Rentowa rental management software logo
    Back to home

    Privacy Policy

    Last updated: 27 August 2026

    1. Privacy at a glance

    General information

    The following notes provide an overview of what happens to personal data when you use the Rentowa website, the Rentowa web application, the Rentowa iOS app or other services we provide.

    Personal data is any information relating to an identified or identifiable natural person.

    Detailed information can be found in the sections of this privacy policy below.

    Who is responsible?

    The controller for the processing described in this privacy policy is Alwin Gilles e.K., Uedemer Straße 1–7, 47546 Kalkar, Germany. Contact person: Milcho Jovanovski. Email: contact@rentowa.com. Phone: +49 162 399 7926.

    How do we collect data?

    Data is processed in particular when you:

    • visit rentowa.com,
    • submit a contact or demo form,
    • use a Rentowa user account,
    • use Rentowa as an administrator or employee of a rental company,
    • request support,
    • take part in a product demonstration or online meeting,
    • use features such as the camera, QR/barcode scanner or digital signatures.

    Other data is generated automatically when operating the website or application, for example technical connection, server, security and log data.

    What do we use data for?

    • providing and securing our website and applications,
    • managing user accounts and company access,
    • performing and administering our contractual relationships,
    • handling inquiries,
    • providing support,
    • sending transactional emails,
    • error diagnosis and ensuring IT security,
    • complying with legal obligations.

    What rights do you have?

    Subject to the statutory requirements, you have rights to:

    • access,
    • rectification,
    • erasure,
    • restriction of processing,
    • data portability,
    • objection,
    • withdrawal of consent given,
    • lodging a complaint with a data protection supervisory authority.

    2. Controller

    The controller within the meaning of the General Data Protection Regulation is:

    Alwin Gilles e.K., Uedemer Straße 1–7, 47546 Kalkar, Germany

    Contact person: Milcho Jovanovski

    Email for general and data protection inquiries: contact@rentowa.com

    Phone: +49 162 399 7926

    Website: https://rentowa.com

    For data protection inquiries, the contact address stated above is available.

    3. Scope

    This privacy policy applies to the processing of personal data by Alwin Gilles e.K. in connection with:

    • the marketing website rentowa.com,
    • the Rentowa web application,
    • the Rentowa iOS app,
    • user accounts and company access,
    • contact, demo and support inquiries,
    • billing and administration of Rentowa contract customers,
    • public Rentowa catalogues and booking request features, insofar as Alwin Gilles e.K. is itself the controller,
    • our official social media presences.

    For future applications or features, this privacy policy applies only insofar as they are actually described in it. Before introducing new processing activities, the privacy policy will be updated accordingly.

    4. Roles of Rentowa and the rental companies

    4.1 Rentowa as controller

    Alwin Gilles e.K. is responsible in particular for processing whose purposes and means we determine ourselves. This includes in particular:

    • operation of the marketing website,
    • handling contact and demo inquiries,
    • administration of the Rentowa contractual relationship,
    • administration of Rentowa user accounts,
    • billing of our own services,
    • general security and abuse prevention,
    • support and communication,
    • operation of our social media presences.

    4.2 Rentowa as processor

    Rental companies may use Rentowa to process personal data of their own customers, contacts, employees or business partners. This may include, for example:

    • customer master data,
    • bookings,
    • rental contracts,
    • invoices,
    • payment information,
    • delivery addresses,
    • handover and return protocols,
    • condition and damage photos,
    • digital signatures,
    • internal notes.

    In these cases, the respective rental company is generally the controller within the meaning of the GDPR. Alwin Gilles e.K. generally processes the data as a processor under Art. 28 GDPR and on the documented instructions of the rental company.

    The details of this processing are governed by a separate data processing agreement.

    4.3 Public catalogues and booking requests

    If a rental company provides a public product catalogue or booking request form via Rentowa, the respective rental company is generally responsible for the customer data collected there.

    The relevant booking form must therefore refer to the privacy policy of that rental company.

    This Rentowa privacy policy does not replace the rental company's own privacy information towards its customers.

    Data subjects whose data was stored in Rentowa by a rental company should generally first contact that rental company to exercise their rights. We support the rental company within the scope of our legal and contractual obligations.

    5. Categories of personal data

    Depending on the type of use, the following data in particular may be processed:

    5.1 Contact and master data

    • first and last name,
    • company name,
    • address,
    • email address,
    • phone number,
    • customer number,
    • contact person details.

    5.2 User account and authentication data

    • email address,
    • password hash,
    • email verification status,
    • user role,
    • permissions,
    • company or tenant assignment,
    • invitation and activation data,
    • session and security data,
    • password reset information.

    User accounts are generally created by invitation from a company. Open public self-registration is currently not provided.

    User accounts can additionally be protected by two-factor authentication.

    5.3 Company data

    • company name and legal form,
    • address,
    • email address and phone number,
    • website,
    • logo,
    • VAT identification number,
    • tax number,
    • bank details,
    • invoice settings,
    • company locations,
    • users and roles.

    5.4 Contract, booking and operational data

    • contract and booking numbers,
    • rental period,
    • booked items and quantities,
    • prices, discounts and taxes,
    • booking status and status history,
    • responsible employees,
    • internal notes,
    • delivery and collection information,
    • return information,
    • damage and condition information,
    • checklists,
    • handover and return protocols.

    5.5 Online payments (Stripe)

    If a rental company (tenant) has activated online payments, its customers can pay for bookings directly online. Payment processing is handled by Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland ("Stripe"). The payment process takes place on pages hosted by Stripe; payment data — in particular card and bank details — is collected directly by Stripe and at no point reaches Rentowa's servers. Rentowa transmits to Stripe the details required to process the payment (name, email address, booking reference, amount, currency) and receives the payment status back from Stripe.

    For the payment processing itself, Stripe is an independent controller under data protection law. This may involve transfers of personal data to Stripe, Inc. in the USA; such transfers are based on the adequacy decision for the EU-US Data Privacy Framework and, additionally, the EU Standard Contractual Clauses. For details, see stripe.com/privacy.

    The legal basis is Art. 6(1)(b) GDPR (performance of the rental or booking contract). The controller for the booking is the respective rental company; Rentowa acts as its processor.

    5.9 Booking widget on our tenants' websites

    Rental companies can embed the Rentowa booking widget into their own website. When visitors open such a website, their browser loads the widget together with article and availability data from Rentowa's servers; for technical reasons this involves processing of the IP address (server logs, deleted after 14 days, Art. 6(1)(f) GDPR — secure operation).

    Data that visitors enter into the widget (contact details, requested rental period, articles) is processed by Rentowa on behalf of the respective rental company; the controller under data protection law is the operator of the website in which the widget is embedded. Details are provided in that website's privacy policy; a corresponding notice is shown directly on the widget's form.

    5.10 Accounting integration (sevDesk)

    If a tenant activates the sevDesk integration, issued invoices are automatically mirrored into the tenant's sevDesk account. This transmits invoice data, including the invoice recipient's details (name, address, customer number, amounts), to sevdesk GmbH, Offenburg (Germany). The processing is carried out on the tenant's behalf and instructions for the purpose of the tenant's bookkeeping (Art. 6(1)(b) and (c) GDPR in conjunction with §§ 147 AO, 257 HGB). The integration is disabled by default; the tenant's API key is stored encrypted.

    5.11 Channel manager (Beds24)

    If a tenant activates the channel manager, Rentowa synchronises bookings and availability with booking portals (e.g. Airbnb, Booking.com) via Beds24 GmbH, Invalidenstraße 65, 10557 Berlin (Germany). Rentowa receives the guest data transmitted by the respective portal (name, email address, phone number, country, booking period, price) and creates it as a booking in the tenant's system; in the other direction, occupancy periods are transmitted to prevent double bookings.

    This guest data is not collected from the data subject directly (Art. 14 GDPR); guests are informed by the respective booking portal and by the tenant as controller. The integration is disabled by default; access tokens are stored encrypted.

    5.6 Content and file data

    • product and inventory images,
    • condition and damage photos,
    • contracts,
    • invoices,
    • handover and return protocols,
    • digital signatures,
    • other attachments and documents.

    5.7 Technical data

    • IP address,
    • browser type and version,
    • operating system,
    • device type,
    • app version,
    • date and time of access,
    • pages and features accessed,
    • server, security and error logs,
    • session identifiers,
    • technical diagnostic information.

    5.8 Categories of data subjects

    Processing may concern in particular:

    • website visitors,
    • prospects and demo requesters,
    • Rentowa contract customers,
    • administrators and users of Rentowa companies,
    • employees of rental companies,
    • customers and contacts of rental companies,
    • suppliers and business partners,
    • support requesters.

    Rentowa is a B2B offering aimed at businesses and professional users aged 18 and over. Deliberate processing of personal data of minors is not intended.

    6. Legal bases

    We process personal data in particular on the following legal bases:

    6.1 Consent — Art. 6(1)(a) GDPR

    This legal basis concerns in particular optional analytics features, optional cookies and other processing for which consent is expressly obtained.

    6.2 Contract performance and pre-contractual measures — Art. 6(1)(b) GDPR

    • demo and contract inquiries,
    • user accounts,
    • provision of the Rentowa platform,
    • administration of Rentowa contract customers,
    • support and contract-related communication.

    6.3 Legal obligations — Art. 6(1)(c) GDPR

    This legal basis concerns in particular commercial, tax, accounting and regulatory obligations.

    6.4 Legitimate interests — Art. 6(1)(f) GDPR

    Our legitimate interests are in particular:

    • secure and stable operation,
    • protection against abuse and unauthorised access,
    • error diagnosis,
    • IT security,
    • handling general inquiries,
    • internal organisation,
    • documentation of system and business processes,
    • establishment, exercise and defence of legal claims.

    Where we rely on legitimate interests, we take the rights and interests of data subjects into account through a balancing of interests.

    7. Provision of the marketing website

    The marketing website is provided via Lovable Cloud.

    According to our current configuration, the marketing website database is operated in the Ireland region, eu-west-1.

    When visiting the website, the following data in particular may be processed:

    • IP address,
    • browser and operating system,
    • requested page or file,
    • date and time,
    • referrer URL,
    • technical error and security information.

    Processing serves the secure, stable and error-free provision of the website. The legal basis is Art. 6(1)(f) GDPR.

    Service provider

    Lovable Labs AB, Sveavägen 17, 111 57 Stockholm, Sweden — service: Lovable Cloud. Purpose: hosting, database, backend and edge functions as well as integrated email delivery.

    The technical infrastructure of Lovable Cloud is based, among other things, on Supabase technologies. Where further sub-processors are used, their engagement and any data transfers are governed by the provider's contractual terms and current sub-processor list.

    8. Contact and demo form

    When you submit a contact form, we process in particular:

    • name,
    • email address,
    • subject,
    • message content,
    • time of the inquiry.

    The details are stored in the database table for contact inquiries. In addition, an edge function sends a notification to us and a confirmation to the sender.

    To operate the email infrastructure, technical delivery information is processed, including:

    • recipient,
    • template used,
    • delivery status,
    • error information,
    • unsubscribe and suppression information.

    Contact inquiries are generally stored for up to 24 months. Longer storage may occur if the inquiry leads to a contractual relationship or if statutory documentation and retention obligations apply.

    The legal basis is Art. 6(1)(b) GDPR for pre-contractual or contractual inquiries and Art. 6(1)(f) GDPR for other inquiries.

    Providing the information marked as mandatory is necessary in order to handle the inquiry. Further information is voluntary.

    9. Cookies, local storage and consent management

    9.1 Strictly necessary technologies

    We use cookies, local storage or comparable technologies insofar as they are necessary to provide functions you have expressly requested. These may include in particular:

    • login and session cookies,
    • security and CSRF cookies,
    • language settings,
    • consent decisions,
    • technically necessary user interface states.

    Section 25(2) TDDDG applies to strictly necessary access to terminal equipment information. Subsequent processing of personal data takes place, depending on the context, on the basis of Art. 6(1)(b) or (f) GDPR.

    9.2 Language setting

    The selected language may be stored in the browser's local storage under a technical key such as rentowa.lang. This serves to deliver the website in the language chosen by the user.

    9.3 Lovable Analytics and web performance measurement

    Lovable Analytics and the associated optional performance technologies are currently disabled. Before any future activation, consent will be obtained insofar as this is legally required.

    If activated in the future, performance values such as loading times, layout stability and responsiveness could be measured. The legal bases would then be Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

    Declining optional analytics features has no effect on the general use of the website.

    9.4 No advertising or remarketing technologies

    We currently do not use:

    • Google Analytics or Google Ads integration,
    • Meta Pixel,
    • Meta Conversion API,
    • LinkedIn Insight Tags,
    • custom audiences,
    • remarketing technologies,
    • cross-site advertising profiles.

    Should such services be introduced in the future, they will only be activated after a corresponding update of this privacy policy and, where required, after prior consent.

    10. Rentowa web application and Laravel Cloud

    The Rentowa application is provided via Laravel Cloud.

    For the application we use a PostgreSQL database in the EU Central region, Frankfurt.

    The service provider is Laravel Holdings Inc. — service: Laravel Cloud. Purpose: hosting the application, operating the PostgreSQL database, queues, scheduled processes and technical application infrastructure.

    Processing takes place to provide the application and to perform our contracts with Rentowa customers on the basis of Art. 6(1)(b) GDPR.

    Insofar as technical security, error and operational data are processed, processing is additionally based on Art. 6(1)(f) GDPR.

    11. User accounts and authentication

    User accounts are currently created exclusively by invitation from a company.

    Login is via email address and password. Email address confirmation is required before regular use.

    We process in particular:

    • name,
    • email address,
    • password hash,
    • user role,
    • permissions,
    • company assignment,
    • invitation status,
    • email verification status,
    • session and security information.

    Passwords are not stored in plain text but protected using the password hashing procedure provided by Laravel.

    A user can currently belong to only one company or tenant.

    The legal bases are Art. 6(1)(b) and (f) GDPR.

    12. Tenant separation and access permissions

    Rentowa is a multi-tenant application.

    A company's data is separated server-side from the data of other companies using a tenant identifier.

    Tenant users only receive access to data of their own company. The scope of access depends on the assigned role and respective permissions. Possible roles include in particular:

    • administrator,
    • office manager,
    • office staff,
    • warehouse,
    • accounting,
    • read only.

    Access by Rentowa

    Technical full access may be held by persons with authorised access to the Laravel Cloud organisation or the production environment.

    In addition, there is a platform role SUPER_ADMIN. It can access different tenants for support, administration or troubleshooting purposes.

    Entry as a super administrator is documented in the audit log of the affected tenant. During such access, a visible notice is displayed in the application.

    Access only takes place insofar as it is necessary for operation, support, maintenance, troubleshooting, security or the fulfilment of contractual obligations.

    The legal basis is Art. 6(1)(b) or (f) GDPR.

    13. Archiving of users and customer records

    User and customer records are generally archived first when removed. Archiving serves in particular to:

    • keep booking and contract histories traceable,
    • avoid damaging invoices and protocols,
    • comply with statutory retention obligations,
    • prevent inadmissible retroactive changes.

    Archived records remain stored until permissible deletion takes place or the data is no longer required.

    Archiving is not equivalent to complete deletion.

    14. Invoices, payments and accounting

    Rentowa enables the creation and management of invoices as well as the documentation of payments and deposits. The following may be processed:

    • invoice and customer data,
    • invoice line items,
    • amounts and taxes,
    • payment method,
    • payment status and payment date,
    • payment references,
    • bank details,
    • deposit information,
    • refunds,
    • DATEV export data.

    Processing takes place in particular to perform the contract and to comply with commercial and tax law obligations. The legal bases are Art. 6(1)(b) and (c) GDPR.

    Where online payment is activated, payments are processed via Stripe (see section 5.5); complete card and bank details are never stored in Rentowa.

    15. Email communication via Brevo

    For transactional emails from the Rentowa application we use Brevo. These include in particular:

    • account invitations,
    • email verifications,
    • password reset messages,
    • booking confirmations,
    • return reminders,
    • payment reminders,
    • invoices,
    • support replies,
    • security notifications.

    The following data in particular is transmitted to the email service provider:

    • recipient address,
    • name,
    • subject,
    • message content,
    • technical delivery information.

    Processing takes place on the basis of Art. 6(1)(b) or (f) GDPR.

    Service provider: Brevo SAS (formerly Sendinblue), 106 boulevard Haussmann, 75008 Paris, France. Purpose: sending and technical delivery of transactional emails.

    No marketing newsletters are currently sent.

    16. File storage, images and documents

    For private file and image storage, Rentowa uses Cloudflare R2 Object Storage.

    The bucket used is configured with Cloudflare's EU jurisdiction. The objects stored in the bucket are subject to Cloudflare's EU jurisdiction. This ensures that the objects are stored within the European Union. Cloudflare does not state a single city or classic AWS region for R2; the technical region value for the S3-compatible interface is “auto”.

    In the production environment, the following content in particular is processed via private R2 storage:

    • product and inventory images,
    • condition and damage photos,
    • photos taken at handover and return,
    • contracts,
    • invoices,
    • handover and return protocols,
    • other attachments and documents.

    Private files are not made available via freely accessible public storage addresses. Access generally takes place via protected or time-limited, signed URLs.

    Depending on the feature, certain image or content data may additionally be stored technically within the database, for example in encoded form.

    Insofar as this content contains data of a rental company or its customers, Alwin Gilles e.K. generally processes the data as a processor under Art. 28 GDPR and on the documented instructions of the respective rental company.

    Service provider used

    Cloudflare, Inc., 101 Townsend Street, San Francisco, California 94107, USA.

    Service: Cloudflare R2 Object Storage. Purpose: private storage and delivery of files, images and documents. Storage jurisdiction: European Union.

    Cloudflare is a US-based service provider. Insofar as processing or access outside the EU/EEA cannot be excluded in the course of service provision, safeguards are provided in accordance with the Data Processing Addendum applicable with Cloudflare and the transfer mechanisms set out therein, in particular EU Standard Contractual Clauses.

    17. Digital signatures

    Rentowa enables rental companies to capture a rental customer's signature on an employee's device. The following may be stored:

    • the image of the signature,
    • the entered name of the signing person,
    • the assignment to the handover or contract process,
    • date and time,
    • the processing user.

    The signature serves to document handovers, returns and contractual processes.

    Rentowa does not use the signature for automated biometric identification of a person.

    The respective rental company is responsible for the lawfulness of the collection and for informing the rental customer. Alwin Gilles e.K. generally processes the data as a processor.

    18. Camera and QR/barcode scanner

    The iOS app can access the camera when the user selects a corresponding function. The camera is used in particular for:

    • QR and barcode scanning,
    • inventory and product images,
    • condition photos,
    • damage photos,
    • photos at handover and return.

    Camera access only takes place after the corresponding device permission has been granted.

    Camera permission can be revoked at any time in the iOS system settings. Functions that strictly require the camera may then no longer be available.

    The camera is currently not used for scanning identity cards, passports or driving licences.

    19. Face ID

    The iOS app can use Face ID to protect local access to the app.

    The biometric check is performed by the device's operating system. Rentowa does not receive any facial data and does not store any biometric Face ID characteristics on its servers.

    Rentowa only receives technical feedback on whether local authentication was successful.

    The use of Face ID is voluntary and can be deactivated via the device settings.

    20. No device GPS tracking

    Rentowa currently does not use GPS tracking of employees, customers or rental items. In particular, the following are not processed automatically:

    • current device locations,
    • movement profiles of employees,
    • GPS positions of rental items,
    • persistent location histories.

    Users can enter delivery and collection addresses manually. Technical coordinates for distance or route calculation may be derived from these addresses.

    21. Map, geocoding and routing services

    For map, address and distance functions, Rentowa currently uses services from the OpenStreetMap ecosystem.

    21.1 Map tiles

    When a map view is opened, map tiles are currently loaded directly from tile.openstreetmap.org. In doing so, the IP address of the device used is technically transmitted to the map server.

    The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in displaying delivery areas, locations and distances within the application. Before use, we assess whether overriding interests of the data subjects apply.

    21.2 Nominatim

    The Nominatim service may be used to convert a manually entered delivery address into geographic coordinates. The entered address is transmitted server-side to the service.

    21.3 OSRM

    For route or distance calculation, coordinates derived from an address may be transmitted to the OSRM service at router.project-osrm.org.

    21.4 Responsibility

    The services mentioned are used technically in connection with providing Rentowa features.

    Insofar as data of a tenant or its customers is processed, this generally takes place within the scope of processing on behalf.

    The use of public community endpoints is reviewed regularly. We reserve the right to switch to self-hosted services or contractually bound providers.

    We are currently assessing whether the map, geocoding and routing services will in future be self-hosted or replaced by contractually bound providers.

    22. Server, application and access logs

    22.1 Application logs

    The Rentowa application keeps technical application logs in order to detect errors, secure operations and investigate security incidents.

    The regular retention period of these Laravel application logs is generally 14 days.

    22.2 Platform and HTTP logs

    Laravel Cloud and other infrastructure operators may additionally keep technical access logs. These may contain IP addresses, timestamps, requested resources and technical connection information.

    The respective retention period depends on the technical configuration and the terms of the infrastructure operator. The legal basis is Art. 6(1)(f) GDPR.

    23. Audit logs

    Rentowa maintains an immutable audit log of significant user and system actions. The following may be logged:

    • logins,
    • creation and modification of customer data,
    • booking changes,
    • invoice changes,
    • archiving and deletion operations,
    • exports,
    • role and permission changes,
    • super administrator access.

    An audit entry may contain in particular:

    • tenant,
    • user identifier,
    • name of the acting user,
    • affected record or entity,
    • type of action,
    • changed values,
    • time of the action.

    According to the current application configuration, the audit log does not contain a separately stored IP address or device identifier.

    Audit data is stored for the duration of the contractual relationship and beyond, insofar as this is necessary to comply with statutory documentation and retention obligations, to preserve the integrity of booking and invoice data or to defend legal claims.

    Audit entries are retained for different periods depending on their content and purpose. Technical and security-related entries are deleted as soon as they are no longer required for security, evidence or legal defence. Entries forming part of commercial, tax or accounting records may be stored for the applicable statutory retention period.

    24. Backups

    Backups are created regularly to ensure availability and recoverability. The backup cycle configured on the application side currently provides for:

    • full retention of all backups for 7 days,
    • daily backups for a further 16 days,
    • weekly backups for 8 weeks,
    • monthly backups for 4 months,
    • yearly backups for 2 years.

    Backups are created daily in the production environment and pruned according to the configured schedule. Application-side backup storage is capped at a total of 5 GB. Depending on the storage volume reached, older backups may be removed earlier by the automatic cleanup than the maximum periods stated above.

    Laravel Cloud may additionally perform its own database or infrastructure backups. Separate retention periods may apply to these.

    Deleted data may still be contained in backup copies until the end of the respective backup cycle. It is not used there for regular operational purposes and is removed as part of scheduled overwriting.

    25. End of contract and deletion of tenant data

    The deletion and return of tenant data after the end of the contract is governed by the respective contract and data processing agreement. An export period of 60 days is generally envisaged. The concrete implementation and the start of the period are communicated to the company concerned upon contract termination.

    After the period communicated in each case, operational tenant data is deleted or anonymised, provided that:

    • no statutory retention obligation exists,
    • the data is not required to defend legal claims,
    • no other permissible further processing is necessary.

    Invoice, booking and business records subject to statutory retention may continue to be stored separately with restricted access.

    Data may still be contained in backup copies until the end of the applicable backup cycle.

    Deviating arrangements may be agreed contractually in individual cases.

    26. Account deletion

    Data subjects can request deletion of their user account at any time by email to contact@rentowa.com. A separate self-service function in the application is currently not available.

    The request is reviewed and processed manually. The requester receives an acknowledgement of receipt.

    The request is generally processed without undue delay, at the latest within one month of receipt.

    In the case of a justified account deletion, the personal data assigned to the user account is deleted or anonymised, unless legal or contractual reasons require further storage.

    Deleting a user account does not automatically result in the deletion of:

    • the entire company tenant,
    • the rental company's data,
    • invoices and tax-relevant documents,
    • booking and contract histories,
    • data processed by the rental company as controller,
    • data required to defend legal claims.

    If the user is the only administrator of their company, another administrator must be designated before deletion, or the further procedure must be clarified with Rentowa.

    Deletion of a complete company tenant can only be carried out by a Rentowa super administrator in the context of contract termination.

    27. Transactional emails and no newsletters

    Rentowa currently sends only transactional and service messages. These include in particular:

    • invitations,
    • account confirmations,
    • password reset messages,
    • booking information,
    • reminders,
    • invoices,
    • support messages,
    • security information.

    No marketing newsletters are currently sent.

    Should newsletters be introduced in the future, this will only take place on an appropriate legal basis and, where applicable, after prior consent and double opt-in.

    28. Online meetings and product demonstrations

    For product demonstrations, consultations and online meetings we use Microsoft Teams and Zoom. The following may be processed:

    • name,
    • email address,
    • dial-in data,
    • IP address,
    • device and connection information,
    • time and duration of participation,
    • voluntarily transmitted audio and video data,
    • chat messages,
    • shared screen content and files.

    Meetings are currently not recorded, automatically transcribed or summarised by AI on our part.

    Processing takes place to conduct pre-contractual or contractual communication under Art. 6(1)(b) GDPR and on the basis of our legitimate interest in efficient communication under Art. 6(1)(f) GDPR.

    The providers used are in particular Microsoft Teams, provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, and Zoom, provided by Zoom Communications, Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA, or by Zoom Voice Communications B.V. for users in the European Economic Area.

    The providers may process personal data in accordance with their own privacy policies and, where applicable, outside the EU/EEA.

    29. Social media presences

    Rentowa currently maintains official profiles on LinkedIn and Instagram.

    On rentowa.com only ordinary links to these profiles are used. Social media feeds, plugins or tracking pixels are not embedded.

    When visiting a social media profile, the respective platform operator processes personal data in accordance with its own privacy policy. The following may be processed:

    • IP address,
    • device and browser information,
    • profile information,
    • interactions,
    • messages,
    • page and post views,
    • analytics and advertising data.

    We may receive aggregated statistics on reach and interactions from the platform operators.

    Data subject rights regarding processing carried out by the respective platform can usually be exercised most effectively directly with the platform operator.

    30. No AI-based decisions

    Rentowa currently does not use any active AI features to which customer, booking or document data is transmitted.

    Personal data is currently not transmitted to providers of generative AI systems.

    Rentowa currently does not perform any automated:

    • approval or rejection of customers,
    • credit or risk assessment,
    • customer classification,
    • booking decision,
    • legally significant assessment.

    Automated decision-making within the meaning of Art. 22 GDPR does not currently take place.

    Before introducing such features, this privacy policy will be updated and the data protection permissibility will be assessed.

    31. Special categories of personal data

    Rentowa is not designed for the targeted processing of special categories of personal data under Art. 9 GDPR. These include in particular:

    • health data,
    • information on religion or belief,
    • political opinions,
    • trade union membership,
    • genetic or biometric identification data,
    • information on sex life or sexual orientation.

    Users should not enter such information into free-text fields or notes without legal necessity.

    There are currently no dedicated data fields for identity card, driving licence or passport data and no function for uploading copies of such documents.

    Technically, however, such information can be entered in free note fields. The respective rental company is responsible for using free-text fields only for necessary and lawfully processed information.

    32. Recipients and service providers

    Personal data may be transmitted in particular to the following categories of recipients:

    • hosting and cloud providers,
    • database and storage providers,
    • email service providers,
    • communication and video conferencing providers,
    • map, geocoding and routing services,
    • tax advisors, legal advisors or authorities, where necessary,
    • further processors and sub-processors.

    The services currently used include in particular:

    • Lovable Cloud for the marketing website, its database and edge functions,
    • Laravel Cloud for operating the Rentowa application and the PostgreSQL database,
    • Cloudflare for DNS, proxy, CDN and security functions,
    • Cloudflare R2 for private file and image storage with EU jurisdiction,
    • Brevo for transactional emails,
    • Apple for provision of the iOS app and device-side diagnostic services,
    • Microsoft Teams and Zoom for online meetings,
    • OpenStreetMap map servers, Nominatim and OSRM for map, address and route functions,
    • Stripe Payments Europe, Ltd. (Dublin, Ireland) — online payment processing, only where online payment is activated; US transfers based on the EU-US Data Privacy Framework and the Standard Contractual Clauses,
    • sevdesk GmbH (Offenburg, Germany) — mirroring of invoices into the tenant's accounting, only where the integration is activated,
    • Beds24 GmbH (Berlin, Germany) — synchronisation with booking portals, only where the channel manager is activated.

    Insofar as a provider processes personal data as a processor, the legally required data processing agreement is concluded.

    For the processing of tenant data, a current sub-processor list is maintained as part of or an annex to the respective data processing agreement.

    33. Cloudflare

    We use Cloudflare services for several technical purposes.

    33.1 DNS, proxy, CDN and security functions

    Cloudflare is used for:

    • domain name system,
    • proxy and content delivery functions,
    • protection against attacks and abusive access,
    • improving availability and loading speed.

    The following may be processed:

    • IP address,
    • technical connection data,
    • requested domain and resource,
    • browser and device information,
    • security and attack information,
    • date and time of access.

    Processing serves our legitimate interest in secure, fast and resilient provision of our services pursuant to Art. 6(1)(f) GDPR.

    33.2 Cloudflare R2 Object Storage

    Cloudflare R2 is used for the private storage of files, images and documents.

    The objects stored in the bucket are subject to Cloudflare's EU jurisdiction. This ensures that the objects are stored within the European Union. Access generally takes place via private and time-limited, signed URLs.

    33.3 Provider and international transfers

    The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, California 94107, USA.

    Cloudflare processes personal data in accordance with the applicable contract and Data Processing Addendum.

    Insofar as a transfer or access outside the European Union or the European Economic Area takes place, such processing is based in particular on appropriate safeguards such as EU Standard Contractual Clauses.

    34. Apple and diagnostic data

    The iOS app may collect technical crash and diagnostic data via the operating system and App Store functions provided by Apple.

    Whether and to what extent Apple transmits such data depends in particular on the privacy and diagnostics settings of the device.

    Rentowa currently does not use an additional crash reporting SDK such as Sentry or Firebase Crashlytics and no separate mobile analytics SDK.

    Further processing by Apple takes place in accordance with Apple's privacy policy.

    35. Transfers to third countries

    Some of our service providers are based, or operate technical infrastructure, outside the European Union or the European Economic Area.

    A transfer to a third country only takes place where a permissible basis exists, in particular:

    • an adequacy decision under Art. 45 GDPR,
    • a valid certification under the EU-US Data Privacy Framework,
    • EU Standard Contractual Clauses under Art. 46 GDPR,
    • other appropriate safeguards,
    • a statutory derogation under Art. 49 GDPR.

    Even if a primary database region within the EU has been selected, support, security, telemetry or sub-processing activities may take place in other countries.

    36. Retention periods

    Unless a more specific retention period is stated, we store personal data only for as long as it is:

    • necessary for the respective purpose,
    • required to fulfil our contractual obligations,
    • prescribed by legal obligations,
    • necessary to defend or enforce legal claims.

    In particular, the following principles currently apply:

    • contact inquiries: generally up to 24 months,
    • Laravel application logs: generally 14 days,
    • user accounts: until permissible deletion or archiving,
    • operational tenant data: as governed by the respective contract; an export period of 60 days after end of contract is envisaged,
    • backups: according to the backup cycle described in section 24,
    • invoice and booking records: according to the applicable commercial and tax retention periods,
    • audit logs: depending on content and purpose; entries forming part of commercial, tax or accounting records for the applicable statutory retention period.

    After the respective period has expired, data is deleted, anonymised or its processing is restricted.

    37. Technical and organisational security measures

    Taking into account the state of the art, implementation costs, the nature and scope of processing and the risks to data subjects, we take appropriate technical and organisational measures. These include in particular:

    • HTTPS encryption,
    • password hashing,
    • role-based permissions,
    • server-side tenant separation,
    • private file storage,
    • time-limited access links,
    • audit logging,
    • backups,
    • access restrictions,
    • security and error logging,
    • documented super administrator access.

    Despite appropriate protective measures, no technical system can guarantee complete security.

    38. Mandatory information

    Certain information is required in order to:

    • initiate or conclude a contract,
    • set up a user account,
    • provide the platform,
    • handle a contact inquiry,
    • manage invoices and business processes.

    Mandatory fields are marked as such.

    Without the required information, the respective function or service may not be able to be provided. Further information is voluntary.

    39. Rights of data subjects

    Subject to the statutory requirements, data subjects have in particular the following rights:

    39.1 Access

    You can request information as to whether and which personal data concerning you is processed.

    39.2 Rectification

    You can request the rectification of inaccurate data and the completion of incomplete data.

    39.3 Erasure

    You can request the erasure of your data, provided that no legal or other permissible grounds for further storage exist.

    39.4 Restriction of processing

    Under the statutory conditions you can request a restriction of processing.

    39.5 Data portability

    Where the statutory requirements are met, you can receive data in a structured, commonly used and machine-readable format.

    39.6 Objection

    Under the conditions of Art. 21 GDPR you can object to processing based on Art. 6(1)(e) or (f) GDPR.

    39.7 Withdrawal of consent

    Consent given can be withdrawn at any time with effect for the future. The lawfulness of processing carried out until withdrawal remains unaffected.

    39.8 Contact

    Requests can be directed to contact@rentowa.com.

    To prevent unauthorised disclosure of data, we may request appropriate proof of identity.

    If data was stored in Rentowa by a rental company acting as controller, the request may be forwarded to that rental company.

    40. Your right to object (Art. 21 GDPR)

    Insofar as we process personal data on the basis of Art. 6(1)(e) or (f) GDPR, you have the right, on grounds relating to your particular situation, to object at any time to that processing. Following an objection we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

    Where personal data is processed for direct marketing, you may object to that processing at any time without giving reasons.

    Objections can be directed to contact@rentowa.com.

    41. Right to lodge a complaint

    You have the right to lodge a complaint with a data protection supervisory authority. The following authority is in particular competent for the controller:

    Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

    You may also contact another competent supervisory authority, in particular at your habitual residence, place of work or the place of the alleged infringement.

    42. Objection to unsolicited advertising

    The use of contact data published in the imprint or in this privacy policy to send advertising and information material that has not been expressly requested is hereby objected to.

    We reserve the right to take legal action in the event of unsolicited advertising, in particular spam emails.

    43. Changes to this privacy policy

    We update this privacy policy when features, service providers, technical systems, processing purposes or legal requirements change.

    The current version is available at https://rentowa.com/datenschutz.

    Material changes requiring renewed consent or individual notification will be communicated in an appropriate form.

    44. Language versions

    This privacy policy may additionally be provided in English.

    The English version serves to improve comprehension for international users.

    In the event of discrepancies or differences in interpretation, the German version prevails.