Ta wersja jest tłumaczeniem udostępnionym w celach informacyjnych. Prawnie wiążąca jest wersja niemiecka.
Privacy Policy
Last updated: 29 July 2026
The protection of personal data is important to us. This privacy policy informs you about which personal data we process, for which purposes, on which legal basis, how long we store it, and which rights you have.
This policy addresses three groups of people. Please read the sections relevant to you:
- Section A — visitors to our website,
- Section B — customers with an account on the RUBINLAKE platform,
- Section C — persons whose profession-related data is contained in our database without them using our services (information pursuant to Art. 14 GDPR).
With regard to the terms used, such as "processing" or "controller", we refer to the definitions in Art. 4 GDPR.
Controller and contact
The controller within the meaning of the GDPR for the processing described in this policy is:
RUBINLAKE GmbH Bettinastraße 62 D-60325 Frankfurt am Main, Germany Email: contact@rubinlake.com
Data protection officer: Ralitsa Popova, reachable at the postal address above (attn. "Data Protection") and by email at contact@rubinlake.com.
You can contact us at any time with any questions about data protection and to exercise your rights (see "Your rights" below) — even if you do not have an account with us.
Section A — Visiting our website
Server log data
When you access our website, your browser automatically transmits certain data to the delivering server, in particular:
- date and time of access,
- the page or file accessed,
- IP address,
- browser type and version, operating system,
- the previously visited page (referrer),
- volume of data transferred and access status.
This data is technically required to deliver the website and to ensure its stability and security (e.g. to defend against attacks and analyse errors). The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the secure and stable operation of the website. Log data is stored only briefly and is generally deleted within 30 days at the latest, unless a security-relevant incident requires longer retention.
We use a hosting provider to operate the website, which processes the aforementioned data on our behalf on the basis of a data processing agreement. Where processing takes place outside the EU or EEA, it is based on the safeguards described in the section "Transfers to third countries".
Consent management
To obtain and manage consent for services requiring consent, we use the consent management platform Usercentrics (Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany). This involves processing your consent decisions, the time of the decision, and technical data (e.g. truncated IP address, browser information) in order to be able to demonstrate granted and refused consent.
The legal basis is Art. 6(1)(c) GDPR (obligation to demonstrate consent under Art. 7(1) GDPR) and Section 25(2) no. 2 of the German TDDDG for the technically required storage of your decision. You can change your consent settings at any time via the fingerprint or settings icon on our website.
Cookies and similar technologies
We use cookies and comparable technologies (e.g. local storage) on our website in two cases only:
- Technically required: storage that is strictly necessary to provide the function you requested — such as your language preference and your consent decision. The legal basis is Section 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(f) GDPR.
- Consent-based: all other purposes, in particular audience measurement (see "Google Analytics 4"). The legal basis is Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. Without your consent, these services are not loaded.
Google Analytics 4
If you have consented, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google Analytics uses cookies and similar technologies to evaluate the use of our website (e.g. pages visited, session duration, approximate region of origin, device used).
We have configured Google Analytics in a privacy-friendly manner: collection is disabled by default and is only activated after your consent (Consent Mode); IP addresses are processed in truncated form. The legal basis is exclusively your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can withdraw your consent at any time with effect for the future via the consent settings.
In the course of using Google Analytics, data may be transferred to servers of Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework; EU standard contractual clauses are additionally in place. Further information can be found in Google's privacy policy: https://policies.google.com/privacy
Videos (YouTube)
In individual help articles in our Help Center, we embed videos from the YouTube service (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). When you access a page with an embedded video, a connection to YouTube's servers is established; YouTube thereby receives your IP address and information about the page accessed. If you are logged into your Google account at the same time, Google may attribute the access to your account; you can prevent this by logging out beforehand.
The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in explaining our services clearly through video content. Further information: https://policies.google.com/privacy
Appointment booking (Calendly)
For scheduling demo and consultation appointments, we link to the scheduling service Calendly (Calendly LLC, Atlanta, USA). The link itself does not transfer any data. Only when you open the Calendly page and book an appointment there does Calendly process the data you enter (e.g. name, email address, chosen time slot); we receive this data to conduct the appointment. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures at your request). Calendly LLC is certified under the EU-US Data Privacy Framework. Further information: https://calendly.com/privacy
Contact by email
Our website does not contain contact forms. If you contact us by email, we process the data you provide (email address, content of your message) to handle your enquiry. The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to a contract or its initiation, and otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). We delete the correspondence as soon as it is no longer required for processing and no statutory retention obligations apply.
Links to social networks
Our website does not embed plugins or other active content from social networks. References to our profiles on social networks are simple links; no data is transferred to the respective providers when you visit our website.
Section B — Using the RUBINLAKE platform
This section applies additionally if you create an account on the RUBINLAKE platform and use our services.
Registration and account
When you register and use your account, we process the data you provide, in particular your name, business email address, organisation, and login credentials. For secure sign-in (including single sign-on), we use a specialised authentication service provider as a processor. The legal basis is Art. 6(1)(b) GDPR (performance of the contract).
Subscription and payment
Payment processing is handled by the payment service provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland). Stripe processes your payment and billing data (e.g. name, billing address, VAT identification number, payment method) as an independent controller; we do not receive your full payment details (e.g. card numbers). In the course of payment processing, data may be transferred to Stripe Inc. in the USA; Stripe Inc. is certified under the EU-US Data Privacy Framework. The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR (commercial and tax law obligations). Further information: https://stripe.com/privacy
Platform usage data
We process information about how you use the platform (e.g. actions performed, features accessed, timestamps) in order to provide our services, handle billing (e.g. consumption of quotas), ensure security, prevent misuse, and improve our services. The legal basis is Art. 6(1)(b) GDPR, and otherwise Art. 6(1)(f) GDPR (legitimate interest in security and further development).
AI-supported features
The platform includes AI-supported features, in particular an assistant that lets you work in natural language. Your inputs and the associated responses are stored in your account so that you can continue and review conversations.
To provide these features, we use carefully selected AI model providers and service providers for quality assurance and error analysis as processors, some of which are based in the USA (for safeguards, see "Transfers to third countries"). Your inputs are not used by these service providers to train their own or third-party AI models. Certain processing steps of our browser extension also take place locally on your device, without the relevant content being transferred to servers for this purpose.
The legal basis is Art. 6(1)(b) GDPR (provision of the contractually agreed features) and Art. 6(1)(f) GDPR (legitimate interest in quality assurance and error analysis).
Transactional messages
To provide the service, we send account- and contract-related messages (e.g. confirmations, security notices, invoices) by email and, where applicable, by SMS. We use dispatch service providers as processors for this purpose. The legal basis is Art. 6(1)(b) GDPR.
Export to CRM systems
You can transfer data from the platform to third-party systems of your choice, in particular CRM systems such as HubSpot or Pipedrive. The transfer takes place exclusively at your instigation. Your company is solely responsible, as an independent controller, for the processing of the data in the target system; the privacy provisions of the respective provider apply. The legal basis for the transfer by us is Art. 6(1)(b) GDPR.
Section C — Information for persons in our database (Art. 14 GDPR)
RUBINLAKE operates a database of profession-related information about companies and their contact persons, which our customers use for sales and recruiting purposes in business-to-business (B2B) contexts. This section informs you pursuant to Art. 14 GDPR if data about you is contained in this database without us having collected it from you. Since individually notifying all data subjects would involve disproportionate effort (Art. 14(5)(b) GDPR), we make this information publicly available here.
Categories of data processed
- master data (e.g. name),
- profession-related information (e.g. current employer, position, career history, qualifications and skills),
- business contact details (e.g. business email address, business phone number),
- company information (e.g. industry, size, location),
- profession-related estimates derived from the above (e.g. career level, estimated experience or salary ranges), which are labelled as such.
We do not process special categories of personal data within the meaning of Art. 9 GDPR and no data from the private sphere (e.g. private addresses are not offered).
Sources
The data originates from publicly accessible sources (in particular company websites, commercial and company registers, press publications, and publicly viewable professional profiles) and from licensed data partners who contractually warrant to us that they collected the data lawfully.
Purposes and legal basis
We process this data to enable our customers to identify and contact relevant business contacts (business initiation in the B2B sector, sales, recruiting) and to ensure data quality (validation, updating, duplicate matching).
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest, and that of our customers, lies in initiating business contacts in a professional context. We exclusively process profession-related data concerning data subjects in their business role; the impact on their private sphere is thereby limited. A documented balancing of interests exists and its essential considerations can be requested from us.
Recipients
Recipients of the data are our customers — companies that use the data under their own data protection responsibility for their B2B sales and recruiting processes — as well as the categories of processors described in this policy (hosting, data validation and enrichment, AI features). Our customers are contractually obliged to use the data only in compliance with applicable data protection and competition law.
Storage period
We review and update the database on an ongoing basis. Records that prove to be outdated or no longer relevant are corrected or deleted. In the event of an objection (see below), we permanently exclude the data concerned from processing.
No automated decision-making
There is no automated decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you. The platform provides information; decisions (e.g. whether to make contact) are made exclusively by people at our customers.
Your right to object (Art. 21 GDPR)
You can object to the processing of your data at any time — informally, free of charge, and without stating reasons — by email to contact@rubinlake.com or by post to the address above. No account is required. After an objection, we no longer process your data for the stated purposes and use a suppression list to ensure that it is not re-added. In addition, you are entitled to all the rights set out in the section "Your rights", in particular the right of access.
Transfers to third countries
Some of the service providers we use are based in the USA or process data in other countries outside the EU or EEA. In these cases, transfers only take place if appropriate safeguards under Chapter V GDPR are in place:
- certification of the recipient under the EU-US Data Privacy Framework (adequacy decision of the EU Commission pursuant to Art. 45 GDPR), and/or
- the conclusion of EU standard contractual clauses (Art. 46(2)(c) GDPR), supplemented by additional technical and organisational measures where necessary.
Categories of recipients with third-country relevance include, in particular: hosting and infrastructure providers, AI model providers, data validation and enrichment providers, payment, authentication and dispatch service providers, and analytics and appointment scheduling services. On request, we will inform you of the specific safeguards in place for the processing concerning you.
Storage period
Unless otherwise stated above, we store personal data only for as long as is necessary for the stated purposes. The following criteria apply in detail:
- Account data: for the duration of the contractual relationship; after the contract ends, it is deleted unless statutory retention obligations apply.
- Billing and accounting records: in accordance with commercial and tax law retention periods (Section 257 of the German Commercial Code (HGB), Section 147 of the German Fiscal Code (AO)) for up to ten years; during this period, processing is restricted to fulfilling these obligations (Art. 6(1)(c) GDPR).
- Server log data: generally up to 30 days (see Section A).
- Conversations with AI features: for the duration of the contractual relationship, unless you delete them earlier.
- Database records (Section C): continuous updating; deletion or permanent suppression in the event of an objection or established lack of relevance.
Data security
We transfer data between your browser and our systems exclusively in encrypted form (TLS) and take technical and organisational measures pursuant to Art. 32 GDPR to protect personal data against loss, misuse, and unauthorised access. Access to personal data within our company is restricted to the persons who need it to perform their tasks.
Your rights
As a data subject, you have the following rights:
- access to the data we process about you (Art. 15 GDPR),
- rectification of inaccurate or incomplete data (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR),
- withdrawal of granted consent with effect for the future (Art. 7(3) GDPR); the lawfulness of processing carried out before the withdrawal remains unaffected.
An informal message to contact@rubinlake.com or to our postal address is sufficient to exercise these rights.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement. The supervisory authority responsible for us is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit Gustav-Stresemann-Ring 1 65189 Wiesbaden, Germany https://datenschutz.hessen.de
Obligation to provide data
There is no obligation to provide personal data when using the website. For the conclusion and performance of a contract concerning the RUBINLAKE platform, the provision of certain data (e.g. name, email address, billing data) is required; without this data, we cannot conclude or perform the contract.
Changes to this privacy policy
We amend this privacy policy when our services or legal requirements change. The version published on this page applies; the date of the last change can be found under "Last updated" above. In the event of significant changes affecting your account, we will additionally inform you by email or within the platform.