Privacy Policy of DiBike Digitize Bike Business Group GmbH & Co. KG

Last updated: August 2026

1. Controller responsible for data processing (hereinafter: “we”)

The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:

DiBike Digitize Bike Business Group GmbH & Co. KG
Reinhardtstraße 7
10117 Berlin
Germany

Email: kontakt@dibike.org

Further information about us can be found in our legal notice.

2. Personal data, purposes of processing and legal bases

As a rule, our website can be used without you having to provide personal data. Providing personal data is voluntary.

Personal data means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more specific characteristics relating to the identity of that natural person.

The purpose of data processing is to operate this website and provide information about our services and ways to contact us.

Personal data is collected on our website only where this is

  • necessary for the provision and use of the website and individual functions (e.g. contact form) (legal bases: Art. 6(1), sentence 1, lit. b GDPR – steps taken prior to entering into a contract; where consent is required, Art. 6(1), sentence 1, lit. a GDPR),

  • necessary to safeguard our legitimate interest in improving the user experience and maintaining the security of use (legal basis: Art. 6(1), sentence 1, lit. f GDPR),

  • necessary for initiating contractual relationships (legal basis: Art. 6(1), sentence 1, lit. b GDPR; in individual cases, Art. 6(1), sentence 1, lit. a GDPR for additional processing based on consent).


Further details on data processing can be found below under the relevant headings:

3. Hosting, access data and technical logs

For the hosting and technical operation of our website, we use Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus. Hostinger processes personal data on our behalf on the basis of a data processing agreement pursuant to Art. 28 GDPR.

For prototypes, demos, landing pages as well as test or pre-release versions of digital services, we may additionally use external development and hosting services, in particular Lovable Labs AB, Regeringsgatan 25, 111 53 Stockholm, Sweden. Where personal data is transmitted through these services, it is processed exclusively for the purposes stated in each case, for example registering interested parties, testing processes or preparing digital services.

When our websites are accessed, technically necessary connection data is processed. This may include, in particular, the IP address, date and time of access, the page or file accessed, the referrer URL, browser type and version, and the operating system. We do not maintain a complete access log of all page views. However, limited technical error, security and system logs may be generated. These may contain the data mentioned above insofar as this is necessary for error analysis, the detection and prevention of abusive access, and ensuring the security and stability of our information technology systems.

The processing is based on Art. 6(1), sentence 1, lit. f GDPR. Our legitimate interest lies in the secure, stable and functional provision of our websites and digital services and in preventing attacks and misuse.

4. Cookies

Our website stores cookies. Cookies are small files that make it possible to store specific information relating to the user’s access device (PC, smartphone, etc.). On the one hand, they serve to improve the user-friendliness of websites and therefore benefit users (e.g. by storing login data). On the other hand, they are used to collect statistical data on website usage and to analyse this data in order to improve our offering. Further information can be found in the following sections of this Privacy Policy.

Where you consent to the use of non-essential cookies, the legal basis is Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG) and Art. 6(1), sentence 1, lit. a GDPR (consent). Further information on this and on the cookies and services used can be found in our consent management tool. The provider is CookieYes Limited, Warren Yard, Wolverton Mill, Milton Keynes, England, MK12 5NW, United Kingdom.

As a user, you can control the use of cookies. Most browsers provide an option to restrict or completely prevent the storage of cookies. Please note, however, that the use and in particular the convenience of using the website may be limited without cookies.

5. Contact via email / contact form

If you send us enquiries by email or via the contact form, the information you provide will be stored by us for the purpose of processing your enquiry. The processing is carried out in order to respond to your enquiry and to take steps prior to entering into a contract on the basis of Art. 6(1), sentence 1, lit. b GDPR.

6. User accounts and registrations

For certain DiBike digital services, the creation of a user account or registration is required. In connection with registration and the use of a user account, we may in particular process company name, name and contact details of contact persons, email address, login data, technical identifiers, IP address, as well as registration and access times.

The processing is carried out to provide protected or registration-based services, to manage user accounts, to authenticate and authorise users and to ensure system security.

The legal basis is Art. 6(1), sentence 1, lit. b GDPR insofar as the processing is necessary for registration, use and administration of the respective service. Where the processing serves technical provision, system security, error analysis or misuse detection, it is based on Art. 6(1), sentence 1, lit. f GDPR. Our legitimate interest lies in the secure, stable and user-friendly operation of our digital services.

7. Chat function via Brevo

For the provision and operation of the chat function on our website, we use Brevo Conversations, a service provided by Sendinblue SAS, 17 rue de Salneuve, 75017 Paris, France. If you use the chat function, we process the content you enter as well as the data required for technical provision. This may include, in particular, your name, email address, the content of your message, the date and time of your enquiry, as well as technical connection data such as your IP address.

The processing is carried out in order to handle your enquiry, communicate with you and ensure the functionality and security of the chat function.

The legal basis for the processing is Art. 6(1), sentence 1, lit. f GDPR. Our legitimate interest lies in the simple and efficient handling of enquiries and in providing a user-friendly means of communication. Where the processing is necessary for steps taken prior to entering into a contract or for the performance of a contract, it is additionally based on Art. 6(1), sentence 1, lit. b GDPR.

8. Newsletter via Brevo

We also use Brevo for sending our newsletter.

If you subscribe to our newsletter, we process your email address and, where provided by you, further information such as your name. We also store the time of registration and confirmation in order to document your consent.

Registration for our newsletter uses the so-called double opt-in procedure. This means that after registering, you will receive an email asking you to confirm your subscription. Your email address will only be added to our newsletter distribution list after this confirmation.

The processing is carried out exclusively on the basis of your consent pursuant to Art. 6(1), sentence 1, lit. a GDPR. You may withdraw your consent at any time with effect for the future, for example by using the unsubscribe link contained in each newsletter or by contacting us. The lawfulness of processing carried out before the withdrawal of consent remains unaffected.

9. Google Analytics

Our website uses Google Analytics to analyse the use of our website and thereby make it more user-friendly and effective and to better promote and offer our services. The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For users whose habitual residence is in the European Economic Area or Switzerland, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, EU, is the controller responsible for Google services (hereinafter: “Google”). Google Ireland Limited is an affiliated company of Google LLC whose services we integrate and which is also required to comply with the GDPR.

On 10 July 2023, the European Commission adopted the adequacy decision for the new EU-US Data Privacy Framework (DPF). US companies can participate in the framework by committing themselves to detailed data protection requirements. Google LLC participates in the framework and is certified accordingly.

Google Analytics uses cookies. The information generated by cookies about your use of our website is generally transmitted to and stored on a Google server in the USA. However, the IP address transmitted by your device as part of Google Analytics is not combined with other Google data. IP anonymisation is activated on our website. This means that your IP address is shortened by Google within Member States of the European Union or other states party to the Agreement on the European Economic Area before being transmitted further. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there. On our behalf, Google uses this information to evaluate your use of the website, compile reports on website activity and provide us with further services related to website and internet usage.

The legal basis for its use is Art. 6(1), sentence 1, lit. f GDPR, because we have a legitimate interest in analysing and promoting our website or, where you have given consent based on a notice provided by us on the website (“cookie banner”), Art. 6(1), sentence 1, lit. a GDPR and Section 25(1) TDDDG.

10. Google Maps

We also use Google Maps by Google LLC to display interactive maps and locations. When you access a page on which Google Maps is embedded, your IP address, technical usage data, information about the device used and, if you are logged into Google, additional data may in particular be transmitted to Google.

The legal basis for its use is Art. 6(1), sentence 1, lit. f GDPR because we have a legitimate interest in displaying locations or, where you have given consent based on a notice provided by us on the website (“cookie banner”), Art. 6(1), sentence 1, lit. a GDPR and Section 25(1) TDDDG.

11. Calendly

For certain appointment bookings, we use Calendly. The provider is Calendly LLC, 115 E Main St, Ste A1B, Buford, GA 30518, USA. When using Calendly, your name, email address, appointment data, communication data and technical usage data may in particular be processed.

The processing is carried out for the purpose of scheduling, conducting and following up on appointments and communicating with you. The legal basis is Art. 6(1), sentence 1, lit. b GDPR insofar as the processing is necessary for steps taken prior to entering into a contract or for the performance of a contract. Otherwise, the processing is based on Art. 6(1), sentence 1, lit. f GDPR. Our legitimate interest lies in the efficient and user-friendly organisation of appointments.

The transfer of personal data to the USA cannot be ruled out. Calendly LLC is certified under the EU-US Data Privacy Framework. Data transfers to the USA may therefore take place on the basis of the European Commission’s adequacy decision pursuant to Art. 45 GDPR. Where required, additional appropriate safeguards pursuant to Art. 46 GDPR, in particular the European Commission’s Standard Contractual Clauses, are used.

12. Appointment booking via Microsoft Bookings

For appointment bookings and appointment management, we use Microsoft Bookings. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.

If you book an appointment with us via Microsoft Bookings, we process the data you enter in the booking form. This generally includes your name, email address, where applicable your telephone number, the name of your company, the selected appointment and any additional information you voluntarily provide as part of the booking process. Technical data, in particular your IP address and information about your browser and device, may also be processed.

Microsoft Bookings is not loaded automatically when you access the relevant page on our website, but only once you actively enable the external calendar. Once activated, a connection to Microsoft is established. In particular, your IP address, browser data and other technical information may then be transmitted to and processed by Microsoft. Activation takes place only on the basis of your consent pursuant to Section 25(1) TDDDG and Art. 6(1), sentence 1, lit. a GDPR. You can refuse consent by not activating the external calendar and instead using the alternative contact or booking options.

The data provided as part of the appointment booking is processed for the purpose of taking steps prior to entering into a contract or performing a contract, where the appointment relates to such purposes, pursuant to Art. 6(1), sentence 1, lit. b GDPR. Where data processing is necessary for the organisation, administration and technical provision of the appointment booking service, it is based on our legitimate interest pursuant to Art. 6(1), sentence 1, lit. f GDPR. Our legitimate interest lies in the efficient, user-friendly and reliable coordination of appointments.

13. Microsoft Forms

For certain forms, registrations, surveys or enquiries from interested parties, we use Microsoft Forms. In particular, contact data, company data, enquiry data and communication data may be processed. The specific data collected in each case is set out in the respective form. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Dublin D18 P521, Ireland.

The processing is carried out to handle your enquiry, take steps prior to entering into a contract, perform a contract or otherwise communicate with you. Depending on the respective purpose, the legal basis is Art. 6(1), sentence 1, lit. b GDPR or Art. 6(1), sentence 1, lit. f GDPR. Our legitimate interest lies in the structured and efficient handling of incoming enquiries.

14. Leasing-Check

If you use Leasing-Check, the following personal data and technical information in particular may be processed: company name, address of the business premises or operating unit and contact details of contact persons, email address, login data as well as registration, activation and access data, technical identifiers, in particular retailerId, userId and systemId, IP address, timestamps and technical access, error and status data, information relating to technical service providers, ERP or merchandise management systems, in particular system information, technical endpoints, integration data and API or system identifiers; search parameters, in particular the email address of the person entitled to leasing benefits, contract numbers and other required technical contract or transaction references.

Search parameters may only be entered where they are lawfully available in connection with a specific service, maintenance or workshop case.

The processing is carried out in particular for registering, verifying and activating retailers and workshops; providing and operating Leasing-Check; authenticating and authorising users and systems; carrying out service entitlement checks; technically transmitting enquiries to connected leasing providers; and displaying the information provided by them. The legal basis is Art. 6(1), sentence 1, lit. b GDPR. Where processing serves technical provision, system security, error analysis, misuse detection, logging or further development of the service, it is based on Art. 6(1), sentence 1, lit. f GDPR. Our legitimate interest lies in particular in the secure, stable, traceable and misuse-protected operation of Leasing-Check. Where statutory retention or documentation obligations apply, processing is based on Art. 6(1), sentence 1, lit. c GDPR.

15. Data transfer to connected leasing providers

As part of a specific Leasing-Check enquiry, we transmit the data required for that enquiry to the respective connected leasing provider being queried. This may include, in particular, search parameters such as an email address or contract number, retailerId, systemId, timestamps and technical contextual information.

The data is transmitted exclusively for the purpose of processing the respective enquiry. The legal basis is Art. 6(1), sentence 1, lit. b GDPR for the performance of a contract. Leasing providers respond to enquiries on the basis of their own data records and are independently responsible for the accuracy, timeliness and completeness of the contract, status and entitlement data they provide. Leasing providers do not have reciprocal access to data, contract information or response data of other leasing providers.

16. Payment processing and invoicing

For paid subscriptions booked online via Leasing-Check, we use Mollie. The provider is Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands. In particular, name, company, billing address, email address, contract and service data, payment data, invoice data as well as transaction and payment status data may be processed.

For invoicing, accounting and the fulfilment of tax obligations, we may use accounting and tax service providers. This may in particular include DATEV eG, Paumgartnerstraße 6–14, 90429 Nuremberg, Germany.

The processing is based on Art. 6(1), sentence 1, lit. b GDPR insofar as it is necessary for the performance of a contract and payment processing, and on Art. 6(1), sentence 1, lit. c GDPR insofar as statutory retention or documentation obligations apply.

17. Storage periods

We delete your personal data once the purpose for which it was processed has been fulfilled, unless statutory retention obligations require continued storage. Specifically, we delete your data as follows:

In all other respects, we review at least annually whether the data stored about you can be deleted.

18. Rights of data subjects

You are not legally required to provide your personal data. However, providing personal data may be necessary in order to enter into a contract or to use certain functions of the website. If you do not provide the required data, it may therefore not be possible to conclude a contract or provide a particular website function.

There is no automated decision-making on the website and no profiling takes place.

The rights of data subjects arise in particular from Articles 15 to 23 and Article 77 GDPR as well as Sections 32 to 37 of the German Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG).

With regard to your personal data, you have the following rights vis-à-vis us:

  • Right of access, Art. 15 GDPR

  • Right to rectification, Art. 16 GDPR

  • Right to erasure, Art. 17 GDPR

  • Right to restriction of processing, Art. 18 GDPR

  • Right to data portability, Art. 20 GDPR


If you have given your consent to the processing of personal data, you have the right to

  • withdraw your consent, Art. 7 GDPR

with effect for the future.

You also have the right to

  • object to the processing of personal data, Art. 21 GDPR

  1. You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you where such processing is based on Art. 6(1), sentence 1, lit. f GDPR (data processing based on a balancing of interests).

    If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or unless the processing is necessary for the establishment, exercise or defence of legal claims.

  2. In individual cases, we process personal data for direct marketing purposes. Where this applies to you, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing.

    If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes.


You may object without any particular formality. Where possible, the objection should be addressed to us; see Section 1 above.

If you believe that the processing of personal data concerning you infringes data protection law, you also have the

  • right to lodge a complaint

with the competent supervisory authority, pursuant to Art. 77 GDPR. Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.

Contact details for the data protection authorities of the German federal states, supervisory authorities for the non-public sector, broadcasting organisations and churches, as well as authorities in Europe and other countries and the Virtual Data Protection Office, can be found here: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html

The supervisory authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information, Friedrichstraße 219, 10969 Berlin.

Digitize Bike Business

Open digital infrastructure for the bicycle industry

COnTACT

Networking

© 2025 DiBike Digitize Bike Business Group GmbH & Co. KG