
  • Google Ireland Limited (Ireland) – web analytics (only with consent)
  • Stripe Payments Europe, Limited (Ireland) – payment processing

The current overview of the sub-processors engaged in the context of processing on behalf of customers is available at https://dashboard.reviewbird.io/legal/sub-processors.

12. Transfers to third countries

Insofar as we engage service providers based or processing data outside the EU/EEA (in particular in the USA), a transfer takes place only where appropriate safeguards are in place. These are in particular certification under the EU-US Data Privacy Framework or the conclusion of the European Commission’s standard contractual clauses together with supplementary protective measures.

13. Storage period

We process personal data only for as long as is necessary for the respective purposes. Server log files are deleted or anonymized after 30 days at the latest. Account data is stored for the term of the contractual relationship and deleted after its end in accordance with the Licence and Usage Terms. For data subject to statutory retention obligations (in particular invoices), the statutory periods of generally six to ten years apply; such data is blocked until the period expires.

14. Your rights

Subject to the statutory requirements, you have the right of access (Article 15), to rectification (Article 16), to erasure (Article 17), to restriction of processing (Article 18), to data portability (Article 20) and a right to object (Article 21) to processing based on Article 6(1)(f) GDPR.

Insofar as processing is based on consent, you may withdraw it at any time with effect for the future (Article 7(3) GDPR). A message to [email protected] is sufficient to exercise your rights.

You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

15. No automated decision-making

Automated decision-making, including profiling, within the meaning of Article 22 GDPR does not take place.

16. Obligation to provide data and updates

Providing the data required for registration and performance of the contract is necessary for the conclusion of the contract; without this information we cannot conclude or perform the contract. We adapt this privacy policy if the legal situation or our processing changes. The version published on our website at the relevant time applies.