Privacy Policy
This policy explains how personal data is handled when you visit www.regionrise.com. We keep data collection to the minimum required to operate this website. If we contacted you and you did not give us your data yourself, see Business contacts and outreach.
Controller
regionrise GmbH, Bärbel-Bohley-Ring 34, 13355 Berlin, Germany.
Email: contact@regionrise.com.
See our Imprint for full company details.
Hosting and server logs
This website is hosted on Cloudflare Pages (Cloudflare, Inc.). When you access the site, Cloudflare automatically processes connection data such as your IP address, the requested page, the date and time, and your browser/operating system. This is technically necessary to deliver the site securely and to defend against attacks. The legal basis is Art. 6 (1)(f) GDPR (our legitimate interest in a secure, functioning website). A data processing agreement is in place with Cloudflare; data may be processed on servers operated by Cloudflare, including outside the EU under appropriate safeguards (EU Standard Contractual Clauses).
These connection logs are retained for a maximum of 7 days and are then deleted automatically. We do not create separate copies of them and do not use them for any other purpose.
Fonts
Our fonts (Poppins and Soleil) are hosted directly on this website. No font data is requested from third-party providers such as Google Fonts, so no data is transmitted to them when you load the site.
Cookies and analytics
This website does not set any cookies and does not use advertising services.
We use PostHog to understand how the site is used (for example which pages are visited). PostHog runs in a strictly cookieless mode: it stores no cookies and no other information on your device, and session recording is disabled. Because nothing is stored on or read from your device, no cookie banner or prior consent is required.
On each visit, PostHog processes a limited set of data: the pages you view and their addresses, the website you came from, your browser and device type, the date and time, and your IP address. PostHog uses your IP address and browser and device type only to generate a daily, privacy-preserving identifier; the IP address is not stored on the recorded events and is not used to determine your location. This data is not used to build advertising profiles and is not shared with other services. Analytics events are retained for a maximum of 12 months and are then deleted automatically.
The provider is PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA, acting as our processor under a data processing agreement pursuant to Art. 28 GDPR. The data is hosted on PostHog's EU infrastructure (servers in Frankfurt, Germany). Where PostHog accesses data from the United States (for example for support), the transfer is safeguarded by the EU Standard Contractual Clauses.
We rely on our legitimate interest in operating and improving our website (Art. 6(1)(f) GDPR). You can object to this processing at any time by enabling the "Do Not Track" setting in your browser or by contacting us using the details above.
External links and services
Some buttons and links lead to third-party services that have their own privacy policies. These are only loaded when you actively click them:
- Booking — “Book a call” opens Google Calendar Appointment Scheduling (Google Ireland Ltd.).
- LinkedIn — links to our company and team profiles.
We have no influence over the data processing on these external platforms once you leave our site.
Contacting us
If you contact us by email, the data you provide (e.g. your email address and message) is processed to handle your enquiry, on the basis of Art. 6 (1)(b) and (f) GDPR.
We keep email correspondence for as long as needed to handle your enquiry and any follow-up arising from it. If it does not lead to a business relationship, we delete it once the matter is closed. Where correspondence forms part of a commercial transaction, statutory retention obligations apply — six years under §257 HGB and ten years under §147 AO — and we then keep it solely to meet those obligations until they expire.
Business contacts and outreach (Art. 14 GDPR)
If we contacted you and you did not give us your data yourself, this section explains what we process and why.
Categories of data
Business contact details only: first and last name, business email address, job title, employer, public professional profile, and publicly available information about your company such as job postings, commercial register announcements, procurement notices or trade fair appearances. We do not process special categories of personal data under Art. 9 GDPR and no private contact details.
Where the data comes from
We name the specific source in the message we sent you. Sources we use are: business contact databases (Apollo.io), enrichment services (Clay), public company websites and career pages, public professional profiles, exhibitor directories of trade fairs, public job postings, procurement notices (TED, service.bund.de) and official commercial registers. On request we will name the specific source again at any time.
Purpose and legal basis
We process your data to contact you once about a possible business relationship. The legal basis is our legitimate interest in direct business communication, Art. 6 (1)(f) GDPR. Our interest is initiating business relationships. We assume that a relevant professional message to your work address does not override your interests. If you see it differently, one short message is enough.
Recipients and international transfers
Your data is processed within our company and by service providers who support us with sending and administration, in particular Apollo.io and Clay. Some of these providers are based in the United States. Transfers take place on the basis of the European Commission's standard contractual clauses.
Retention
If you do not respond, we delete your data no later than 12 months after the last contact. If you object, we keep only what is necessary to permanently exclude you from further contact.
Your right to object
You can object to this processing at any time, Art. 21 (2) GDPR. For direct marketing this right is absolute: no reason is required and no balancing of interests takes place. After your objection we will not contact you again. A short reply to any of our messages, or an email to privacy@regionrise.com, is sufficient.
Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing. To exercise your rights, contact us at privacy@regionrise.com.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
Changes
We may update this policy to reflect changes to the website or legal requirements. The current version always applies.