Privacy statement for the customer portal, partner and team area
As of 7 October 2026
Translation - not reviewed. Only the German version is legally binding. Deutsche Fassung
1.Controller
Ömer Hüseyin Coskun, Leienbergstr. 1, 53783 Eitorf
Email: mail@oemer-coskun.de
I have not appointed a data protection officer because there is no obligation to do so.
2.Scope of this statement
This privacy statement applies to the customer portal, the partner area and the team area. The website has its own privacy statement.
3.Customer portal: which data
In the customer portal I process your name and the contact address from the order, your billing details (address, purchase order number, cost centre, billing email), the reports on the days worked with the hours billed, quotes, invoices, contracts and documents, as well as your messages, approvals, requests, uploaded files and answers in the questionnaire at the start of the order.
4.Purpose and legal basis
The processing serves to carry out the order and to invoice it (Art. 6(1)(b) GDPR) and to fulfil statutory retention obligations (Art. 6(1)(c) GDPR).
5.Partner area
The partner area is used by recruiters with a partnership agreement. There I process the details of the partnership (company, contact person, address, billing details, agreement, day rate, monthly target), the project requests you submitted, which I assign to you by your email address, and the placed orders with timesheets, commissions, customer protection list and documents.
The legal basis is the partnership agreement (Art. 6(1)(b) GDPR), and Art. 6(1)(c) GDPR for keeping vouchers and business letters.
6.Team area
The team area is used by self-employed team members whom I engage as subcontractors. I process name, email address, the details for their own invoice (company name, address, tax number, VAT ID, VAT status), the expiry date of the professional liability insurance with the day I saw the proof (without a copy), details on self-employment (other clients, status determination), the working days recorded, monthly statements and contracts.
Customers see the name of the team member working on their order. The legal basis is the contract with the team member (Art. 6(1)(b) GDPR), Art. 6(1)(c) GDPR for retention and Art. 6(1)(f) GDPR for the proofs of insurance and self-employment.
8.Payment of subscriptions
For subscriptions you can store a SEPA direct debit or a card in the customer portal and the partner area. The payment data is collected by Stripe (Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Dublin 2, Ireland); I only store a shortened form of it (last four digits, brand, expiry date, country of the bank). For the direct debit mandate I keep its wording, the time, the shortened IP address and the browser details as proof.
The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(f) GDPR for the proof of the mandate. Stripe may transfer data to the USA; Stripe, Inc. is certified under the EU-US Data Privacy Framework (Art. 45 GDPR).
9.Emails
You receive the report on the days worked at the frequency you choose in the portal, as well as sign-in links, invoices, contracts, statements and notices about the order.
I send emails via Brevo (Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France) as a processor. Brevo receives your email address and the content of the email. A tracking pixel that reports the opening of an email is switched off.
Incoming emails are received by my own mail server, which runs on my server in Germany (hosting as above). No other provider receives them.
10.Delivery, hosting and backup
All requests pass through the network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare protects the server against attacks and forwards the requests; in doing so, Cloudflare processes the connection data (IP address, requested address, browser details) as a processor. The legal basis is Art. 6(1)(f) GDPR (secure and reliable operation).
Data may be transferred to the USA in the process. Cloudflare is certified under the EU-US Data Privacy Framework; the transfer is based on the adequacy decision of the EU Commission of 10 July 2023 (Art. 45 GDPR).
I rent the server on which this service and its data are stored from one.com. It is located in a data centre of dogado GmbH in Dortmund, Germany. The provider processes the data as a processor pursuant to Art. 28 GDPR.
Backup with a storage provider outside the server: missing: operator.
11.Notifications to me
For notifications to myself I use the messaging service Telegram (Telegram FZ-LLC, Dubai, United Arab Emirates). There is no data processing agreement with Telegram, and the messages are also stored outside the EU. The legal basis is Art. 6(1)(f) GDPR (quick handling). Basis of the transfer to a third country: missing: operator.
I am notified there of new messages, requests, change requests, uploaded files, approvals, erasure requests and recorded working days. These notifications may contain your name, your company, your email address, the name of the order, amounts, file names and the text of your message or request.
12.Storage period
I keep invoices and other accounting vouchers for 8 years, contracts, quotes and correspondence as business letters for 6 years, each from the end of the calendar year (Section 147 AO, Section 14b UStG, Section 257 HGB). I keep approvals and decisions in the portal until the end of the regular limitation period, 3 years from the end of the calendar year (Sections 195, 199 BGB).
I delete the other data as soon as it is no longer required for the order, the partnership or the cooperation and for statutory obligations. In the customer portal, 'Your data' shows how long each kind of data is kept.
13.Your rights
You have the right of access to your data (Art. 15 GDPR), to rectification (Art. 16 GDPR), to erasure (Art. 17 GDPR), to restriction of processing (Art. 18 GDPR) and to data portability (Art. 20 GDPR). An informal email to mail@oemer-coskun.de is sufficient.
You can withdraw a consent at any time with effect for the future (Art. 7(3) GDPR). Processing carried out before the withdrawal remains lawful.
14.Right to object
Where I process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation (Art. 21(1) GDPR). I will then no longer process the data unless I can demonstrate compelling legitimate grounds which override your interests, or the processing serves the establishment, exercise or defence of legal claims.
15.Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for me is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen), Kavalleriestraße 2-4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.