The following notice provides an overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally.
Controller
The controller for this website is
AuthoriseMe GmbH Austraße 34 35745 Herborn Germany
- Phone
- +49 2772 57 59 100
- info(at)authoriseme.eu
- Managing Director
- Raffael A. Fruscio
Contact details of the data protection officer (Art. 13 (1) (b) GDPR)
We have appointed a data protection officer. You can reach them at
data.de(at)raan-group.com
How do we collect your data and what do we use it for?
Your data is collected when you provide it to us, e.g. when you send us an email or commission our services. All data transmitted to us, including any personal data resulting from it (e.g. name, email address etc.), is stored and processed by us for the purpose of handling your request or providing our services. If you do not provide us with this data, we cannot process your request or provide our services. This data is processed on the basis of Art. 6 (1) (b) or (c) GDPR if your request is connected to the performance of a contract or is necessary to carry out pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of the requests addressed to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR), where this has been requested. Consent can be withdrawn at any time. Further data is collected automatically when you visit the website by means of our IT systems. This is primarily technical data such as the internet browser used, the operating system or the time of the page request etc. This data is required to ensure the error-free display of the website. If we cannot collect this data, we cannot display the website. This data is collected on the basis of Art. 6 (1) (f) GDPR.
Data processing within the Raan Group
AuthoriseMe GmbH is part of the Raan Group. The companies within the group work closely together on internal organisation, sales and marketing. Specialised companies or divisions of our group of companies carry out certain data processing tasks centrally for the affiliated companies in the group. In addition, certain data processing operations are carried out in centralised IT systems. Insofar as a contract exists between you or your company and one or more companies of our group, your data may be processed centrally by one company of the group or jointly by the companies, for example for the central management of customer data, telephone customer service, contract processing, billing purposes as well as collection and disbursement, for direct marketing purposes or for joint mail processing. To safeguard your rights and in consideration of the requirements of the EU General Data Protection Regulation (GDPR), we have concluded an agreement that establishes rules on the processing of your personal data. As so-called joint controllers (under Art. 26 GDPR), we are jointly responsible for the processing of your data. With regard to the processing of your data, you can contact each participating company individually and assert your rights. Further information on data protection and the handling of personal data can be found in the privacy notices of the respective affiliated companies.
Storage period
Your data is stored until the purpose for storing the data no longer applies, you withdraw your consent to storage, or you request us to delete it. Mandatory statutory provisions, in particular statutory retention periods, remain unaffected by this.
What are your rights?
On the basis of Articles 15–20 GDPR, you have the following rights regarding the processing of personal data:
- You have the right at any time to receive information free of charge about the origin, recipients and purpose of the data stored about you (Art. 15 GDPR).
- In the event of the processing of incorrect personal data, you have the right to rectification (Art. 16 GDPR).
- Where the statutory requirements are met, you can request the erasure or restriction of processing and object to the processing (Art. 17, 18 and 21 GDPR).
- If you have provided the data and the data processing is carried out by automated means, you have the right to data portability (Art. 20 GDPR).
- Furthermore, you have the right to lodge a complaint with a supervisory authority.
Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)
If data processing is based on Art. 6 (1) (e) or (f) GDPR, you have the right at any time to object, on grounds relating to your particular situation, to the processing of your personal data; this also applies to profiling based on these provisions. You can find the respective legal basis on which processing is based in this privacy notice. If you object, we will no longer process your affected personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims (objection pursuant to Art. 21 (1) GDPR). If your personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing. If you object, your personal data will subsequently no longer be used for the purpose of direct marketing (objection pursuant to Art. 21 (2) GDPR).
Profiling
We do not carry out any profiling or automated decision-making.
Cookies
We use technically necessary or functional cookies and — only with your consent — cookies for analytics and marketing purposes. Technically necessary or functional cookies: • Session/login cookie: maintains your session after login, recognises you and ensures the security of the platform. • Cart cookie: stores the identifier of your cart during the ordering process. • Language cookie: remembers the display language you have chosen. • Short-lived notice cookie: displays one-off status messages after an action and is deleted immediately afterwards. • Short-lived order cookie: passes the key figures of a completed order to the confirmation page once and is deleted as soon as that page is opened. • Referral cookie (bv_ref): If you reach the platform via a referral link from one of our partners, we store the associated referral code for up to 30 days in order to grant you the discount linked to that link on a later order. The code is only stored if it belongs to a partner known to and active with us. • Consent cookie: stores your decision about the cookies that require consent, so that we do not have to ask you again on every visit. These cookies are processed on the basis of our legitimate interest in the secure and functional operation of the platform (Art. 6 (1) (f) GDPR) or on Section 25 (2) TDDDG, as the storage is strictly necessary to provide the service expressly requested by you. Cookies for analytics and marketing purposes are used only after you have agreed in the consent banner. Without your consent these services are not loaded. Details are set out in the following section.
Hosting
This platform is hosted by an external service provider (hereinafter referred to as the "host"). The personal data collected on this platform is stored on the host's infrastructure. This may include IP addresses, contact requests, meta and communication data, contract data, contact data, names, platform access and other data generated via the platform. The host is used for the purpose of fulfilling the contract with our potential and existing customers (Art. 6 (1) (b) GDPR) and in the interest of a secure, fast and efficient provision of our online offering by a professional provider (Art. 6 (1) (f) GDPR). We have concluded the legally required data processing agreement with the host.
We use the following host:
Google Cloud (Google Cloud Platform)
Services in the field of providing information technology infrastructure and related services (e.g. compute, storage and database capacity as well as object storage). Service provider for customers in the European Economic Area: Google Cloud EMEA Limited, Velasco, Clanwilliam Place, Dublin 2, Ireland. Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR), performance of a contract (Art. 6 (1) (b) GDPR). Privacy policy: https://cloud.google.com/terms/cloud-privacy-notice. Data processing agreement: https://cloud.google.com/terms/data-processing-addendum.
Hosting and data storage take place in a data centre in Frankfurt am Main (region europe-west3) within the European Union. Delivery is handled via Google's global network; the routing and connection handling of the data may technically also take place via non-European (including US) servers. In addition, Google LLC, a US company, is involved as a sub-processor, so that a transfer of data to the USA cannot be entirely ruled out. Google LLC holds a certification under the "EU-US Data Privacy Framework" (DPF), which is intended to ensure compliance with European data protection standards for data processing in the USA; in addition, standard contractual clauses pursuant to Art. 46 GDPR are in place.
Payment processing
As part of contract fulfilment, we offer a secure payment option via a payment service provider. The payment data you enter is processed and stored solely by the payment service provider; we do not receive any account or credit card data, only confirmation or notice of the payment. We have concluded the legally required data processing agreement with the provider.
We use the following payment service provider:
Stripe
Payment service provider (technical integration of online payment methods). Service provider: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA. Legal basis: performance of a contract (Art. 6 (1) (b) GDPR). Privacy policy: https://stripe.com/en-de/privacy. Basis for third-country transfers: EEA – Data Privacy Framework (DPF).
Email delivery
We use an external service provider to send transactional emails (e.g. account activation, invoices, notifications). The provider processes the recipient data (email address, name) solely on our behalf to deliver these emails. We have concluded the legally required data processing agreement with the provider.
We use the following service provider:
Brevo (Sendinblue GmbH)
Services in the field of transactional email delivery. Service provider: Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany (part of Brevo SAS, 106 Boulevard Haussmann, 75008 Paris, France). Legal bases: performance of a contract (Art. 6 (1) (b) GDPR), legitimate interests (Art. 6 (1) (f) GDPR). Privacy policy: https://www.brevo.com/legal/privacypolicy/.
Reach measurement and advertising
With your consent we use services for reach measurement and for measuring the success of our advertising campaigns. These record which pages you open, which steps of the ordering process you reach, and which campaign or referral link brought you to us. If an order is placed we additionally transmit the order number, the order value and the countries booked. Your email address is not transmitted, neither in plain text nor in hashed form. The legal basis is exclusively your consent under Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG. You may withdraw your consent at any time with effect for the future by opening the cookie settings again via the corresponding link and changing your selection. The lawfulness of processing carried out until withdrawal remains unaffected. If you do not give consent, or withdraw it, these services are not loaded; using the platform remains fully possible regardless.
We use the following services:
Cookiebot
In addition to the cookies required for technical purposes, we also use cookies and external services to optimize our platform and our offerings. To do this, we need your consent, which we obtain and store with the help of Cookiebot technology in accordance with the legal requirements. When you access our platform, a cookie from the provider Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark, is therefore stored in your browser, in which the consent you have given or the revocation of consent is stored. Once consent has been given, it can be revoked at any time. The data collected will be stored until you ask us to delete it, or you delete the Cookiebot cookie yourself, or the purpose for data processing no longer applies. You can make changes at any time via the cookie settings button.
We use various Google services. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google is certified in accordance with the EU-US Data Privacy Framework (DPF); see the notice below regarding the transfer of data to US companies certified under the DPF.
Google Analytics
This platform uses functions of the web analysis service Google Analytics. Google Analytics enables us to analyse the behaviour of visitors. We receive various usage data, such as page views, length of visit, operating systems used and origin of the user. This data is summarised in a user ID and assigned to the respective end device. Google Analytics also uses various modelling approaches to supplement the recorded data records and uses machine learning technologies for data analysis. Google Analytics uses technologies that enable the recognition of the user for the purpose of analysing user behaviour (e.g. cookies or device fingerprinting). The information collected by Google about the use of this platform is generally transmitted to a Google server in the USA and stored there. The use of this service is based on your consent in accordance with Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG. Consent can be revoked at any time.
Google Ads
Google Ads enables us to display adverts in the Google search engine or on third-party websites when the user enters certain search terms in Google (keyword targeting). Furthermore, targeted adverts can be displayed based on the user data available at Google (e.g. location data and interests) (target group targeting). As the operator, we can evaluate this data quantitatively by analysing, for example, which search terms led to the display of our advertisements and how many advertisements led to corresponding clicks. The use of this service is based on your consent in accordance with Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG. Consent can be revoked at any time.
Notice regarding the transfer of data to US companies certified under the DPF
Some companies to which we transfer data are certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA that is intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link:
https://www.dataprivacyframework.gov/participant/5780Error monitoring
To detect and fix technical errors, we use an external error-monitoring service. If an error occurs in the application, a technical error report (e.g. error message, affected code location, browser or device type, timestamp) is transmitted to the service provider. Personal data is filtered out before transmission (PII scrubbing). No tracing, no session recording and no setting of cookies takes place. The processing serves exclusively the stability and security of the platform and is based on our legitimate interest in error-free operation (Art. 6 (1) (f) GDPR). We have concluded the legally required data processing agreement with the service provider.
We use the following service provider:
Sentry
Service for monitoring and analysing application errors. Provider: Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. Data processing takes place in a data-centre region within the European Union. Legal basis: legitimate interests (Art. 6 (1) (f) GDPR). Privacy policy: https://sentry.io/privacy/. Basis for any third-country transfers: standard contractual clauses pursuant to Art. 46 GDPR.
Notarial certification of the power of attorney
In some of the countries you select, a certified and, where applicable, apostilled power of attorney is required for the power of attorney to be legally valid. For online certification you can use a partner service and its partner notaries. In this case, the data required for the certification (in particular name, contact details and the power-of-attorney document) is transmitted to the partner service. Alternatively, you can have the certification carried out independently by a notary of your choice; in that case no data is transmitted to the partner service. We have concluded the legally required data processing agreement with the service provider.
We use the following service provider:
Platus / beglaubigt.de
Service for the online certification of documents via partner notaries. The online certification is carried out via https://app.beglaubigt.de. Legal basis: performance of a contract (Art. 6 (1) (b) GDPR). Partner's terms and conditions: https://platus.com/agb.
Last updated: July 2026