Privacy Policy
This Privacy Policy explains how BetStup UG (haftungsbeschränkt) processes your personal data in accordance with the General Data Protection Regulation (GDPR).
Data Protection Information
Transparency and responsible handling of data are central components of our work. In this privacy policy, you will learn which data we process and for what purposes this is done.
This version is translated from the German version. In case of any discrepancies between this English translation and the original German version, the German version shall apply.
1. Controller Responsible for Data Processing
The data controller in the sense of the GDPR is:
BetStup UG (haftungsbeschränkt)
(hereinafter referred to as "BetStup")
Bahnhofstraße 74
32257 Bünde
Germany
Email: [email protected]
2. Scope of This Privacy Policy
This Privacy Policy applies to BetStup's corporate and agency website and to the personal data we process via this website and in connection with general inquiries, sales inquiries, quotation processes, and agency-related contractual relationships.
Separate privacy policies and contractual terms generally apply to BetStup's standalone software products, SaaS applications, customer portals, or other digital services. Where applicable, those product-specific policies take precedence over the general information on this page.
To the extent that we process personal data exclusively on behalf of our agency clients, for example in connection with development, hosting, support, or operational services for client projects, such processing is generally carried out as processing on behalf under Art. 28 GDPR on the basis of the agreements concluded with the respective client.
Typical Categories of Data
- Access and log data when visiting the website
- Master data and contact data in connection with inquiries and business relationships
- Communication content
- Contract, billing, and payment data
- Usage and account data to the extent you use our own digital offerings
3. Visiting Our Website
When you access our website, technically necessary information is automatically transmitted by your browser to the web server. This includes in particular:
- IP address
- date and time of access
- the page called up or file requested
- referrer URL
- browser type, browser version, and operating system
Processing is carried out to provide the website, ensure stability and security, and prevent misuse. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and functional operation of our online offering.
Server log data is stored only as long as necessary for secure operation and error analysis. As a rule, deletion takes place after a few days and no later than within 30 days, unless longer storage is exceptionally required for evidentiary or security purposes.
4. Contact and Communication
If you contact us by email or by other means, we process your information for the purpose of handling the inquiry and related communication. This generally includes your name, contact details, company affiliation, and the content of your message.
The legal basis is Art. 6(1)(b) GDPR insofar as your inquiry is aimed at the conclusion or performance of a contract or concerns pre-contractual measures. In all other cases, we process your data on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the proper handling of business inquiries.
Where we provide a contact, initial consultation, or inquiry form on this website and you use it, we process the data entered there for the purpose of handling your inquiry. This may include company name, name, email address, telephone number, and message content. If an external provider is used for the technical operation of the form, this is done on the basis of a data processing agreement under Art. 28 GDPR.
Unless statutory retention obligations prevent this, we delete communication data as soon as the inquiry has been fully processed and no further business relationship exists.
4a. Inquiries via the Initial Consultation Funnel and the Digital Check
On the “Free Initial Consultation” page we provide a multi-step inquiry process instead of a classic contact form. You first answer five questions about your project and only provide your contact details in the final step. Your entries are transmitted to us only when you submit that final step.
On the “Digital Check” page you likewise answer five questions and immediately receive an assessment on screen of which digital step makes sense first for your company. That evaluation happens entirely in your browser and requires no contact details; without the form that follows, we learn nothing about your answers. Only if you then request the detailed written assessment are your contact details transmitted to us, together with your five answers, the result determined, and — if you give it — your feedback on whether that result fits.
The following applies equally to both forms; they are transmitted by the same technical route and processed in the same system.
Data processed
- Mandatory: first and last name, email address, and your consent to this privacy policy
- Voluntary: telephone number, company, and your message
- Project details (initial consultation funnel): the services you are interested in, project stage, company size, budget range, and desired timeframe
- Project details (digital check): your biggest current challenge, how you win customers, the state of your website, how much of your work is manual, and company size, along with the result determined from them
- Technical metadata: time of submission, page visited, language version, time taken, country of origin as determined by Cloudflare, and browser identifier (user agent)
- Origin data: campaign parameters (e.g. utm_source) and referring page, where present — see section 9
The legal basis for processing your inquiry is Art. 6(1)(b) GDPR, as the inquiry concerns pre-contractual measures, supplemented by your consent under Art. 6(1)(a) GDPR, which you give explicitly when submitting. You may withdraw your consent at any time with effect for the future at [email protected].
Prioritisation of your inquiry
From your answers we automatically calculate a score that helps us sort inquiries and respond more appropriately. In the digital check, the same answers additionally determine the recommendation shown to you. Both values serve solely for internal prioritisation and preparation of the conversation. A human always decides how your inquiry is handled; no automated decision with legal effect or similarly significant impact within the meaning of Art. 22 GDPR takes place.
Technical processing and storage
Transmission takes place via an interface operated by us at Cloudflare Germany GmbH or Cloudflare, Inc. (“Cloudflare”). Your inquiry is briefly stored there and is then retrieved by a system that we operate ourselves on our own infrastructure at our business premises and that is not publicly accessible. Cloudflare acts as a processor on our behalf pursuant to Art. 28 GDPR; a corresponding data processing agreement is in place. According to our configuration, processing takes place in data centres within the European Union. After retrieval, your data is processed solely within our own customer management; no further service providers are involved.
To protect against automated submissions, we check each transmission technically, including via a form field that is invisible to you, a check of the submitting domain, and a limit on the number of submissions per IP address. No additional personal profiles are created in the process. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in preventing abuse and spam.
Bot detection with Cloudflare Turnstile
In addition, we use “Cloudflare Turnstile” on the form pages, a Cloudflare service for distinguishing human input from automated access. Turnstile replaces the classic captcha: in our configuration it runs invisibly in the background and, as a rule, requires no input and no interaction from you.
According to the provider, technical characteristics of your access are processed in doing so, in particular your IP address, a characteristic of the encrypted connection (TLS fingerprint), the browser identifier (user agent), and the identifier of our form together with the calling domain. Cloudflare states that it cannot directly identify any individual from these characteristics and uses them solely for bot detection and for improving that detection. They are not used for advertising, for building user profiles, or for cross-site tracking. According to our configuration, Turnstile sets no cookie that clears further page views.
The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in protecting our forms against automated abuse. Insofar as information on your device is accessed or stored in the process, this is strictly necessary to provide the service you expressly requested — the transmission of your inquiry — within the meaning of § 25(2)(2) TDDDG; no consent is required for it. Cloudflare acts as a processor on our behalf pursuant to Art. 28 GDPR in this respect as well. Further information can be found in Cloudflare’s privacy policy for Turnstile.
So that accidentally reloading the page does not erase what you have already entered, we store your entries locally in your browser (session storage) while you fill in the funnel. This data leaves your device only upon submission and is deleted when the browser tab is closed. This storage is technically necessary for the service you requested within the meaning of § 25(2) TDDDG.
We delete the inquiry data held in temporary storage at Cloudflare as soon as it has been transferred into our customer management system, and no later than 30 days. Further storage in the customer management system is governed by section 8.
5. Contractual Relationships, Services, and Billing
In the context of agency-related contractual relationships, we process the data required for quotations, contract conclusion, service delivery, project communication, support, billing, and the enforcement of claims. This includes in particular contact persons, contact details, contractual content, project information, and invoicing and payment data.
The legal bases are Art. 6(1)(b) GDPR for contract performance, Art. 6(1)(c) GDPR for commercial and tax retention obligations, and Art. 6(1)(f) GDPR for the establishment, exercise, or defense of legal claims.
This Privacy Policy does not describe the full scope of data processing within BetStup's standalone software products. Users of those products are informed separately in the respective product-specific privacy policies.
Commercially and tax-relevant documents are generally stored for six or ten years in accordance with statutory requirements.
6. Recipients and Data Processors
Personal data is disclosed only to those recipients who require it to fulfill the respective purposes. These may include in particular:
- hosting and infrastructure providers
- email, form, and communication service providers
- analytics and consent management providers, where used
- marketing and advertising platforms, in particular in connection with Facebook and Instagram advertising as well as Meta Pixel, where used
- payment service providers and banks where required in the context of agency contracts or offered payment methods
- tax advisors, legal advisors, and other professional confidentiality-bound service providers where required
- authorities and public bodies where there is a legal obligation
Where external service providers act as processors on our behalf, we conclude agreements pursuant to Art. 28 GDPR.
For hosting this website, delivery via a content delivery network, for receiving and temporarily storing inquiries from the initial consultation funnel and the digital check, and for bot detection on those forms (Cloudflare Turnstile), we use Cloudflare (Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany, and Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). A data processing agreement pursuant to Art. 28 GDPR is in place with Cloudflare. According to our configuration, processing takes place in data centres within the European Union.
7. Data Transfers to Third Countries
In individual cases, processing may also be carried out by service providers in countries outside the European Union or the European Economic Area. In such cases, we ensure an adequate level of data protection.
Where a transfer to a third country takes place, this occurs only on the basis of an adequacy decision under Art. 45 GDPR, appropriate safeguards under Art. 46 GDPR, or another statutory permission. Appropriate safeguards may include, in particular, the European Commission's Standard Contractual Clauses or certification under the EU-U.S. Data Privacy Framework, where the respective provider falls under it.
Further information about service providers used and the relevant transfer mechanisms is available upon request at [email protected].
8. Storage Period
We store personal data only for as long as this is necessary for the respective purpose or as long as statutory retention obligations exist.
Access and server logs: generally a few days, no more than 30 days, unless longer retention is required for security reasons
Contact inquiries: until the inquiry has been fully processed and thereafter only insofar as required for evidence, follow-up questions, or statutory obligations
Inquiries from the initial consultation funnel: in temporary technical storage until transfer into our customer management system, and no later than 30 days; thereafter the periods for contact inquiries or contract data apply
Contract and billing data: for the duration of the contractual relationship and thereafter in accordance with statutory retention obligations
Usage and account data of our own digital offerings: until termination of the user relationship and thereafter only insofar as statutory obligations or legitimate interests require this
9. Cookies and Similar Technologies
We use technically necessary cookies or comparable storage technologies where this is required for the secure and functional operation of the website.
In addition, after launch we may use consent-based services such as consent management tools, web analytics, reach measurement, or tag management, for example Google Analytics, Google Tag Manager, Umami, or comparable technologies. Such services are activated only on the basis of your prior consent where consent is legally required. The legal basis is then Art. 6(1)(a) GDPR in conjunction with the applicable rules governing access to terminal equipment information.
Further information on providers, functionality, storage periods, possible third-country transfers, and withdrawal options for consent-based services can be found in our Cookie Policy. The consent modal is used primarily to select and later withdraw your preferences.
Where we use Google Tag Manager, it serves exclusively for the technical integration and control of additional tags and scripts. According to our intended setup, Google Tag Manager itself is not intended to create independent user profiles, but it may technically transmit data such as the IP address or device-related information to Google where this is required for service delivery. Any consent-based services delivered through the tag manager are loaded only after your consent.
Where we use Google Analytics, this takes place only with active consent, IP anonymization, a defined storage period, and privacy-friendly settings chosen by us. If we instead use Umami or comparable analytics tools, this likewise takes place only within the legally permissible scope and, where required, only after your consent.
Where we use Meta Pixel or comparable Meta business tools for advertising measures on Facebook or Instagram, this likewise takes place only on the basis of your prior consent where legally required. This may in particular serve conversion measurement, remarketing, audience building, and the evaluation and optimization of our advertising campaigns.
Details about the cookies, services, providers, durations, and withdrawal options currently in use can be found additionally in our Cookie Policy.
Origin data for inquiries: Only if you have consented to the “Marketing” category in the consent modal do we store campaign parameters (e.g. utm_source, utm_campaign) and the referring page locally in your browser for the duration of your browsing session, so that an inquiry can be attributed to the campaign it originated from. The legal basis is Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. Without this consent, no such storage takes place on your device; in that case we evaluate only the parameters of the specific page called up and transmit them with your inquiry.
Technically necessary cookies or storage technologies serve the secure provision of the website and are based on Art. 6(1)(f) GDPR; insofar as access to terminal equipment information is concerned, this takes place only within the legally permissible scope.
10. Your Rights as a Data Subject
Under the GDPR, you have the following rights:
Right of Access (Art. 15 GDPR)
You have the right to obtain information about the personal data we store about you.
Right to Rectification (Art. 16 GDPR)
You may request the correction of inaccurate or incomplete data.
Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR)
You may request deletion of your data unless retention obligations or other legal bases apply.
Right to Restriction of Processing (Art. 18 GDPR)
You may request restriction of processing under certain conditions.
Data Portability (Art. 20 GDPR)
You have the right to receive your data in a structured, commonly used, and machine-readable format.
Right to Object (Art. 21 GDPR)
You may object to the processing of your data, in particular in relation to direct marketing and profiling.
Withdrawal of Consent (Art. 7(3) GDPR)
If processing is based on your consent, you may withdraw it at any time.
Right to Lodge a Complaint (Art. 77 GDPR)
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is generally the authority at your place of residence, work, or the place of the alleged infringement.
To exercise these rights, please contact us at: [email protected]
You also have the right to lodge a complaint with a supervisory authority. For our company in North Rhine-Westphalia, the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia is of particular relevance.
11. Security of Personal Data
We implement appropriate technical and organizational measures to protect personal data against loss, manipulation, unauthorized access, and other unauthorized processing.
- TLS encryption for data transmissions
- access and authorization concepts
- regular updates of systems in use
- backup and recovery measures
- organizational processes to ensure confidentiality and integrity
Despite all due care, complete security of data transmission on the internet cannot be guaranteed.
12. No Automated Decision-Making
We do not carry out automated decision-making, including profiling within the meaning of Art. 22 GDPR, in connection with this website. The prioritisation score described in section 4a for inquiries from the initial consultation funnel serves solely to organise our internal handling. It has no legal effect on you and does not similarly affect you; a human always decides how your inquiry is handled.
13. Data Protection Contact
For questions about data protection or to exercise your rights, please contact us:
BetStup UG (haftungsbeschränkt)
Bahnhofstraße 74
32257 Bünde
Germany
Email: [email protected]
Note: Where required by law, we respond to requests from data subjects without undue delay and generally within one month.
14. Changes to This Privacy Policy
We update this Privacy Policy whenever our website, our processes, or the legal requirements change. The version published on this page is the authoritative version.
Last updated: March 24, 2026