•   Levenslange garantie
  •   Geverifieerd door experts
Carly logoKoop nu

Privacy Policy

The protection of personal data and the responsible handling of the information you entrust to us are of great importance to us. We, Carly Solutions GmbH & Co KG, process personal data in accordance with legal regulations, in particular the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

In this Privacy Policy, we inform you about what personal data we process when you visit our website www.mycarly.com, including when you use our community and our repair cost service, and what rights you have regarding the processing of your personal data. In this Privacy Policy, we also inform you about the use of your personal data when you use the Carly OBD adapter (“Carly Adapter”) in connection with services provided by the Carly app (e.g., the diagnostic service, used car check, or the coding function). This applies both if you purchased the Carly Adapter directly from us (B2C) and if you are an end customer of one of our business partners (B2B customer) and the Carly Adapter was provided by our B2B customer.

We therefore ask that you carefully read the following information.

1. Definitions

Personal data refers to any information relating to an identified or identifiable natural person. This includes, for example, your name, address, or email address.

Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.

Data subject means any identified or identifiable natural person whose personal data is processed by the controller.

Controller or “data controller” means the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data.

With regard to the terms used, we also refer to the definitions in Article 4 of the GDPR. The terms used are to be understood as gender-neutral.

2. Data Controller and Contact Information

The data controller within the meaning of the GDPR is:

Carly Solutions GmbH & Co KG Kolpingring 8 82041 Oberhaching Email: interaktion@mycarly.com

3. Data Protection Officer and Contact Information

You can contact our external Data Protection Officer at:

PROLIANCE GmbH Leopoldstr. 21 80802 Munich www.datenschutzexperte.de

Email: datenschutzbeauftragter@datenschutzexperte.de

When contacting the Data Protection Officer, please specify the company to which your inquiry relates. Please refrain from attaching sensitive information, such as a copy of your ID, to your inquiry.

4. Processing of Personal Data

4.1 Scope of Data Processing

4.1.1 Visiting Our Website

When you visit our website, your browser transmits certain data to our web server for technical reasons, as is the case with other websites. This data consists of the following (“server log file information”):

  1. Browser types and versions used,
  2. The operating system used by the accessing system,
  3. The website from which an accessing system reaches our website (so-called referrer),
  4. The subpages of our website accessed via the accessing system,
  5. The date and time of access to the website,
  6. The Internet Protocol address (IP address),
  7. The Internet service provider of the accessing system, and
  8. Other data and information used for security purposes in the event of attacks on our information technology systems.

We analyze this collected data and information statistically. We do not draw any conclusions about you based on the use of this general data and information. The data from the server log files is stored separately from any personal data you provide.

4.1.2 Registration / Login

When you register on our website to use our services, we process registration information for this purpose, specifically your email address and password, as well as details provided during registration, particularly the car brand you drive and the country in which you live (“Registration Information”).

When you log in to our website after registering, we process your email address and password (“login information”).

We also offer you the option to log in using Facebook Login and Google Sign-On to access our services. In this case, additional registration is neither required nor possible.

To log in via Facebook Login, you will be redirected to the Facebook website. There, you can log in with your user credentials. This links your Facebook profile to our service. As a result of this link, Meta Platforms Ireland Limited, Block J, Serpentine Avenue, Dublin 4, Ireland (“Meta”)—depending on your privacy settings—in particular your email address. Of this data, we use only your email address (“Facebook login data”), which is absolutely necessary for registration and login so that we can identify you.

By linking your Facebook profile to our service, Meta receives event data (in particular, information about actions you take on our website, in our app, or in our store, such as visits to our website, installation of our app, and purchases of our products) (“Facebook Event Data”), depending on your privacy settings.

To the extent that we are jointly responsible with Meta for the collection and transfer of your personal data in connection with Facebook Login, we have entered into the Addendum for Controllers with Meta to define the respective responsibilities for fulfilling the obligations under the GDPR, as set forth in the Terms of Use for Meta Business Tools for Facebook Login. The Addendum for Controllers stipulates that we are responsible for providing you with this information regarding the processing of your personal data.

Meta is responsible for enabling you to exercise your rights as data subjects under Articles 15–20 of the GDPR with respect to the personal data stored by Meta pursuant to the joint processing.

For more information on how Meta processes your personal data, including the legal basis on which Meta relies and the options available to you for exercising your rights regarding Meta’s processing of your personal data, please refer to Meta’s Privacy Policy.

To sign in via Google Sign-On, you will be redirected to Google’s website. There, you can sign in with your user credentials. This links your Google profile to our service. As a result of this link, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”), depending on your privacy settings, in particular your email address. Of this data, we use only your email address (“Google login data”), which is absolutely necessary for registration and login so that we can identify you.

By linking your Google profile to our service, Google receives event data (specifically, information about actions you take on our website, in our app, or in our store, such as visits to our website, installation of our app, and purchases of our products) (“Google Event Data”), depending on your privacy settings.

For more information on how Google processes your personal data—including the legal basis on which Google relies and the options available to you for exercising your rights regarding Google’s processing of your personal data—please refer to Google’s Privacy Policy. To protect your personal data, we have entered into a data processing agreement with Google in accordance with Article 28 of the GDPR.

4.1.3 Order Processing

As part of order processing, we collect and process your “Customer Information” (specifically your first and last name, email address, phone number (optional), billing address, and, if different, shipping address, including street, house number, city, zip code, state, and additional address details (optional)), your “payment information” (specifically payment method, payment service provider, transaction details, currency information, and payment terms), as well as “order information” (specifically information regarding the products and services you have ordered and the details you have provided in this context, including quantity, shipping method, and shipping address).

4.1.4 Customer Account

To set up and maintain your ongoing customer account, we process your registration, login, customer, order, and payment information.

4.1.5 User Inquiries

To process your concerns and inquiries via email or through our contact form, we process your email address, name (optional), and the information you provide to us as part of the inquiry (“User Inquiry Information”).

4.1.6 Newsletter and Newsletter Tracking

If you subscribe to our newsletter, in addition to your email address, we process the information you provide to us via the input form used for this purpose, as well as—via a tracking pixel embedded in the newsletter—whether and when you open the newsletter and which links in the email you click on (“Newsletter Information”).

4.1.7 Surveys

If you participate in our online survey, we process your email address and the information you provide (“Survey Information”). If you participate in our customer satisfaction surveys related to our support services, we process your email address and the information you provide (“Customer Satisfaction Information”).

4.1.8 Job Applications

If you apply for a position with us, we process your name, address, email address, resume, cover letter, and any other information you provide to us as part of your application (“Application Information”).

4.1.9 Repair Cost Service

If you use our Repair Cost Service and request that the results of the fault and cost analysis be sent to you via email, we process your email address as well as the information you provide in the form regarding your vehicle, specifically the make, model, fuel type, year of manufacture, and mileage (range), details on short- or long-distance use, as well as the information you provide regarding the symptoms you have observed in your vehicle and the details of your fault and cost analysis (“Repair Cost Service Information”).

4.1.10 Carly Adapter

If you use the Carly Adapter in connection with Carly App services (e.g., the diagnostic service, used car check, or coding function), we process your user data (e.g., name, email address), vehicle data (e.g., vehicle manufacturer, vehicle model, vehicle identification number (“VIN”)) , report metadata (e.g., report type, unique report ID, creation timestamp), and report-specific details (e.g., diagnostic reports, Carcheck categories, battery SOH test, fault codes) (“OBD Information”).

4.1.11 Community

If you use our community, we process your username, email address, posts, and related information such as date and time. (“Community Information”).

4.2 Purpose and Legal Basis for Data Processing

We process your server log file information based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR in order to:

  1. Deliver the content of our website correctly;
  2. Optimize the content of our website;
  3. Ensure the ongoing functionality of our IT systems and the technology behind our website;
  4. Provide law enforcement agencies with the information necessary for criminal prosecution in the event of a cyberattack; and
  5. Enhance data protection and data security within our company to ultimately ensure an optimal level of protection for the personal data we process.

We process your customer, payment, user inquiry, order, repair cost service, OBD, and community information for the following purposes:

  1. To perform the contract with you pursuant to Article 6(1)(b) of the GDPR, including to accept orders, organize their processing and billing, respond to related user inquiries, and offer our services, including the repair cost service, services related to the use of the Carly Adapter and the Carly App (e.g., diagnostic service, used car check, and coding function) and the community. To provide the repair cost service, services related to the use of the Carly Adapter and the Carly App, and the community, we also process your registration and login data to fulfill the contract with you in accordance with Art. 6(1)(b) of the GDPR;
  2. Based on our legitimate business interests pursuant to Article 6(1)(f) of the GDPR, we process your inquiries and concerns; detect and prevent fraud and misuse; verify that content published by users in our community does not violate applicable laws, our Terms of Service, or our Code of Conduct; and improve our services, the user-friendliness and effectiveness of our offerings, to the extent necessary in connection with a merger, acquisition, sale of assets, or insolvency of our company, to the extent necessary to assert, exercise, or defend legal claims or in response to court proceedings within the scope of their judicial activities, and to protect the safety of our users, our own safety, and that of third parties; and
  3. To fulfill our legal obligations pursuant to Article 6(1)(c) of the GDPR, for example, to comply with our commercial and tax record-keeping obligations and, with regard to our community, to fulfill our obligations under the Digital Services Act.

We process your OBD information and your community information based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR for the purposes of quality assurance (QA), verifying the accuracy of diagnoses (diagnostic validation), and systematically further developing our products and services (product improvement), including the training and optimization of algorithms and AI models. Our legitimate interest lies in the continuous improvement and assurance of the functionality and security of our products, services, and AI models.

[We also process your OBD information based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR for the purposes of generating analyses and statistics. To this end, the OBD information is analyzed, typically evaluated in [aggregated and/or pseudonymized form], and linked with other data sources to develop evaluation models, scores, and forecasts. We may market these models as products to third parties. Our legitimate interest lies in the further development and improvement of data-driven services, as well as in the commercial exploitation of the insights gained in the process. In doing so, we do not provide third parties with any analyses that would allow them to link the data to specific individuals or specific vehicles. ]

You have the right to object to this processing at any time on grounds relating to your particular situation.

With your separate consent pursuant to Art. 6(1)(a) of the GDPR:

 1) We store your payment information (in particular, payment method and payment service provider) to facilitate your payment process when you use our products and services in the future;

 2) We process your registration, login, customer, and order information, as well as your Google and Facebook login credentials, to set up and maintain your customer account and to identify you for the use of our services;

 3) We provide your E email address to the shipping provider so that it can inform you about the status of your shipment;

 4) We process customer and order information for marketing purposes to provide you with information that is even better tailored to your needs and to optimize our offers and services;

 5) We collect your Facebook event data and transmit it to Meta to enable the matching of contact information;

 6) We collect your Google event data and transmit it to Google to enable contact information matching;

 7) We process your newsletter information to inform you about our offers via email at regular intervals of one month and to statistically measure the success of our online marketing campaigns. For an email address registered for the first time to receive the newsletter, will receive a confirmation email for legal reasons. This confirmation email serves to verify that you are the owner of the email address that authorized receipt of the newsletter; and

 8) We process your survey information and customer satisfaction information to analyze your user experience and your opinions and preferences regarding our offerings and to improve them.

Unless you have objected, we process your customer information—including that related to our repair cost service and our community—as an existing customer, in particular your email address, based on our legitimate interests pursuant to Art. 6(1)(f), to inform you at regular intervals (once a month) via email about our offerings, to inform you, when using our community, about activities related to your posts (e.g., whether there has been a new response to your question), and to contact you once a month via email to invite you to participate in surveys in order to analyze your user experience, your opinions, and your preferences regarding our services.

If you apply for a job with us, we process your application information to determine whether we can offer you a position. In this case, we process your application information based on Article 6(1)(b) of the GDPR and Section 26(1) of the BDSG for the purpose of carrying out pre-contractual measures in response to your request or for the purpose of deciding whether to establish an employment relationship.

4.3 Processing of OBD Information on Our Own Behalf in a B2B Context

If you are an end customer of a business partner (B2B customer) of ours and the Carly adapter was provided by our B2B customer, we process your OBD information not only as a processor on behalf of our B2B customer but also as an independent controller within the meaning of Article 4(7) of the GDPR for our own purposes, if and to the extent that the respective B2B customer has authorized this. The following information supplements the general notes on the processing of OBD information in this Privacy Policy and is specifically directed at affected end customers of our B2B customers.

  1. Source of the Data

We do not receive your OBD information directly from you, but indirectly through our B2B customers or their technical systems. The categories of data processed include, in particular: Vehicle data (e.g., vehicle manufacturer, vehicle model, vehicle identification number), report metadata (e.g., type of report, unique report ID, timestamp), user data (e.g., name, email address), and report-specific detail data (e.g., diagnostic reports, Carcheck categories, battery SOH tests, error codes).

  1. Purposes and Legal Bases for Processing as a Data Controller

We process your OBD information as a data controller based on our legitimate interests pursuant to Art. 6(1)(f) of the GDPR or, where applicable, based on consent obtained by our B2B customer pursuant to Art. 6(1)( a) of the GDPR for the respective purposes authorized by our B2B customer. These purposes typically include:

  • quality assurance (QA), verification of the accuracy of diagnoses (diagnostic validation), and systematic further development of our products and services (product improvement), including the training and optimization of algorithms and AI models; as well as
  • analysis, aggregation, and enrichment of the data, generally in aggregated and/or pseudonymized form, to create products (e.g., evaluation models, scores, forecasts) that we may distribute to third parties.

Our legitimate interest lies in the continuous improvement and assurance of the functionality and security of our products, services, and AI models, as well as in the commercial exploitation of the insights gained in the process. We do not provide third parties with analyses that would enable them to link the data to specific individuals or specific vehicles.

  1. Role of Our B2B Customers

Our B2B customers are themselves responsible for fulfilling their data protection obligations toward you as the end customer. This includes, in particular, informing you about the transfer of your data to us and, to the extent that our processing is based on consent, obtaining valid consent for our independent processing. There is no joint controllership within the meaning of Article 26 of the GDPR between us and our B2B customers; rather, we each act as independent controllers for our respective processing purposes.

  1. Your Rights as a Data Subject

Even as an end customer of our B2B customers, you are entitled to the data subject rights described in Section 9 of this Privacy Policy with respect to us as the data controller, in particular the right of access (Art. 15 GDPR) , rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and the right to object to processing (Art. 21 GDPR). You have the right to object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) of the GDPR. To exercise your rights, please contact us using the contact information provided in Section 2 of this Privacy Policy.

4.4 Retention Period

The data we collect and process will be deleted as soon as it is no longer necessary for the purposes for which it was collected.

Server log file information is stored for a maximum of seven days for security reasons (e.g., to investigate cases of misuse or fraud) and is deleted thereafter. Data that must be retained for evidentiary purposes is exempt from deletion until the respective incident has been fully resolved.

Provided that no statutory retention obligations preclude deletion, and the assertion, exercise, or defense of legal claims does not require longer storage, we will delete:

 1) your registration, login, customer, payment, and order information when you delete your customer account with us or when we close your customer account due to prolonged inactivity after contacting you;

 2) Your personal data from OBD information no later than [24] months after it is collected;

 3) Your Google and Facebook login and event data after a maximum of 6 months;

 4) Your user inquiry information after 12 months;

 5) We will delete your repair cost service information upon your request, if you delete your customer account with us, or if we close your customer account due to prolonged inactivity after contacting you in advance;

 6) Your newsletter information after 6 months, with the exception of your email address, which we will only delete once you unsubscribe from the newsletter or revoke your consent to receive it;

 7) Your survey information after 6 months;

 8) Your community information or parts thereof if you delete your customer account with us, if you as a user request that your question or answer be deleted from the thread, or if your post violates applicable laws, our Terms and Conditions, or our Code of Conduct; and

 9) Your customer satisfaction information after 12 months.

Retention obligations arise in particular for commercial and tax law reasons. In accordance with legal requirements, data is retained for 6 years pursuant to Section 257(1) of the German Commercial Code (HGB) (e.g., accounting documents) and for 10 years pursuant to Section 147(1) of the German Fiscal Code (AO) (e.g., accounting documents, commercial and business correspondence, and documents relevant for tax purposes).

To the extent that we process your personal data based on your consent, we will delete your personal data if you revoke your consent to the processing of your personal data.

Job application information will be deleted 6 months after a rejection. If you were offered a position as part of the application process, your application information will be stored for the purpose of fulfilling the employment relationship for a period of 3 years following the termination of the employment relationship, unless legal requirements mandate a longer retention period.

4.5 Recipients of Your Information

1) Payment Service Provider

a) Adyen

During the ordering process in our online store, you have the option to select a payment method. Payments are processed by the payment service provider Adyen N.V., Simon Carmiggeltstraat 6-50, 1011 DJ Amsterdam, Netherlands (“Adyen”). For payment processing, we process and transmit your payment information (in particular, payment method and payment service provider) to Adyen to fulfill the contract with you in accordance with Article 6(1)(b) of the GDPR. In addition, we transmit your IP address to Adyen for the purposes of preventing and detecting fraud in accordance with Article 6(1)(f) of the GDPR. We have entered into a data processing agreement with Adyen in accordance with Article 28 of the GDPR to protect your personal data. All data is transmitted in encrypted form. Adyen collects and stores the data and only shares it with the companies involved in the payment process.

b) Klarna

If, during the ordering process, you choose to pay by invoice or via SEPA direct debit / instant bank transfer via Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden (“Klarna”), we will transmit the data required for payment processing to Klarna. Klarna is itself the data controller responsible for processing the personal data that we transmit to Klarna for the purpose of fulfilling the contract with you in accordance with Article 6(1)(b) of the GDPR. The data we automatically transmit to Klarna for your payment transaction includes your name, address, and payment information (in particular, payment method and currency information).

c) PayPal

If you select PayPal as your payment method, we will transfer the data required for payment processing to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (“PayPal”). PayPal is itself the data controller responsible for processing the personal data that we transmit to PayPal for the purpose of fulfilling the contract with you in accordance with Article 6(1)(b) of the GDPR. The data we automatically transmit to PayPal for your payment transaction includes your name, address, and payment information (specifically, payment method and currency information).

2) Shipping, Logistics, and Warehouse Service Providers

a) DHL, Deutsche Post, and Gate56

When you order a product from us, we provide the data necessary for shipping to our shipping and warehouse service providers DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn (“DHL”), Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn (“Deutsche Post”) and Gate56 GmbH, Rudolf-Diesel-Str. 11, 56220 Urmitz ( “Gate56”). These shipping and warehousing service providers are themselves data controllers responsible for processing the personal data that we transmit to them for the purpose of fulfilling the contract with you in accordance with Article 6(1)(b) of the GDPR. The data we transfer to these shipping and warehouse service providers includes, in particular, your name and address, email address, a description of the goods, the quantity, weight, and value of the shipment) . As part of the shipping process, this data may also be transferred to the authorities of the transit or destination country for customs clearance, to issue a tax clearance certificate, or for security checks in accordance with the regulations of the respective country.

b) Shipup

We use the services of Shipup, 47 rue Marcel Dassault, 92100 Boulogne-Billancourt, France (“Shipup”), for data transmission between shipping services. We process and share your personal data—in particular your email address—based on our legitimate interest pursuant to Art. 6(1)(f) of the GDPR, to continuously improve individual features and offerings as well as the user experience, e.g., by providing more relevant notifications regarding the shipping status of orders. We have entered into a data processing agreement with Shipup in accordance with Article 28 of the GDPR to protect your personal data.

3) Cloud Providers

a) AWS

We use the Amazon Web Services (AWS) service provided by Amazon Web Services EMEA Sàrl, Rue Plaetis 5, 2338 Luxembourg, Luxembourg (“AWS”). AWS hosts our website on its servers. The use of Amazon Web Services is based on our legitimate interest in providing our services on this website, in accordance with Article 6(1)(f) of the GDPR. In this context, your personal data—in particular your registration, login, customer, payment, order, community, and repair cost service information—is processed by AWS. We have entered into a data processing agreement with AWS in accordance with Article 28 of the GDPR to protect your personal data. AWS’s security standards are certified according to ISO 27001, SOC 1/2/2, and PCI DSS Level 1.

b) Chargebee

We use the Chargebee platform for contract management and invoicing. The provider is Chargebee Inc., 909 Rose Avenue, Suite 950, North Bethesda, MD 20852, USA (“Chargebee”).

Chargebee is a service that, among other things, collects and manages personal data online for automated invoicing. Upon conclusion of the contract, your customer, payment, and order information is transmitted via an encrypted interface. The data you enter is stored on Chargebee’s servers. Billing occurs automatically at the times specified in the contract. The legal basis for data processing is the performance of the contract with you pursuant to Art. 6(1)(b) of the GDPR. To ensure data processing complies with data protection regulations, we have entered into a data processing agreement with Chargebee pursuant to Art. 28 of the GDPR.

c) OpenAI

We use the OpenAI API services provided by OpenAI Ireland Limited, “The Liffey Trust Centre,” 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland ( “OpenAI”). We process and share your community information with OpenAI—in particular your email address—based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR, in order to verify that content published by users in our community does not violate applicable laws, our Terms of Service, or our Code of Conduct, and thereby also to comply with our obligations under the Digital Services Act. If the OpenAI API detects a potential violation, the matter is forwarded to one of our employees. This employee manually reviews the content in question and then decides on the next steps. We have entered into a data processing agreement with OpenAI in accordance with Article 28 of the GDPR to protect your personal data. We use the OpenAI API without any data storage options.

d) Peaberry Software

Through the Customer.io email tool, we use the services of Peaberry Software Inc. d/b/a Customer.io, 921 SW Washington St, Suite #820, Portland, OR 97205, USA (“Peaberry Software”). To send our newsletter and inform you via email about offers, we process and share your newsletter information, customer information (in particular, your email address) and repair cost service information (in particular, your email address as well as the selected car make, model, and year of manufacture). In addition, to send you the cost and fault analysis in connection with your use of the repair cost service, we process your repair cost service information (in particular, your email address as well as the selected car make, as well as model and year of manufacture) based on Article 6(1)(b) of the GDPR in order to provide our service to you, and we share this information with Peaberry Software for the purpose of sending you the cost and fault analysis. We process and share your community information (in particular your email address) with Peaberry Software based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR to provide you with a positive user experience in our community and to inform you about activities related to your posts in our community (e.g., if someone has responded to your question).

In addition, we process and share newsletter information with Peaberry Software in accordance with Article 6(1)(a) of the GDPR to statistically evaluate how newsletters and promotional emails are opened and used, if you have subscribed to our newsletter. To protect your personal data, we have entered into a data processing agreement with Peaberry Software in accordance with Article 28 of the GDPR.

e) Salesforce

We use the Tableau platform for data visualization and business intelligence provided by Salesforce.com, Inc., Salesforce Tower, 415 Mission Street, 3rd Floor, San Francisco, CA 94105, USA (“Salesforce”) . For the purposes of analysis and user experience improvements, we process your order information based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR. To protect your personal data, we have entered into a data processing agreement with Salesforce in accordance with Article 28 of the GDPR.

f) Sentry

We use the error-tracking tool provided by Functional Software, Inc., d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA (“Sentry”). We process and share your personal data with Sentry—in particular your email address—based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR to ensure the functionality and security of our website and our services. We have entered into a data processing agreement with Sentry pursuant to Article 28 of the GDPR to protect your personal data.

g) Simplesat

We use the services of Duoventures Limited (d/b/a Simplesat), 5/F., Heng Shan Centre, 145 Queen’s Road East, Wanchai, Hong Kong (“Simplesat”) for customer satisfaction surveys related to our support. For this purpose, we process and share your personal data with Simplesat based on your consent pursuant to Article 6(1)(a) of the GDPR; or, if you are an existing customer and have not objected, based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR. To protect your personal data, we have entered into a data processing agreement with Simplesat in accordance with Article 28 of the GDPR.

g) SurveyMonkey

We use the services of SurveyMonkey Europe UC, 2 Shelbourne Buildings, Second Floor, Shelbourne Rd, Ballsbridge, Dublin 4, Ireland (“SurveyMonkey”) for online surveys. For this purpose, we process and share your survey information with SurveyMonkey based on your consent pursuant to Article 6(1)(a) of the GDPR, or—if you are an existing customer and have not objected—based on our legitimate interest pursuant to Article 6(1)( f) of the GDPR. To protect your personal data, we have entered into a data processing agreement with SurveyMonkey in accordance with Article 28 of the GDPR.

h) Twilio

We use the customer service platform Segment provided by Twilio Ireland Limited, 70 Sir John Rogerson’s Quay, Dublin 2, D02 R296, Ireland (“Twilio”).

Based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR to continuously improve individual features, offerings, and the user experience, we process your email address and share it with Twilio. To protect your personal data, we have entered into a data processing agreement with Twilio pursuant to Article 28 of the GDPR.

i) Zendesk, Inc.

We use the Zendesk CRM system to process user inquiries. The provider is Zendesk, Inc., 1019 Market Street, San Francisco, CA 94103, USA (“Zendesk”) . We process your personal data—in particular your customer, payment, customer inquiry, and order information—using Zendesk based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR to handle your inquiries and to fulfill our contractual obligations pursuant to Article 6(1)(b) of the GDPR, enabling us to process orders quickly and efficiently. We have entered into a data processing agreement with Zendesk in accordance with Article 28 of the GDPR to protect your personal data.

5. International Data Transfers

In connection with the services used by Chargebee, Peaberry Software, Salesforce, Sentry, and Zendesk, and in the case of the services used by AWS, Google, Meta, SurveyMonkey, and Twilio, your personal data may be transferred to locations in the United States. The aforementioned companies participate in the EU-US Data Privacy Framework and maintain active certification under it. The European Commission has determined in an adequacy decision that personal data transferred to companies participating in the EU-US Data Privacy Framework is adequately protected. As a result of this decision, personal data from the European Economic Area (“EEA”) may be transferred to this third country without the need for additional safeguards. In other words, data transfers to these companies are treated the same as data transfers within the EU.

We have also entered into appropriate safeguards in the form of standard contractual clauses with PayPal and SimpleSat to ensure the security of your data, insofar as it is transferred—in the case of PayPal, to locations in the United States, and in the case of SimpleSat, to Hong Kong.

6. Cookies

When you visit our website, information may be stored on your device in the form of cookies. Cookies are small text files that are sent from a web server to your browser and stored on your device. When you visit our website again, the cookies are transmitted back to our web server. This allows us, for example, to recognize you when you return to our site. Cookies can be divided into so-called “first-party cookies” (used by us) and so-called “third-party cookies” (used by third parties). Generally, cookies can be divided into three categories, namely

  • Category 1: Technically necessary cookies, which are absolutely essential for ensuring the technical functionality of the website,
  • Category 2: Functional cookies, which serve to create the most pleasant browsing experience possible and to optimize the website, and
  • Category 3: Tracking and advertising cookies (so-called marketing cookies), which are used to analyze user behavior on the website and thereby enable interest-based advertising.

The legal basis for the use of Category 1 cookies is our legitimate interest in providing and ensuring the technical functionality of our website, repair services, and community pursuant to Art. 6(1)(f) of the GDPR and § 25(2) of the Telecommunications, Digital Services, and Data Protection Act (“TDDDG”). The legal basis for the use of Category 2 and 3 cookies is your consent provided via the cookie management tool on our website, in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.

Detailed information about the individual cookies used on our website www.mycarly.com and information regarding the associated processing of your personal data can be found in our cookie management tool on our website.

To configure, request, or delete your consent settings, please click the “Cookies” button at the bottom of our website’s homepage.

7. Data Security

We implement state-of-the-art technical, contractual, and organizational measures to ensure the security of data processing. In doing so, we ensure compliance with data protection laws, in particular the GDPR, and that the data we process is protected against destruction, loss, alteration, and unauthorized access.

8. Automated Decision-Making.

We do not engage in automated decision-making as defined in Article 22 of the GDPR.

9. Your Rights as a Data Subject

As a data subject, you have the right to obtain confirmation as to whether we are processing personal data concerning you and, if so, the right to access the personal data concerning you and to receive a copy of such data (Art. 15, paras. 1 and 3 of the GDPR).

If we process inaccurate personal data, you have the right to rectification (Art. 16 of the GDPR).

In certain cases provided for by law, you may request the erasure of personal data concerning you or the restriction of processing (Art. 17 and 18 GDPR).

If the processing is based on your consent within the meaning of Art. 6(1)(a) GDPR, you may withdraw your consent at any time (Art. 7(3) GDPR) , without affecting the lawfulness of the processing carried out on the basis of your consent prior to its withdrawal. We will inform you separately if we require your consent to process your personal data for specific, explicit, and legitimate purposes not covered by this Privacy Notice.

If the processing is based on your consent within the meaning of Article 6(1)(a) of the GDPR or on a contract pursuant to Article 6(1)(b)

GDPR and is carried out by automated means, you have the right to receive the personal data concerning you in a structured, commonly used, and machine-readable format, and the right to transmit this data to another controller without hindrance from the controller to whom the personal data was provided (Article 20 of the GDPR).

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you based on Article 6(1)(e) or (f) of the GDPR (Article 21(1) of the GDPR). You may object at any time to the processing of your personal data based on Article 6(1)(f) GDPR for the purposes of direct marketing (Art. 21(2) GDPR) at any time, without having to provide reasons related to your specific situation.

You also have the right to lodge a complaint with the competent data protection supervisory authority. For example, you may contact the supervisory authority in the EU Member State where you have your habitual residence or workplace, or where the alleged infringement occurred. The data protection supervisory authority responsible for us is the Bavarian State Commissioner for Data Protection and Freedom of Information.

If you wish to exercise your rights, please contact us using the contact information provided in Section 2 of this Privacy Policy.

10. Changes to This Privacy Policy

New legal requirements, business decisions, or technical developments may lead to changes in this notice and require us to update this Privacy Notice accordingly. You can find the most current version on our website. Please note that external links to third-party websites or their contact information may change over time. If you find any information that is no longer up to date, please let us know.