Privacy Policy
This privacy policy describes the processing of personal data when using the Clever Dialer websites of Sellwerk GmbH & Co. KG. It applies to the websites cleverdialer.de, cleverdialer.at, cleverdialer.ch, cleverdialer.co.uk, cleverdialer.es and cleverdialer.com (hereinafter jointly "our websites" or individually "our website"). It also explains the choices you have regarding your personal data ("Your rights") and how you can contact us.
Note on the language version: This document is a translation of the German original. The German version is authoritative; in the event of any discrepancy or ambiguity in the translation, the German wording shall be used for interpretation. This does not affect your statutory rights. The German version is available at www.cleverdialer.de/datenschutzerklaerung-website.
I. Who is the controller and how can I contact the Data Protection Officer?
The controller within the meaning of the GDPR is
Sellwerk GmbH & Co. KG
Pretzfelder Straße 7-11
90425 Nuremberg
Email: support@cleverdialer.de
Commercial Register Nuremberg HRA 16002
Managing Directors: Dipl. Kff. Constanze Oschmann, Dipl. Kfm. Michael Oschmann
For questions regarding the processing of your personal data by us or on the subject of data protection in general, please contact our Data Protection Officer, Dr Stefan Drewes, whom you can reach at the address stated in the Legal Notice or at the following email address: privacy@cleverdialer.com
II. Your rights as a data subject
Every data subject has the following rights:
Right of access (Art. 15 GDPR)
Right to rectification of inaccurate data (Art. 16 GDPR)
Right to erasure, or a right to be "forgotten" (Art. 17 GDPR)
Right to restriction of the processing of personal data (Art. 18 GDPR)
Right to data portability (Art. 20 GDPR)
You may object at any time, without giving reasons, to the processing of personal data for advertising purposes, including an analysis of customer data for advertising purposes.
In addition, the data subject also has a general right to object (cf. Art. 21(1) GDPR). In that case, the objection to a data processing operation must be substantiated. Where the data processing is carried out on the basis of consent, your consent may be withdrawn at any time with effect for the future.
To exercise your data subject rights, the easiest way is to contact support@cleverdialer.de or the address stated in the Legal Notice. In addition, you have the right to lodge a complaint with the data protection supervisory authority responsible for you.
III. On the processing of personal data by Sellwerk GmbH & Co. KG
In the following, we would like to give you an overview of how we safeguard the protection of your personal data when you access our website and which types of personal data we process, for which purposes and to what extent.
1. Processing of personal data – ratings and comments
Our website enables users to submit ratings and comments on individual phone numbers. When a rating or comment is submitted, the following data is collected and stored:
- Star rating
- Comment text
- Email address (mandatory)
- IP address
Purpose of the processing: The rating function is the core function of our website and serves to inform other users about the identity and behaviour of callers. In addition, the comment function can be used to leave comments on phone numbers. The email address is collected as a mandatory field in order to prevent misuse of the comment function and to enable contact to be made in the event of legally relevant complaints. The IP address is stored to prevent misuse and attacks.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in providing a reliable, misuse-free information platform for identifying phone numbers.
Retention period: The IP address is deleted after 90 days. Ratings, comments and the associated email address are stored for as long as the respective phone number entry is provided.
2. Processing of data when accessing our website – log files
When our website is accessed, information of a general nature is automatically recorded. This information (server log files) includes, for example, the type of web browser, the operating system used, the domain name of your internet service provider and similar. In addition, the IP address is transmitted and used to provide the service you have requested. This information is technically necessary in order to deliver the content you have requested correctly, and is unavoidably generated when you use our website.
In accordance with our IT security concept, the resulting log file data is stored for a period of 90 days in order to detect and analyse any attacks against our website.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in ensuring the security and stability of our website.
3. Processing of data when using the website – your enquiries
If you send us an enquiry by email or via the contact form, we collect the data you provide in order to process and respond to your request. We store this information for evidentiary purposes for a period of up to three years.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
4. Hosting and infrastructure
This website is operated within the Google Cloud Platform. The provider is:
Google Cloud EMEA Limited
70 Sir John Rogerson's Quay, Dublin 2, Ireland
or the contractually responsible company:
Google LLC
1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
(hereinafter "Google")
Data processed: Each time our website is accessed, the following data is automatically processed by the web server:
- IP address of the requesting device
- Date and time of access
- Address of the page accessed (URL)
- Volume of data transferred
- Browser type and version
- Operating system
- Referrer URL (previously visited page)
This data is technically necessary in order to deliver the website and is stored in server log files.
Processing on our behalf: We have concluded a Cloud Data Processing Addendum with Google pursuant to Art. 28 GDPR. Google processes customer data exclusively in accordance with our documented instructions and not for its own purposes. Google uses sub-processors; a current list can be viewed at https://cloud.google.com/terms/subprocessors.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in the secure, stable and efficient provision of our website.
Storage location and data processing: We use the Google Cloud Platform with the Europe storage region (region europe-west3, Frankfurt, Germany). The primary data storage takes place in data centres in the European Union. Information on the locations of the Google Cloud Platform data centres can be found at: https://cloud.google.com/about/locations/
A complete restriction of all data processing to the EU cannot be guaranteed due to Google's global infrastructure (e.g. in the case of support and maintenance services). For this case, the safeguards for third-country transfers described below are in place.
Third-country transfer: Insofar as personal data is transferred to the USA, or where access from the USA to data stored in the EU cannot be entirely ruled out (e.g. in the course of support services or technical administration), the following safeguards are in place:
- EU-U.S. Data Privacy Framework (DPF): Google LLC is certified under the European Commission's adequacy decision of 10 July 2023 pursuant to Art. 45 GDPR in accordance with the EU-U.S. Data Privacy Framework.
- Standard contractual clauses (SCCs): In addition, the EU standard contractual clauses pursuant to Commission Implementing Decision (EU) 2021/914 have been agreed. These take effect as a fallback mechanism in the event that the DPF should cease to be valid.
Further information on data protection at Google Cloud can be found at: https://cloud.google.com/privacy/
5. Crash reporting and error monitoring – Sentry
We use the Sentry service for real-time error detection, crash reporting and application monitoring of our website. The provider is:
Functional Software, Inc. d/b/a Sentry
45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA
(hereinafter "Sentry")
Purpose of the processing: Sentry serves to detect, analyse and remedy technical errors and malfunctions in our website. By monitoring the application behaviour, we can ensure and continuously improve the stability, security and functionality of our offering.
Nature of the use: On our website, Sentry is used exclusively server-side. No Sentry SDK is loaded in the user's browser. There is therefore no direct connection between the website visitor's device and the Sentry servers.
Data processed: Due to the exclusively server-side use and the configuration send_default_pii = false, the transmission of personal data to Sentry is excluded as a matter of design. In particular, no IP addresses, user-agent strings, cookies or other device identifiers of website visitors are transmitted to Sentry.
Within the scope of server-side error monitoring, the following is transmitted to Sentry:
- Error messages and stack traces of the server application
- Time of the error
- Technical context data of the server environment (e.g. software version, module configuration)
- The URL accessed or the API endpoint affected at which the error occurred
It cannot be entirely ruled out that, in exceptional cases, individual error messages or stack traces may contain personal data (e.g. where user input such as an email address or phone number becomes part of an error message). Sentry uses automated PII scrubbing mechanisms in order to detect such data in error messages and remove it before transmission and storage.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in ensuring the technically sound operation of our website as well as the timely detection and remedying of errors.
Processing on our behalf: We have concluded a Data Processing Addendum (DPA) with Sentry pursuant to Art. 28 GDPR. Sentry uses sub-processors; a current list can be viewed at https://sentry.io/legal/subprocessors/.
Storage location: For our Sentry organisation, we have selected the "European Union" data storage region. The content data recorded in the course of crash reporting — in particular error events, transaction data, profiling data, session replays and release data — is stored exclusively in Frankfurt, Germany (data at rest).
Certain account and organisation data required for the operation of the Sentry service (in particular user accounts, organisation and project settings, integration metadata, access tokens as well as SSO/SAML metadata) is stored by Sentry in the USA. This data primarily concerns our own employees as Sentry users and does not, as a rule, contain personal data of visitors to our website.
Third-country transfer: Insofar as personal data is stored in the USA, or where access from the USA to data stored in the EU cannot be entirely ruled out (e.g. in the course of support services or technical administration), the following safeguards are in place:
EU-U.S. Data Privacy Framework (DPF): Sentry is certified under the European Commission's adequacy decision of 10 July 2023 pursuant to Art. 45 GDPR in accordance with the EU-U.S. Data Privacy Framework and has undertaken to comply with the level of protection required by the Data Privacy Framework Principles.
Standard contractual clauses (SCCs): In addition, the EU standard contractual clauses pursuant to Commission Implementing Decision (EU) 2021/914 have been agreed (Module 2: controller to processor). These take effect as a fallback mechanism in the event that the DPF should cease to be valid. The applicable law and place of jurisdiction for the SCCs is the Republic of Ireland.
Technical and organisational measures: Sentry maintains extensive technical and organisational security measures, which are documented in the Sentry Security Policy at https://sentry.io/security/.
Retention period: The personal data recorded in the course of crash reporting and error monitoring is stored by Sentry for varying periods depending on the type of data, but for a maximum of 90 days in the case of errors.
Further information on data protection at Sentry can be found at: https://sentry.io/privacy/
Information on security can be found at: https://sentry.io/security/
6. Web analytics – Fathom Analytics
We use the web analytics service Fathom Analytics on our website. The provider is:
Conva Ventures Inc.
BOX 53057, 10-3480 Shelbourne St, Victoria, BC V8P 5N8, Canada
(hereinafter "Fathom")
Purpose of the processing: Fathom Analytics serves the statistical evaluation of the use of our website. The insights obtained help us to improve our offering and tailor it to actual needs.
Data processed: Fathom Analytics processes exclusively the IP address and the user agent (browser identifier) of website visitors. Fathom does not set any cookies and does not carry out any tracking of individual visitors. The IP address of visitors from the European Economic Area is anonymised on EU servers by means of an irreversible hashing procedure (SHA256 with salt) before it reaches Fathom's US-controlled infrastructure. Only aggregated, anonymous usage statistics are produced; conclusions about individual visitors cannot be drawn.
Legal basis: Art. 6(1)(a) GDPR (consent). Fathom Analytics is only loaded on our website after you have given your consent via our consent management platform (OneTrust). Without your consent, no data is transmitted to Fathom.
Withdrawal of consent: You can withdraw your consent at any time with effect for the future by adjusting your cookie settings via our consent management platform (OneTrust). You will find the link to the cookie settings in the footer of our website. The withdrawal does not affect the lawfulness of the processing carried out up to that point.
Storage location and EU isolation: The processing of the IP addresses of visitors from the European Economic Area takes place on EU servers operated by the sub-processor BunnyWay d.o.o. (Slovenia). The anonymisation takes place entirely on these EU servers. Personal data of EU visitors is not transmitted to servers outside the EU.
Retention period: Fathom stores personal data (IP address and user agent) for a maximum of 24 hours. After this period, the data is deleted automatically. Only anonymised, aggregated statistics remain.
Processing on our behalf: We have concluded a Data Processing Agreement with Fathom pursuant to Art. 28 GDPR.
Third-country transfer: Fathom is based in Canada. An adequacy decision by the European Commission pursuant to Art. 45 GDPR exists for Canada in respect of processing carried out in the course of commercial activities. Due to Fathom's EU isolation, however, personal data of visitors from the European Economic Area is processed and anonymised exclusively on EU servers, so that no transfer of identifiable personal data to third countries takes place.
Further information on data protection and data processing at Fathom can be found at: https://usefathom.com/data
7. Consent management – OneTrust
7.1 Consent management platform
Our website uses OneTrust as its consent management platform. The provider is:
OneTrust LLC
1200 Abernathy Rd NE, Suite 300, Atlanta, GA 30328, USA
(hereinafter "OneTrust")
Purpose of the processing: OneTrust serves to obtain and manage your consent for the use of cookies and comparable technologies on our website. The tool enables you to decide, on your first visit to our website, which cookies and services may be activated, and to change this decision at any time thereafter.
Data processed: When you visit our website, OneTrust stores the following data in a cookie on your device:
- Your consent decisions (which cookie categories and services you have permitted or refused)
- Time at which consent was given
- A unique consent ID for documenting your consent
- The version of the cookie settings valid at the time consent was given
- Your decisions made under the IAB Transparency and Consent Framework (TCF) in the form of a standardised string value (TC string)
In addition, your consent decisions are logged server-side in order to be able to demonstrate consent pursuant to Art. 7(1) GDPR.
Legal basis: The processing of the consent data takes place on the basis of Art. 6(1)(c) GDPR (compliance with a legal obligation) in conjunction with Section 25(2) no. 2 TDDDG. Storing the consent cookie is strictly technically necessary in order to implement and document your consent decisions in a legally compliant manner. We are obliged under Art. 7(1) GDPR to be able to demonstrate the consent given. The consent cookie is therefore set without your consent.
Note on strictly necessary cookies (category 1): OneTrust distinguishes between various cookie categories. Category 1 ("Strictly Necessary Cookies") always remains active at system level and is not deactivated even by selecting "Reject All". This is the intended standard behaviour of the platform and is unobjectionable from a data protection perspective, as strictly necessary cookies do not require consent.
Retention period: The OneTrust consent cookie is stored on your device for a period of 12 months. The TCF cookie euconsent-v2, in which your decisions under the Transparency and Consent Framework are stored, has a lifetime of 12 months. Once these periods have expired, you will be asked again for your consent decision. You can delete the cookies at any time via your browser settings. The consent data stored server-side at OneTrust is stored for the duration of our contractual relationship with OneTrust and deleted upon its termination.
Third-country transfer: OneTrust is based in the USA. Insofar as personal data is transferred to the USA, the following safeguards are in place:
- EU-U.S. Data Privacy Framework (DPF): OneTrust is certified under the European Commission's adequacy decision of 10 July 2023 pursuant to Art. 45 GDPR in accordance with the EU-U.S. Data Privacy Framework.
- Standard contractual clauses (SCCs): In addition, the EU standard contractual clauses pursuant to Commission Implementing Decision (EU) 2021/914 have been agreed.
Further information on data protection at OneTrust can be found at: https://www.onetrust.com/privacy-notice/
Our website uses OneTrust in a configuration certified under the IAB Transparency and Consent Framework (TCF) in version 2.3. Via the TCF, your decisions are transmitted in standardised form to the advertising partners integrated on our website, enabling them to recognise for which processing purposes a legal basis exists.
Sellwerk GmbH & Co. KG participates in the IAB Europe Transparency & Consent Framework and complies with its Specifications and Policies. Sellwerk GmbH & Co. KG uses the Consent Management Platform with the identification number 28.
7.2 Consent banner and consent options
On your first visit to our website, you are shown a consent banner in which you are informed in a granular manner about the intended data processing operations. You have the following choices:
(a) Accept all processing
(b) Reject all rejectable processing
(c) Individual selection by processing purpose and/or individual advertising partners (vendors)
You can change or withdraw your consents at any time thereafter via the cookie settings; you will find the link in the footer of our website. The withdrawal of consent does not affect the lawfulness of the processing carried out up to the point of withdrawal (Art. 7(3) GDPR).
7.3 Processing purposes under IAB TCF 2.3
Within the scope of TCF 2.3, the following standardised processing purposes are disclosed on our website. The names and descriptions are prescribed by IAB Europe and are identical to those shown to you in the consent banner.
Purposes for which we obtain your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG)
- Purpose 1: Store and/or access information on a device
- Purpose 2: Use limited data to select advertising
- Purpose 3: Create profiles for personalised advertising
- Purpose 4: Use profiles to select personalised advertising
- Purpose 5: Create profiles to personalise content
- Purpose 6: Use profiles to select personalised content
- Purpose 7: Measure advertising performance
- Purpose 8: Measure content performance
- Purpose 9: Understand audiences through statistics or combinations of data from different sources
- Purpose 10: Develop and improve services
- Purpose 11: Use limited data to select content
Purposes that individual advertising partners base on a legitimate interest as an alternative (Art. 6(1)(f) GDPR)
For purposes 2, 7, 8, 9, 10 and 11, the framework permits a legitimate interest as a legal basis in addition to consent (Art. 6(1)(f) GDPR). Which of the two bases an advertising partner relies on for which purpose is determined by the respective partner; you will find this information for each individual partner in the cookie settings. Insofar as a partner relies on a legitimate interest, you can object there at any time (Art. 21 GDPR). For purposes 1, 3, 4, 5 and 6, only your consent is permissible.
Special purposes (Art. 6(1)(f) GDPR)
Special purposes serve the technically sound and secure operation of the service. The framework does not provide for a right to object in respect of them.
- Special purpose 1: Ensure security, prevent and detect fraud, and fix errors
- Special purpose 2: Deliver and present advertising and content
- Special purpose 3: Save and communicate privacy choices
Features
Features are means of processing that are used solely to fulfil the purposes named above. They do not require separate consent, as they are covered by the decision on the respective purpose.
- Feature 1: Match and combine data from other data sources
- Feature 2: Link different devices
- Feature 3: Identify devices based on information transmitted automatically
Special features
Special features are only used if you expressly consent to them in the consent banner. Without your consent, the corresponding processing does not take place.
- Special feature 1: Use precise geolocation data
- Special feature 2: Identify devices based on information actively requested
7.4 Advertising partners (vendors)
We integrate advertising partners that are registered as vendors in the IAB TCF. You can view the complete and current list of the advertising partners we use at any time in the cookie settings; you will find the link in the footer of our website. Each advertising partner is listed there with the following information:
- Name and privacy policy of the advertising partner
- Processing purposes used and the respective legal basis (consent or legitimate interest)
- Retention period of the cookies used
There you can grant or refuse consent to each individual advertising partner, or object to its legitimate interest.
8. Phone number search and phone number database
a. Description of the service
Our websites offer a free reverse lookup for phone numbers. Users can enter a phone number and receive — where available — information on the number holder from public directory services, community ratings from other users, spam classifications and comments. The service serves to protect consumers against unwanted or fraudulent calls as well as to provide general information about number holders.
b. Processing of personal data of persons carrying out searches
When a phone number search is carried out, the following data of the searching user is processed:
- The phone number entered (search query)
- IP address of the requesting device
- Time of the search query
- Technical data (browser type, operating system)
This data is processed within the scope of the server log files described in Section III.2 and is subject to the same retention periods and legal bases.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in providing the phone number information service.
c. Integration of public directory services
Number holder data (in particular name, address and line of business) is not stored permanently by us. We do not operate our own phone number database containing holder information. Instead, this data is queried in real time via application programming interfaces (APIs) from the respective public directory providers when a search query is carried out:
- Das Telefonbuch (Deutsche Telekom Medien GmbH)
- Das Örtliche (Deutsche Tele Medien GmbH)
- Gelbe Seiten (Gelbe Seiten Zeichen-Service GmbH)
These services receive only the queried phone number; they cannot assign it to the searching user.
Holder data is resolved via public directory services exclusively for German phone numbers (country code +49). For phone numbers from other countries, no holder data is queried; only community ratings, comments and the spam classification are displayed.
The directory providers are independently responsible for the accuracy, currency and lawfulness of the data they provide. The provision of the data by the directory providers takes place on the basis of the respective terms of use and data protection provisions of these providers.
Technical cache: In order to ensure the availability and loading speed of our websites and to reduce the load on the interfaces to the directory providers, we use a temporary cache. Results for frequently requested phone numbers are temporarily cached there. The cache entries expire automatically after a defined period and are not retained permanently. The cache serves exclusively for technical performance optimisation and does not constitute independent data storage.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in providing a fast and reliable information service. The temporary caching is technically necessary in order to ensure the functionality of the service and to avoid overloading the interfaces. The legal basis for the temporary caching furthermore arises from Section 25(2) no. 2 TDDDG, as the caching is strictly technically necessary in order to provide the service expressly requested by the user.
Data protection responsibility: For the directory data temporarily held in the cache, we as the operator of the websites are responsible under data protection law (Art. 4 no. 7 GDPR), as the caching takes place at our instigation and within our infrastructure — even though the data is only held temporarily. The respective directory providers are independently responsible for the original collection and permanent storage of the number holder data in the directory services.
Third-country transfer: The German directory providers (Das Telefonbuch, Das Örtliche, Gelbe Seiten) process data within Germany or the European Union. No transfer of personal data to third countries outside the European Economic Area takes place in the course of the directory queries.
d. User ratings and community data
In addition to the directory data, our websites also display ratings and comments on individual phone numbers that have been submitted by users of our websites. This community data is stored permanently by us. Details on the collection, legal basis and retention period of this data can be found in Section III.1 of this privacy policy.
e. Automated rating (spam score)
We calculate a spam score for phone numbers automatically, which provides an assessment as to whether unwanted or fraudulent calls are likely to originate from a phone number.
The calculation of the spam score is based on aggregated feedback from the users of our service. The data basis originates from the following sources:
- Clever Dialer websites: User ratings and comments submitted on our websites (cleverdialer.de, .at, .ch, .co.uk, .es and .com).
- Clever Dialer Android app: Feedback that users of the Clever Dialer app for Android submit on phone numbers. This constitutes the primary data source for the spam classification. App users are informed about the transmission and processing of this data within the scope of the privacy policy applicable to the app.
Directory data from the external providers (Das Telefonbuch, Das Örtliche, Gelbe Seiten) does not feed into the calculation of the spam score.
Clarification: The automated calculation of the spam score does not constitute automated decision-making within the meaning of Art. 22(1) GDPR producing legal effects concerning the number holder or similarly significantly affecting them. The spam score serves exclusively to inform the users of our websites and has no direct legal or economic consequences for the number holder. Number holders have the opportunity at any time to request a review and correction of the classification.
f. Information obligations towards number holders (Art. 14 GDPR)
As we process personal data within the scope of the community ratings and the spam score calculation that has not been collected directly from the number holders concerned, we provide the following information pursuant to Art. 14 GDPR:
Categories of data processed:
- Phone number
- User ratings (stars, comment text) on this phone number
- User reports from the Clever Dialer Android app on this phone number
- Algorithmically calculated spam score
Source of the data (Art. 14(2)(f) GDPR): The community data stored on a phone number originates from users of our websites and of the Clever Dialer Android app, who have provided this data voluntarily and in the knowledge of the applicable data protection provisions. The spam score is derived algorithmically from this community data.
Purpose of the processing: Protection of consumers against unwanted, harassing or fraudulent calls; provision of an information service for identifying unknown phone numbers.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest and the interest of the public lie in protection against unwanted calls and in the transparency of the telecommunications market. As a rule, this interest outweighs the interest of number holders in the exclusion of the processing, as the community data relates exclusively to the use of the phone number in telecommunications traffic, the data has been provided voluntarily by users, and the algorithmic classification is based on aggregated user reports that do not constitute in-depth personality profiles. In weighing the interests, we take into account in particular that number holders have the opportunity at any time to object to the processing and to request the erasure or correction of their data (see below).
Retention period: User ratings and comments on a phone number are stored for as long as the respective phone number entry is provided (cf. Section III.1). User reports from the Clever Dialer Android app are stored for as long as they are necessary for the calculation of the spam score. The spam score itself is continuously recalculated on the basis of current data and is not stored historically in its own right.
g. Rights of number holders
Number holders whose phone number is associated with community ratings or a spam score on our websites have, in particular, the following rights:
- Right of access (Art. 15 GDPR): You can request information on which data relating to your phone number is stored by us and from which sources it originates.
- Right to rectification (Art. 16 GDPR): You can request the rectification of inaccurate data, including the correction of an incorrect spam classification.
- Right to erasure (Art. 17 GDPR): You can request the erasure of the community data and the spam score stored in relation to your phone number, provided that the conditions of Art. 17 GDPR are met.
- Right to object (Art. 21 GDPR): You can object at any time to the processing of your phone number data on grounds relating to your particular situation. We will then cease the processing unless we can demonstrate compelling legitimate grounds that override your interests.
Note on directory data: Insofar as you wish to have your holder data that originates from public directory services (Das Telefonbuch, Das Örtliche, Gelbe Seiten) erased or amended, please contact the respective directory provider directly. As we do not store this data permanently but retrieve it from the directory providers in real time, an amendment or erasure at the directory provider automatically also takes effect in the results displayed via our websites as soon as the temporary cache entry has expired.
To exercise your rights, please contact: support@cleverdialer.de
We will comply with your request without undue delay, and at the latest within one month of receipt of your request (Art. 12(3) GDPR).
9. Use by minors
Our websites are aimed at adults and young people aged 16 and over. They are not intended for children under 16. We do not knowingly collect personal data from children under 16. Should we become aware that a child under 16 has transmitted personal data to us, we will delete it without undue delay. Parents or legal guardians who suspect that their child has transmitted personal data to us can contact us at: privacy@cleverdialer.com
The provision of an email address is required in order to submit a rating or a comment. No age verification takes place in this context.
IV. Use of cookies for advertising purposes – highfivve
We use cookies of highfivve GmbH on our website. The provider is:
highfivve GmbH
Erika-Mann-Straße 23
80636 Munich
(hereinafter "highfivve")
Purpose of the processing: On the basis of corresponding agreements, highfivve GmbH enables third-party companies to set their own cookies on websites that are part of highfivve GmbH's marketing portfolio, or makes data collected by means of cookies available to third parties. The cookies are used for marketing purposes, for example in order to tailor advertising to the interests of a website visitor, to limit the frequency of display and to measure the effectiveness of an advertisement.
Legal basis: Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG (consent). The cookies of highfivve are set exclusively after you have given your consent via our consent management platform (OneTrust). Without your consent, no data processing by highfivve takes place.
Withdrawal of consent: You can withdraw your consent at any time with effect for the future by adjusting your cookie settings via our consent management platform (OneTrust). You will find the link to the cookie settings in the footer of our website. The withdrawal does not affect the lawfulness of the processing carried out up to that point.
Data processed and pseudonymisation: Cookies transmit only pseudonymous data at all times. Personal identification by means of a cookie is not possible. The cookie contains no information as to which user is currently using the browser. These statements relate to the cookies used. Insofar as advertising partners actively query device characteristics following your consent to special feature 2, your device is recognised not by means of cookies but by means of the combination of these characteristics.
Types of cookies used: The following types of cookies are used via our partner highfivve GmbH:
a. Cookies for campaign validation
These are cookies by means of which it is verified whether an advertising campaign has been carried out by highfivve GmbH for an advertising customer as contractually agreed. This includes cookies of highfivve GmbH and of highfivve GmbH's partners that record whether an advertising banner has been placed on a website with the agreed frequency. This serves to comply with and verify the specifications agreed with a customer for the execution of advertising campaigns (e.g. period, territory, avoidance of the same advertising medium being sent to a user more than once).
b. Cookies for achieving greater targeting accuracy
Cookies of highfivve GmbH are matched with cookies of other service providers in order to increase the probability of a match within a particular segment (e.g. interest). For such matching, highfivve GmbH uses the following cookies: cookies that are set by service providers on behalf of highfivve GmbH in order to analyse tracking behaviour (pages accessed by a user); cookies that highfivve GmbH receives from third parties in order to match them with its own segmentations; cookies that partners of highfivve GmbH set in order to achieve greater targeting accuracy and match with their own cookie data.
Data processed: The following data may be processed within the scope of the advertising monetisation by highfivve:
- Cookie IDs and comparable pseudonymous identifiers
- Information about websites accessed and advertisements clicked
- Time and frequency of the advertising impressions
- Technical information about the device (e.g. browser type, operating system, screen resolution)
- Approximate location (based on the IP address)
- Precise geolocation data (radius of less than 500 metres) – exclusively following your express consent to special feature 1 in the consent banner and only by those advertising partners that have declared this special feature in the Global Vendor List
- Actively queried device characteristics (e.g. installed fonts, screen resolution, browser version) for the purpose of recognising your device – exclusively following your express consent to special feature 2 in the consent banner
These data are not assigned to a specific natural person by highfivve.
Role under data protection law: highfivve GmbH and the advertising partners integrated via it act, with regard to the cookies they set and the associated data processing, as independent controllers within the meaning of Art. 4 no. 7 GDPR or, as the case may be, as joint controllers within the meaning of Art. 26 GDPR. The cookies are integrated on the basis of contractual agreements between us and highfivve GmbH. Insofar as highfivve or its partners process data as independent controllers, their respective data protection notices apply.
Third-country transfer: Insofar as advertising partners integrated via highfivve transfer personal data to third countries outside the European Economic Area, this is done on the basis of adequacy decisions of the European Commission pursuant to Art. 45 GDPR (in particular the EU-U.S. Data Privacy Framework), standard contractual clauses pursuant to Art. 46(2)(c) GDPR, or your express consent pursuant to Art. 49(1)(a) GDPR. Details of the respective transfer safeguards of the advertising partners can be found in their data protection notices, which are accessible via the cookie information tool of highfivve.
Retention period: The lifetime of the cookies set via highfivve varies depending on the advertising partner and the type of cookie. Detailed information on the individual cookies, including their respective lifetime, their provider and the opt-out options, is made available by highfivve GmbH via a software tool. You can view this information at the following link: https://highfivve.com/transparenz/
You have the option of configuring the use of advertising cookies at any time under your cookie settings.
Further data protection notices of highfivve GmbH can be found at: https://highfivve.com/transparenz/
As of: August 2026