Privacy Policy

Language Versions

This privacy policy is also made available in other languages to make it easier to understand for users across Europe. Only the German version is authoritative and legally binding. In the event of any discrepancy or ambiguity between this translation and the German version, the German version shall prevail.

Introduction and Overview

We have prepared this privacy policy (version 30 August 2026) to explain, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (in short, "data") we process as the controller — and the processors we engage (e.g. providers) — will process in future, and what lawful options are available to you. The terms used are to be understood as gender-neutral.

In short: We inform you comprehensively about the data we process about you.

Privacy policies usually sound very technical and use legal terminology. This privacy policy, however, aims to describe the most important things to you as simply and transparently as possible. Wherever it helps transparency, technical terms are explained in a reader-friendly way, links to further information are provided, and graphics are used. We thus inform you in clear and simple language that, in the course of our business activities, we process personal data only where a corresponding legal basis exists.

If you still have questions, please contact the responsible party named below or in the legal notice ("Impressum"), follow the links provided, and look at further information on third-party sites. Our contact details can, of course, also be found in the legal notice.

Scope

This privacy policy applies to all personal data processed by our company and to all personal data processed by companies we engage (processors). By personal data we mean information within the meaning of Art. 4 No. 1 GDPR, such as a person's name, email address and postal address. The processing of personal data allows us to offer and bill for our services and products, whether online or offline. The scope of this privacy policy covers:

  • all online presences (websites, online shops) that we operate
  • social media presences and email communication
  • mobile apps for smartphones and other devices

In short: This privacy policy applies to all areas in which personal data is processed in a structured manner within the company via the channels named above. Should we enter into a legal relationship with you outside these channels, we will inform you separately where applicable.

Legal Bases

In the following privacy policy, we provide you with transparent information on the legal principles and provisions — that is, the legal bases of the General Data Protection Regulation — that enable us to process personal data. With regard to EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can, of course, read this EU General Data Protection Regulation online on EUR-Lex, the gateway to EU law, at https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A32016R0679.

We only process your data if at least one of the following conditions applies:

  1. Consent (Article 6(1)(a) GDPR): You have given us your consent to process data for a specific purpose. An example would be the storage of data you entered into a contact form.
  2. Contract (Article 6(1)(b) GDPR): We process your data in order to fulfil a contract or pre-contractual obligations with you. For example, if we enter into a purchase agreement with you, we need personal information beforehand.
  3. Legal obligation (Article 6(1)(c) GDPR): We process your data if we are subject to a legal obligation. For example, we are legally required to retain invoices for accounting purposes. These usually contain personal data.
  4. Legitimate interests (Article 6(1)(f) GDPR): In the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we must process certain data in order to operate our website securely and cost-effectively. This processing therefore constitutes a legitimate interest.

Other conditions, such as tasks carried out in the public interest and the exercise of official authority, as well as the protection of vital interests, generally do not apply to us. Should such a legal basis nevertheless be relevant, it will be indicated at the appropriate point.

In addition to the EU regulation, national laws also apply:

  • In Germany, the Federal Data Protection Act (Bundesdatenschutzgesetz), abbreviated BDSG, applies.

Should further regional or national laws apply, we will inform you accordingly in the following sections.

Contact Details of the Controller

Should you have questions about data protection or the processing of personal data, you will find the contact details of the responsible person or body below:

KRV Transporte und Dienstleistungen e. K.
Kevin Rüchel-Volkmann
Langforter Str. 19
40764 Langenfeld
Germany

Email: kontakt@krvtd.com
Phone: +49 1578 5559857

Commercial register: HRA 27992, Düsseldorf Local Court
VAT ID: DE347700651

Retention Period

As a general rule, we only store personal data for as long as is strictly necessary to provide our services and products. This means that we delete personal data as soon as the reason for processing it no longer applies. In some cases, we are legally required to continue storing certain data even after the original purpose no longer applies, for example for accounting purposes.

Should you wish to have your data deleted or withdraw your consent to data processing, the data will be deleted as quickly as possible, provided there is no obligation to retain it.

We will inform you below of the specific duration of the respective data processing, where we have further information on this.

Rights under the General Data Protection Regulation

In accordance with Articles 13 and 14 GDPR, we inform you of the following rights to which you are entitled, in order to ensure fair and transparent data processing:

  • Pursuant to Article 15 GDPR, you have a right of access as to whether we process data about you. If so, you have the right to receive a copy of the data and to obtain the following information:
    • the purpose for which we carry out the processing;
    • the categories, i.e. the types, of data being processed;
    • who receives this data, and if the data is transferred to third countries, how security can be guaranteed;
    • how long the data will be stored;
    • the existence of the right to rectification, erasure or restriction of processing, and the right to object to the processing;
    • that you may lodge a complaint with a supervisory authority;
    • the origin of the data if we did not collect it from you;
    • whether profiling is carried out.
  • Pursuant to Article 16 GDPR, you have a right to rectification of the data, which means we must correct data if you find errors.
  • Pursuant to Article 17 GDPR, you have the right to erasure ("right to be forgotten"), meaning specifically that you may request the deletion of your data.
  • Pursuant to Article 18 GDPR, you have the right to restriction of processing, meaning that we may only continue to store the data but may not use it further.
  • Pursuant to Article 20 GDPR, you have the right to data portability, meaning that we will provide you with your data in a common format upon request.
  • Pursuant to Article 21 GDPR, you have a right to object, which, if exercised, results in a change to the processing.
    • If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you may object to the processing. We will then examine as quickly as possible whether we are legally able to comply with this objection.
    • If data is used to conduct direct marketing, you may object to this type of data processing at any time. We will then no longer be permitted to use your data for direct marketing.
  • Pursuant to Article 77 GDPR, you have the right to lodge a complaint. This means you may complain to the data protection authority at any time if you believe that the processing of personal data violates the GDPR.

In short: You have rights — do not hesitate to contact the responsible party listed above!

Supervisory Authority

If you believe that the processing of your data violates data protection law, or that your data protection rights have otherwise been infringed, you may lodge a complaint with the supervisory authority. In Germany, each federal state has its own data protection officer. The following local data protection authority is responsible for our company:

North Rhine-Westphalia Data Protection Authority

State Commissioner for Data Protection: Bettina Gayk
Address: Kavalleriestraße 2-4, 40213 Düsseldorf, Germany
Phone: +49 211/38424-0
Email: poststelle@ldi.nrw.de
Website: https://www.ldi.nrw.de/

Data Transfer to Third Countries

We only transfer or process data in countries outside the scope of the GDPR (third countries) if you consent to such processing or if another legal permission exists. This applies in particular where processing is required by law or necessary for the performance of a contractual relationship. Your consent is, in most cases, the main reason we allow data to be processed in third countries.

The processing of personal data in third countries such as the USA, where many software providers offer services and host their servers, may mean that personal data is processed and stored in unexpected ways.

We expressly point out that, in the opinion of the European Court of Justice, an adequate level of protection for data transfers to the USA currently exists where a US company processing personal data of EU citizens in the USA is an active participant in the EU-US Data Privacy Framework. More information can be found at: EU-US Data Privacy Framework

In addition, we use what are known as Standard Contractual Clauses (Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are template agreements provided by the European Commission designed to ensure that your data continues to meet European data protection standards even when transferred to and stored in third countries (such as the USA).

Security of Data Processing

To protect personal data, we have implemented both technical and organisational measures. Wherever possible, we encrypt or pseudonymise personal data. This makes it as difficult as possible, within our means, for third parties to draw personal conclusions from our data.

Article 25 GDPR refers here to "data protection by design and by default", meaning that security is always considered — and appropriate measures taken — for both software (e.g. forms) and hardware (e.g. access to the server room).

TLS Encryption via HTTPS

TLS, encryption and HTTPS sound very technical, and they are. We use HTTPS ("Hypertext Transfer Protocol Secure") to transmit data over the internet in a way that cannot be intercepted.

This means that the entire transmission of all data from your browser to our web server is secured — no one can "listen in".

This gives us an additional layer of security and fulfils the requirement of data protection by design (Article 25(1) GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission over the internet, we can ensure the protection of confidential data.

You can recognise the use of this secured data transmission by the small padlock symbol in the top left of your browser, to the left of the web address, and by the use of "https" (instead of "http") as part of our web address.

Cookies

Cookies Summary

- Affected parties: Website visitors
- Purpose: depends on the specific cookie. More details below.
- Data processed: depends on the specific cookie used. More details below.
- Retention period: depends on the specific cookie, ranging from hours to years
- Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What are cookies?

Our website uses HTTP cookies to store user-specific data. Below we explain what cookies are and why they are used, to help you better understand the following privacy policy.

Whenever you browse the internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.

Cookies store certain user data about you, such as language or personal page settings. When you visit our site again, your browser sends this "user-related" information back to our site. Thanks to cookies, our website knows who you are and offers you the settings you are used to.

What types of cookies are there?

There are 4 types of cookies:

Essential cookies: These cookies are necessary to ensure basic functions of the website. For example, they are needed when a user adds a product to the shopping cart, continues browsing other pages, and only proceeds to checkout later.

Functional cookies: These cookies collect information about user behaviour and whether the user receives any error messages. They are also used to measure loading times and website behaviour across different browsers.

Targeting cookies: These cookies improve usability. For example, entered locations, font sizes or form data are stored.

Advertising cookies: These cookies are also called targeting cookies. They serve to deliver individually tailored advertising to the user. This can be very useful, but also very annoying.

Usually, when you first visit a website, you are asked which types of cookies you want to allow. And, of course, this decision is also stored in a cookie.

How can I delete cookies?

You decide for yourself how and whether you want to use cookies. Regardless of which service or website the cookies come from, you always have the option to delete, disable, or only partially allow cookies.

You can manage cookies in your browser. Depending on your browser, this works slightly differently. Here you will find instructions for the most well-known browsers currently in use:

Legal Basis

Since 2009, so-called "cookie guidelines" have existed. These stipulate that the storage of cookies requires your consent (Article 6(1)(a) GDPR). In Germany, the implementation of this guideline was largely regulated in Section 15(3) of the Telemedia Act (TMG), which was replaced by the Digital Services Act (DDG) in May 2024.

For strictly necessary cookies, even where no consent has been given, legitimate interests apply (Article 6(1)(f) GDPR), which in most cases are economic in nature. We want to give visitors to the website a pleasant user experience, and certain cookies are often strictly necessary for this.

Where non-essential cookies are used, this only happens with your consent. The legal basis for this is Art. 6(1)(a) GDPR.

Web Hosting

Web Hosting Summary

- Affected parties: Website visitors
- Purpose: professional hosting of the website and securing its operation
- Data processed: IP address, time of website visit, browser used, and other data
- Retention period: depends on the respective provider
- Legal bases: Art. 6(1)(f) GDPR (legitimate interests)

What is web hosting?

When you visit websites nowadays, certain information — including personal data — is automatically created and stored, including on this website. This data should be processed as sparingly as possible and only where justified.

By "website" we mean the entirety of all web pages on a domain, i.e. everything from the homepage to the very last subpage. By "domain" we mean, for example, example.com.

To view a website, you use a program called a web browser. You probably know some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox and Apple Safari.

To display the website, the browser must connect to another computer where the website's code is stored: the web server. Operating a web server is a complicated and demanding task, which is why it is usually handled by professional providers who offer web hosting and thus ensure reliable, error-free storage of website data.

Why do we process personal data?

The purposes of data processing are:

  1. Professional hosting of the website and securing its operation
  2. Maintaining operational and IT security
  3. Anonymous evaluation of access patterns to improve our offering, and, where necessary, for prosecution or the pursuit of claims

What data is processed?

Even while you are visiting our website right now, our web server — the computer on which this website is stored — usually automatically stores data such as:

  • the complete internet address (URL) of the web page accessed
  • browser and browser version (e.g. Chrome 87)
  • the operating system used (e.g. Windows 10)
  • the address (URL) of the previously visited page (referrer URL)
  • the hostname and IP address of the device from which access is made
  • date and time
  • stored in files known as web server log files

How long is data stored?

As a rule, the above data is stored for two weeks to two months and then automatically deleted. We do not pass this data on to third parties, but cannot rule out that it may be inspected by authorities in the event of unlawful conduct.

In short: Your visit is logged by our provider, but we do not pass on your data without consent!

Legal Basis

The lawfulness of processing personal data in connection with web hosting arises from Art. 6(1)(f) GDPR (protection of legitimate interests), since the use of professional hosting with a provider is necessary to present the company on the internet in a secure and user-friendly manner, and to be able to pursue any attacks or claims arising from this where necessary.

Firebase Hosting Privacy Notice

What is Firebase Hosting?

We use Firebase Hosting, a web hosting and cloud service, for our website. The service provider is the American company Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For the European region, the responsible company is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Firebase Hosting is part of the Google Cloud Platform and offers fast, secure hosting for web applications. The services include content delivery via a global Content Delivery Network (CDN) and SSL encryption.

What data does Firebase process?

When using Firebase Hosting, the following data is automatically processed:

  • IP address
  • timestamp of access
  • requested URL
  • HTTP status code
  • amount of data transferred
  • user agent (browser and operating system)
  • referrer (which page you came from)

How long is the data stored?

By default, Firebase stores access logs for up to 30 days. After this period, the data is automatically deleted.

Data Transfer to the USA

Google also processes some of your data in the USA. Google is an active participant in the EU-US Data Privacy Framework, which governs the correct and secure transfer of personal data of EU citizens to the USA. More information can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en

Google also uses what are known as Standard Contractual Clauses (Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are template agreements provided by the European Commission designed to ensure that your data continues to meet European data protection standards even when transferred to and stored in third countries (such as the USA).

Legal Basis

We have a legitimate interest in using Firebase Hosting in order to provide our online service. The corresponding legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). We only use Firebase to the extent that we have taken the necessary security measures.

More information about Firebase and data protection can be found at https://firebase.google.com/support/privacy and in Google's general privacy policy at https://policies.google.com/privacy.

Communication

Communication Summary

- Affected parties: Everyone who communicates with us by phone, email or online form
- Data processed: e.g. phone number, name, email address, submitted form data
- Purpose: handling communication with customers, business partners, etc.
- Retention period: duration of the business matter and applicable statutory provisions
- Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interests)

If you contact us and communicate with us by phone, email, or online form, personal data may be processed.

The data is processed to handle and process your inquiry and the related business matter. The data is stored for as long as required, or for as long as prescribed by law.

Data Subjects

All those who seek contact with us via the communication channels we provide are affected by the processes described.

Phone

If you call us, the call data is stored in pseudonymised form on the respective end device and by the telecommunications provider used. In addition, data such as name and phone number may subsequently be sent by email and stored for the purpose of answering your inquiry. The data is deleted once the business matter has concluded and statutory provisions permit.

Email

If you communicate with us by email, data may be stored on the respective end device (computer, laptop, smartphone, etc.) and will be stored on the email server. The data is deleted once the business matter has concluded and statutory provisions permit.

Online Forms

If you communicate with us via an online form, data is stored on our web server and, where applicable, forwarded to one of our email addresses. The data is deleted once the business matter has concluded and statutory provisions permit.

Contact Form

Our website features a contact form through which you can send us messages. When you use this form, the following data is processed:

  • Name
  • Email address
  • Phone number (optional)
  • Subject of the inquiry
  • Message text
  • Time of submission

Processing takes place via Firebase Functions and Brevo for sending emails. After successful submission, you will receive an automatic confirmation email from noreply@krvtd.com.

Legal Bases

The processing of data is based on the following legal bases:

  • Art. 6(1)(a) GDPR (consent): You give us consent to store your data and to use it further for purposes related to the business matter;
  • Art. 6(1)(b) GDPR (contract): There is a need to fulfil a contract with you, or we must process the data for pre-contractual activities, such as preparing a quote;
  • Art. 6(1)(f) GDPR (legitimate interests): We want to handle customer inquiries and business communication in a professional manner.

Brevo Email Delivery

What is Brevo?

We use Brevo (formerly Sendinblue) to send transactional emails (e.g. confirmation emails after a contact form submission). Brevo is a cloud-based email service provided by Sendinblue SAS, 55 rue d'Amsterdam, 75008 Paris, France.

What data is processed?

When you use our contact form and we send you a confirmation email, the following data is processed via Brevo:

  • Recipient's email address
  • Email content
  • Time of sending
  • Delivery status

Legal Basis and Data Transfer

The legal basis for using Brevo is Art. 6(1)(f) GDPR (legitimate interests). Our legitimate interest lies in ensuring reliable email delivery.

Brevo processes data primarily within the EU (server location: France) and is bound by European data protection standards.

More information can be found in Brevo's privacy policy: https://www.brevo.com/en/legal/privacypolicy/

Google Analytics Privacy Notice

Google Analytics Summary

- Affected parties: Website visitors
- Purpose: analysis of visitor information to optimise the website
- Data processed: access statistics, including data such as access locations, device data, access duration and time, navigation behaviour and click behaviour
- Retention period: individually configurable; by default, Google Analytics 4 stores data for 2 months
- Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What is Google Analytics?

We use the analytics tracking tool Google Analytics 4 (GA4) from the American company Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) on our website. For the European region, the responsible company is Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Google Analytics collects data about your actions on our website.

Through a combination of various technologies such as cookies, device IDs and login information, you as a user can be identified across different devices. This allows your actions to be analysed across platforms as well.

Why do we use Google Analytics?

With Google Analytics, we can measure how you interact with our website. For example, we can determine which pages are visited most frequently and where visitors come from. This helps us improve our offering and better respond to the needs of our users.

What data does Google Analytics store?

Google Analytics uses a tracking code to create a random, unique ID that is linked to your browser cookie. This is how Google Analytics recognises you as a new user, and a user ID is assigned to you. The next time you visit our site, you will be recognised as a "returning" user.

All collected data is stored together with this user ID, which is what makes it possible to evaluate pseudonymous user profiles.

To analyse our website with Google Analytics, a property ID must be inserted into the tracking code. The data is then stored in the corresponding property. For every newly created property, the Google Analytics 4 property is the default. Depending on the property used, data is stored for different lengths of time.

Through identifiers such as cookies, app instance IDs, user IDs, or custom event parameters, your interactions are measured across platforms. Interactions are any type of action you take on our website. If you also use other Google systems (such as a Google account), data generated via Google Analytics may be linked with third-party cookies.

Data Retention Period

We have set the retention period for your user data in Google Analytics to 2 months. After this period, your user data is deleted. This setting only affects personal data linked to cookies, user recognition and advertising IDs. Aggregated statistics are retained for longer.

Google Consent Mode

We use Google Consent Mode version 2 (Advanced Mode). This means:

  • With your consent: Google Analytics uses cookies and collects detailed data about your user behaviour
  • Without your consent: Google only receives anonymised pings (without cookies) that enable basic statistics

Advanced Consent Mode allows Google to collect anonymised data — which cannot be attributed to any individual — even without cookies. This improves data quality without compromising your privacy.

How can I delete my data or prevent data storage?

You have the right, at any time, to access, rectify, erase, and restrict the processing of your personal data. You may also withdraw your consent to the processing of the data at any time.

You can manage, disable, or delete cookies in your browser. Please note, however, that this may impair certain functions of this website.

If you generally wish to disable, delete, or manage cookies, you will find the corresponding links to instructions for the most well-known browsers under the "Cookies" section.

Legal Basis

The use of Google Analytics requires your consent, which we obtain via our cookie banner. This consent, under Art. 6(1)(a) GDPR (consent), constitutes the legal basis for the processing of personal data that may occur when data is collected by web analytics tools.

In addition to consent, we have a legitimate interest in analysing the behaviour of website visitors in order to improve our offering both technically and economically. With the help of Google Analytics, we can identify website errors, detect attacks, and improve cost-effectiveness. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). We only use Google Analytics to the extent that you have given consent.

Data Transfer to the USA

Google also processes some of your data in the USA. Google is an active participant in the EU-US Data Privacy Framework, which governs the correct and secure transfer of personal data of EU citizens to the USA. More information can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en

Google also uses what are known as Standard Contractual Clauses (Art. 46(2) and (3) GDPR). The relevant Standard Contractual Clauses can be found at: https://business.safety.google/adsprocessorterms

More information about the data processed through the use of Google Analytics can be found in the privacy policy at https://policies.google.com/privacy

Google Tag Manager Privacy Notice

Google Tag Manager Summary

- Affected parties: Website visitors
- Purpose: organisation of the individual tracking tools
- Data processed: Google Tag Manager itself does not store any data. The data captured relates to the tags of the web analytics tools used
- Retention period: depends on the web analytics tool used
- Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What is Google Tag Manager?

We use Google Tag Manager from Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) on our website. For the European region, the responsible company is Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). This tag manager is one of many helpful marketing products from Google. Through Google Tag Manager, we can centrally install and manage code snippets from various tracking tools that we use on our website.

Google Tag Manager itself does not set any cookies and does not store any personal data. It only enables the management and deployment of tags. Tags are small code snippets that, for example, record (track) your activities on our website.

Why do we use Google Tag Manager?

Google Tag Manager helps us organise our website more effectively. Through Google Tag Manager, we can install and manage all tracking tags centrally via a single interface. Tags are small code snippets that, for example, record (track) your activities on our website. JavaScript code snippets are inserted into the source code of our page for this purpose.

What data does Google Tag Manager store?

Google Tag Manager itself does not store any personal data. However, personal data may be collected and processed via the tags it manages. In our case, Google Tag Manager is mainly used to integrate and manage Google Analytics 4.

Legal Basis

The use of Google Tag Manager requires your consent, which we obtain via our cookie banner. This consent, under Art. 6(1)(a) GDPR (consent), constitutes the legal basis for the processing of personal data that may occur through the use of Google Tag Manager.

In addition to consent, we have a legitimate interest in managing various tools as simply as possible and optimising our website's performance. The corresponding legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). We only use Google Tag Manager to the extent that you have given consent.

Google also processes some of your data in the USA. Google is an active participant in the EU-US Data Privacy Framework, which governs the correct and secure transfer of personal data.

If you would like to learn more about Google Tag Manager, we recommend the FAQ at https://www.google.com/intl/en/tagmanager/faq.html

WhatsApp Privacy Notice

WhatsApp Summary

- Affected parties: WhatsApp users who communicate with us
- Purpose: communication with customers
- Data processed: contact details, messages, media
- Retention period: data is deleted after communication ends
- Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What is WhatsApp?

We use the instant messaging service WhatsApp on our website to communicate with our customers. The service provider is the American company WhatsApp Inc., a subsidiary of Meta Platforms Inc. For the European region, the responsible company is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Why do we use WhatsApp?

We want to stay in touch with you, and WhatsApp is the fastest and easiest way to do so. The service is widely used and enables uncomplicated communication with you.

What data is processed by WhatsApp?

When you communicate with us via WhatsApp, various data may be processed:

  • Phone number
  • Name (as stored in WhatsApp)
  • Profile picture
  • Message content (text, photos, videos, voice messages)
  • Metadata (date, time)
  • Location data (if you share it)

Messages between you and us are end-to-end encrypted and therefore cannot be read by WhatsApp itself either.

How long is the data stored?

WhatsApp only stores messages during delivery. Once delivery has succeeded, they are deleted from WhatsApp's servers. On your and our device, the messages remain stored until you or we delete them.

We only store communication data for as long as is necessary to process your inquiry.

Legal Basis

The use of WhatsApp requires your consent, which is given by contacting us via WhatsApp. This consent, under Art. 6(1)(a) GDPR (consent), constitutes the legal basis for the processing of personal data.

In addition, we have a legitimate interest in responding to customer inquiries quickly and efficiently. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interests).

WhatsApp also processes some of your data in the USA. WhatsApp is an active participant in the EU-US Data Privacy Framework, which governs the correct and secure transfer of personal data.

More information about data processing by WhatsApp can be found in the Privacy Policy at https://www.whatsapp.com/privacy


Supplementary Privacy Notices for the "KFZ Übergabe Protokoll" Apps

The following notices supplement the general privacy policy of KRV Transporte und Dienstleistungen e.K. and apply exclusively to the use of our mobile applications "KFZ Übergabe Protokoll start", "KFZ Übergabe Protokoll pro" and "KFZ Übergabe Protokoll plus" (collectively, the "App").

Note: The Apps are offered under the trading name "KRV Mobility Solutions". The legal entity and controller remains KRV Transporte und Dienstleistungen e.K.

Controller for the App

KRV Transporte und Dienstleistungen e.K.
Langforter Str. 19
40764 Langenfeld (Rhineland), Germany
Email: mobility-solutions@krvtd.com

Purpose of Data Processing

The App is used to create digital vehicle handover protocols. Depending on the app variant (start / pro / plus), only the data required for the following purposes is processed:

  • Documenting the vehicle's condition
  • Recording damage, including photos
  • Taking photos of the vehicle and driving licence
  • Recording signatures
  • Creating and storing PDF protocols
  • Managing previously created protocols in the local archive

No automatic transmission to servers or third parties takes place. Data is only shared if the user actively shares a PDF (e.g. via email, messaging app, or cloud service).

Types of Data Processed

Depending on which app variant is used, the following personal data may be processed:

Personal data of the parties involved in the handover:

  • Name of the party handing over the vehicle
  • Name of the party receiving the vehicle
  • Digital signatures
  • Driving licence photo (optional)

Vehicle and protocol data:

  • Licence plate, make, model, VIN
  • Odometer reading
  • Condition (fuel level, tyres, cleanliness, etc.)
  • Accessory details
  • Remarks
  • Date, time, place of handover

Image and photo data:

  • Mandatory photos of the vehicle
  • Damage photos (in pro / plus)
  • Driving licence photos (optional)
  • Timestamp of the photo

Storage of Data

All data is stored exclusively locally on the end device:

  • Android: in the app's data directory
  • iOS: in the app's document directory

There is no cloud synchronisation, no server backup, and no automatic transfer to third parties.

The user can manually delete protocols at any time.

App Permissions

For the App to function, it requires the following system permissions:

  • Camera – for taking photos of the vehicle, damage, and driving licence
  • Storage access – for saving PDFs and photos
  • Internet – solely for technical components (e.g. the PDF preview plugin), without any data transmission to servers

Legal Bases

Processing is based on:

  • Art. 6(1)(b) GDPR – performance of a contract or pre-contractual measures
  • Art. 6(1)(a) GDPR – consent (e.g. photos, signatures)
  • Art. 6(1)(f) GDPR – legitimate interest in proper documentation

The user is responsible for obtaining the consent of any persons photographed or signing.

Disclosure of Data

Data is only shared if the user actively shares a PDF. Responsibility for such sharing lies with the user.

Retention Period

Data remains stored on the device until:

  • it is deleted by the user,
  • the device is reset, or
  • the App is uninstalled.

There is no automatic deletion function.

Data Subject Rights

For all data stored in the App, the rights under the GDPR apply, in particular:

  • Access
  • Rectification
  • Erasure
  • Restriction of processing
  • Data portability
  • Withdrawal of consent
  • Objection

Since the data is stored locally only, these rights must be exercised by the user themselves (e.g. by deleting a protocol).

Security

Data is stored exclusively locally and protected by the security mechanisms of the respective operating system:

  • PIN / password
  • Fingerprint
  • Face ID
  • Device settings

There is no transmission to external systems.


Supplementary Privacy Notices for the "KRV Live-Tracking" App

The following notices supplement the general privacy policy of KRV Transporte und Dienstleistungen e.K. and apply exclusively to the use of the mobile application "KRV Live-Tracking" and the associated web platform at tracking.krvtd.com (collectively, the "App").

Note: The App is offered under the trading name "KRV Mobility Solutions". The legal entity and controller remains KRV Transporte und Dienstleistungen e.K.

Controller for the App

KRV Transporte und Dienstleistungen e.K.
Langforter Str. 19
40764 Langenfeld (Rhineland), Germany
Email: mobility-solutions@krvtd.com

Purpose of Data Processing

The App allows users to share their real-time location via a link. Recipients of the link can follow the location in their browser without installing the App. Data is processed exclusively for the following purposes:

  • Providing the live tracking feature (GPS location data)
  • Managing the user account (email address, name)
  • Billing and management of usage limits (number of tracking sessions per month)
  • Sending email verification and password reset messages

Types of Data Processed

Account data:

  • Name
  • Email address
  • Password (stored encrypted, not in plain text)

GPS and tracking data (only during active tracking):

  • Real-time GPS position (latitude, longitude)
  • Speed
  • Timestamp of position updates
  • Optional destination address and calculated estimated time of arrival (ETA)

Usage statistics:

  • Number of tracking sessions started per month

Storage of Data

All data is stored in Google's Firebase Realtime Database (server location: europe-west1, Belgium). GPS data is transmitted and stored in real time only during an active tracking session. Once a tracking session ends, the position data is marked as inactive. Users can stop tracking data at any time by ending the tracking session.

Account data is stored until the user's account is deleted. Following account deletion, all personal data is irrevocably deleted within 30 days.

App Permissions

For the App to function, it requires the following system permissions:

  • Location (precise, including in the background) – for capturing the GPS position during an active tracking session
  • Internet – to transmit position data to Firebase and to display the map
  • Notifications – to display the active tracking notification in the background (foreground service)
  • Disable battery optimisation – so that tracking runs reliably even when the screen is locked

Background location permission is used exclusively during a tracking session actively started by the user. No background location tracking takes place without an active tracking session.

Disclosure of Data

GPS data is accessible, via the tracking link generated by the user, to anyone the user shares that link with. The user is solely responsible for who they share the tracking link with.

No further disclosure to third parties takes place, with the exception of the following technical service providers:

  • Google Firebase (authentication, database, hosting) – Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. More information: firebase.google.com/support/privacy
  • IONOS SE (email delivery) – Elgendorfer Str. 57, 56410 Montabaur, Germany. More information: ionos.de/terms-gtc/datenschutzerklaerung
  • Google Maps / OpenStreetMap (map display in the web viewer)

Legal Bases

Processing is based on:

  • Art. 6(1)(a) GDPR – consent (GPS tracking, location permission)
  • Art. 6(1)(b) GDPR – performance of a contract (provision of app functions)
  • Art. 6(1)(f) GDPR – legitimate interest (operation and security of the platform)

User Obligations

The user is responsible for ensuring that all persons whose location is shared have expressly consented. Unauthorised tracking of persons without their consent is prohibited and may be a criminal offence.

Data Subject Rights

The data subject rights set out in this privacy policy under the GDPR apply. For requests regarding the deletion of your account or your tracking data, please contact: mobility-solutions@krvtd.com


Supplementary Privacy Notices for the "ApuDrive" App

The following notices supplement the general privacy policy of KRV Transporte und Dienstleistungen e.K. and apply exclusively to the use of the mobile application "ApuDrive" (the "App").

Note: The App is offered under the trading name "KRV Mobility Solutions". The legal entity and controller remains KRV Transporte und Dienstleistungen e.K.

Controller for the App

KRV Transporte und Dienstleistungen e.K.
Kevin Rüchel-Volkmann
Langforter Str. 19
40764 Langenfeld (Rhineland), Germany
Email: kontakt@krvtd.com

Purpose of Data Processing

The App is used for private vehicle management. Only the data required for the following purposes is processed:

  • Managing vehicle data and cost transparency
  • Recording maintenance entries and appointments
  • Creating cost statistics
  • Processing in-app purchases

Types of Data Processed

Account data: email address, password (encrypted), user ID

Vehicle data: make, model, year of manufacture, licence plate, colour, odometer reading, vehicle photo

Cost data: date, amount, category, fuel quantity, fuel price, odometer reading, notes, optional receipt photos

Maintenance data: maintenance type, date, odometer reading, garage, cost, notes, photos, due dates

Usage data: number of free scans used, unlocked in-app purchases

Storage of Data

All data is stored in the Google Firebase Cloud (Firestore Database, server location: europe-west3, Frankfurt). Photos and receipt images are stored in Firebase Storage. Data is accessible only to the respective user and is protected by Firebase Security Rules.

Camera and OCR

The App uses the device camera to scan receipts. Text recognition (OCR) takes place entirely on the device via Google ML Kit — no receipt images are transmitted to external servers. Receipt photos are only stored in Firebase Storage if the user chooses to do so.

In-App Purchases

In-app purchases are processed via RevenueCat (1608 Bush St, San Francisco, CA 94109, USA). RevenueCat processes the purchase ID and purchase status. Payments themselves are processed via the Google Play Store. More information: revenuecat.com/privacy

App Permissions

  • Camera – for scanning receipts
  • Internet – for synchronisation with Firebase and processing in-app purchases
  • Storage – for accessing photos in the gallery

Disclosure of Data

No disclosure to third parties takes place, with the exception of the following technical service providers:

  • Google Firebase (authentication, database, storage) – Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. More information: firebase.google.com/support/privacy
  • RevenueCat (in-app purchases) – 1608 Bush St, San Francisco, CA 94109, USA. More information: revenuecat.com/privacy

Retention Period

Data is stored until the user deletes their account or requests deletion. Deletion requests can be sent to kontakt@krvtd.com.

Legal Bases

  • Art. 6(1)(a) GDPR – consent (camera, receipt photos)
  • Art. 6(1)(b) GDPR – performance of a contract (provision of app functions)
  • Art. 6(1)(f) GDPR – legitimate interest (operation and security)

Supplementary Privacy Notices for the "Meine Arbeitszeit" App

The following notices supplement the general privacy policy of KRV Transporte und Dienstleistungen e.K. and apply exclusively to the use of the mobile application "Meine Arbeitszeit" (the "App").

Note: The App is offered under the trading name "KRV Mobility Solutions". The legal entity and controller remains KRV Transporte und Dienstleistungen e.K.

Controller for the App

KRV Transporte und Dienstleistungen e.K.
Kevin Rüchel-Volkmann
Langforter Str. 19
40764 Langenfeld (Rhineland), Germany
Email: kontakt@krvtd.com

Purpose of Data Processing

The App is used for private time tracking for jobs, clients and projects. Only the data required for the following purposes is processed:

  • Recording and managing working time per project/client
  • Recording absences (sickness, holiday, public holiday)
  • Calculating target/actual hours and overtime balance
  • Creating CSV and PDF reports for personal use or, at the user's request, for sharing with employers/clients
  • Unlocking the unlimited project quota via a one-time in-app purchase

No automatic transmission to servers or third parties takes place. Data (e.g. export files) is only disclosed if the user actively triggers this, for example by sharing a CSV/PDF file via email, messaging app, or cloud service.

Types of Data Processed

Project data: project/client name, colour, target hours per week, break rules, standard working hours, rounding settings

Time tracking data: start/end times, break times, absence type (sick/holiday/public holiday), associated date

Achievements/statistics: unlocked achievements (purely local, with no personal reference beyond the device user)

Purchase data: purchase status of the "unlimited projects" in-app purchase (managed via Google Play, see below)

All of this data is entered by the user themselves; the App does not automatically collect any data in the background (no location, camera, microphone, or contacts).

Storage of Data

All data is stored exclusively locally on the end device in a local database (Room/SQLite). There is no cloud synchronisation, no server backup, and no automatic transfer to third parties. Export files (CSV/PDF) are likewise only generated locally on the device and remain there until the user actively shares or deletes them.

App Permissions

  • Internet – solely for communication with the Google Play Store to process and verify the in-app purchase
  • Storage access – for saving and sharing CSV/PDF exports

The App does not request permissions for location, camera, microphone, or contacts.

In-App Purchases

The one-time in-app purchase to unlock unlimited projects is processed entirely via the Google Play Billing Library. Payment data is processed exclusively by Google; KRV Transporte und Dienstleistungen e.K. only receives information as to whether the purchase was unlocked. No payment data is processed or stored by the App itself.

More information: policies.google.com/privacy

Disclosure of Data

No disclosure to third parties takes place, except for:

  • Google Play (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) – solely to process the in-app purchase
  • disclosure of export files (CSV/PDF) to third parties (e.g. employer, tax advisor) actively initiated by the user themselves

Retention Period

Data remains stored on the device until it is deleted by the user, the device is reset, or the App is uninstalled. There is no automatic deletion function and no server-side data store that would need to be separately deleted.

Legal Bases

  • Art. 6(1)(b) GDPR – performance of a contract (provision of app functions, processing the in-app purchase)
  • Art. 6(1)(f) GDPR – legitimate interest in a functional and secure App

Data Subject Rights

Since all data is stored exclusively locally on the user's device, the rights under the GDPR (access, rectification, erasure, restriction, data portability, objection) must be exercised by the user themselves, e.g. by deleting individual entries in the App or by uninstalling the App. For questions regarding the processing of the in-app purchase, please contact: kontakt@krvtd.com

Security

Data is stored exclusively locally and protected by the security mechanisms of the respective operating system (e.g. device PIN, fingerprint, Face ID). No transmission to external systems takes place, except for communication with Google Play to process the purchase.


Closing Remarks

We hope we have been able to give you the key information about data processing on our website and in our apps.

If you would like to learn more about our data processing, or if you have any questions, please contact:

KRV Transporte und Dienstleistungen e.K.
Kevin Rüchel-Volkmann
Langforter Str. 19
40764 Langenfeld, Germany
Email: kontakt@krvtd.com
Phone: +49 1578 5559857

Version of this privacy policy: 30 August 2026
Last updated: 30 August 2026