Privacy Policy
Protecting your personal data matters to us. Below we inform you, in accordance with Articles 13 and 14 GDPR, about how your data is processed when you use our website and our mobile app.
Last updated: 14 September 2026 · Version 1.0
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws is:
Fadi Zgheib
Einzelunternehmen (Kleingewerbe) (sole proprietorship, small business), trading as “WerkConnect”
Schiersteinerstr. 90
65187 Wiesbaden
Germany
Email: kontakt@werk-connect.de
We have not appointed a data protection officer, as we are not legally required to do so. If you have any questions about data protection, you can reach us at any time at the email address above.
2. General information on data processing
Scope of processing
As a rule, we process our users’ personal data only to the extent necessary to provide a functioning platform along with our content and services. Processing generally takes place either with the user’s consent or where the processing is permitted by statute.
Legal bases
The legal bases for processing personal data follow from Article 6(1) GDPR:
- Article 6(1)(a) GDPR — processing based on your consent (e.g. newsletter, optional location sharing).
- Article 6(1)(b) GDPR — processing for the performance of a contract or pre-contractual measures (e.g. user account, brokering of jobs).
- Article 6(1)(c) GDPR — processing to comply with a legal obligation (e.g. commercial and tax retention requirements).
- Article 6(1)(f) GDPR — processing to safeguard legitimate interests (e.g. the security and functioning of the platform).
Erasure and storage period
Personal data is erased or blocked as soon as the purpose of storage no longer applies. Data is stored beyond that point only where statutory retention periods — in particular those under commercial and tax law — require it.
3. Hosting and provision of the website
We host our website and our server infrastructure with Hostinger International Ltd., 61 Lordou Vironos str., 6023 Larnaca, Cyprus. Data is processed on servers located in Germany (Frankfurt am Main data centre). A data processing agreement pursuant to Article 28 GDPR is in place with this provider in the form of the Data Processing Addendum that forms part of the provider’s terms of service.
Server log files
Each time our website is accessed, information transmitted by your browser is automatically collected and stored in what are known as server log files:
- anonymised or truncated IP address
- date and time of access
- name and URL of the file retrieved
- the browser used and, where applicable, the operating system
- the website from which access occurred (referrer URL)
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in ensuring a smooth connection as well as system security and stability.
4. Registration and user account
Using our platform as a client (Auftraggeber) or as a tradesperson (Handwerker) requires a user account. As part of registration and profile maintenance, we process in particular:
- name or company name and contact details (email address)
- login credentials (passwords are stored in encrypted form only)
- profile details (e.g. trade, service areas, postcode / area of operation)
- for tradespeople: verification details (e.g. proof of trade registration)
- the time of registration and of consents given (e.g. acceptance of the privacy policy and the terms of service)
The legal basis is Article 6(1)(b) GDPR, as the processing is necessary to provide the user account and to perform the user agreement.
6. Brokering of jobs and marketplace functions
The core function of WerkConnect is to broker between clients and tradespeople. When you post a job, submit a quote, or communicate through the built-in chat, we process the data required for this purpose (e.g. job description, quote details, message content, uploaded images).
To carry out the brokering, certain data is made available to the respective other party (e.g. contact and job data between the commissioning client and the selected tradesperson). The legal basis is Article 6(1)(b) GDPR.
7. Waiting list and contacting us
You can sign up for our waiting list on our website. For this we process your email address and your indication of whether you are interested as a client or as a tradesperson. To confirm your sign-up we use the double opt-in procedure: you receive an email containing a confirmation link.
The legal basis is your consent under Article 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future, for example by email to datenschutz@werk-connect.de. If you contact us by email, we process the details you provide in order to handle your enquiry (Article 6(1)(b) or (f) GDPR).
8. Sending email (Mailjet)
To send system and notification emails (e.g. confirming your email address, resetting your password, alerts about quotes and messages) we use the delivery provider Mailjet, a brand of the Sinch group. This involves processing your email address, your name, the content of the email in question, and technical delivery information such as the delivery status.
Storage and processing take place exclusively in data centres within the European Union (Frankfurt am Main, Germany, and Saint-Ghislain, Belgium); no transfer to a third country takes place. A data processing agreement pursuant to Article 28 GDPR is in place with the provider as part of its terms of service. The legal basis is Article 6(1)(b) GDPR for contract-related emails and Article 6(1)(a) GDPR where sending is based on your consent.
9. Push notifications (Firebase Cloud Messaging)
In our mobile app we use Firebase Cloud Messaging, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to send push notifications. A device- or installation-specific token is processed for this purpose so that notifications (e.g. about new quotes or messages) can be delivered to your device.
You can disable push notifications at any time in your device or app settings. The legal basis is your consent (Article 6(1)(a) GDPR) or our legitimate interest in keeping users properly informed (Article 6(1)(f) GDPR). This may involve a transfer of data to the USA; Google bases such transfers on appropriate safeguards (EU standard contractual clauses or the EU-US Data Privacy Framework).
10. Payment processing (Stripe)
We use the payment service provider Stripe (Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland) to process payments. When you make a payment, the data required for it (e.g. payment method and transaction data) is processed directly by Stripe. Your full payment details (e.g. card number) are not transmitted to us.
The legal basis is Article 6(1)(b) GDPR (performance of a contract). Stripe’s own privacy notices apply in addition. Here too, data may be transferred to the USA, safeguarded by appropriate measures.
11. Subscription management in the app (RevenueCat)
If you take out a subscription through the App Store or Google Play, we use the service RevenueCat, provided by RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA, to verify and manage your entitlement. This involves processing a pseudonymous user identifier, a device identifier, and details of the purchase (e.g. product, time of purchase, term and status of the subscription). Your payment data is processed solely by Apple or Google and is not transmitted to us.
The legal basis is Article 6(1)(b) GDPR, as the processing is necessary to provide the paid features you have booked. This involves a transfer of data to the USA; the transfer is safeguarded by the EU standard contractual clauses.
12. Location data (GPS)
Where individual functions of our app use location information (e.g. for on-site job or time tracking), we process it solely on the basis of your explicit consent (Article 6(1)(a) GDPR). You are asked for this consent separately in the app and can withdraw the permission at any time in your device or app settings.
14. Audience measurement and usage analytics (Matomo)
Website. To evaluate the use of this website statistically we use Matomo, an open-source application we run ourselves on our own server in Germany. No data is transmitted to third parties and none is transferred to a third country; we are the sole controller for this data.
Our Matomo installation is configured so that no cookies whatsoever are set or read and your IP address is truncated by two bytes before it is stored. No recognition across multiple websites takes place, and your browser’s “Do Not Track” setting is respected. Because no information is stored on or retrieved from your device, no consent under section 25 TDDDG is required. The legal basis is our legitimate interest in designing our offering to meet demand, under Article 6(1)(f) GDPR.
What is collected: the page visited, the time of the visit, the referring page, the approximate location at region level, and technical details about the browser and device. The raw data is deleted after 90 days; only anonymous aggregate statistics remain.
Mobile app. In our app you can voluntarily provide us with usage data. This function is disabled by default and becomes active only after your explicit consent; the legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR.
Only the following is transmitted:
- which screens and functions you open, and when;
- the operating system used (Android or iOS) and its version;
- the installed version of our app;
- the general device type (e.g. smartphone or tablet);
- a randomly generated identifier created solely on your device.
These technical details allow us to attribute a fault to an operating system or an app version — for example, to notice that a function misbehaves only on iOS. On their own they permit no conclusions about you as a person. Search terms, job content, prices and addresses are expressly not transmitted.
You can withdraw your consent at any time with effect for the future under Profile → Privacy → Usage analytics. Withdrawing it deletes the randomly generated identifier stored on your device, so that earlier and later use can no longer be linked to one another. Your name, your email address and your job data are never transmitted to the analytics system.
15. Error diagnostics and crash reports (Sentry)
To detect and fix technical faults, we use the service Sentry on our server and in our app, provided by Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. If an error or a crash occurs, an error report is transmitted to the service.
What is transmitted: the technical error message, the function or address affected, details of the device, operating system and app or server version, and a pseudonymous identifier that allows related reports from one session to be matched to each other. Transmission of plain-text data such as your name, email address or job content is disabled.
The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in the stability, security and correctness of our platform. Processing takes place on servers in the USA. A data processing agreement pursuant to Article 28 GDPR is in place with the provider; the transfer is safeguarded by the EU standard contractual clauses.
16. Your rights as a data subject
You have the following rights in relation to the personal data concerning you:
- Access (Article 15 GDPR)
- Rectification (Article 16 GDPR)
- Erasure (Article 17 GDPR)
- Restriction of processing (Article 18 GDPR)
- Data portability (Article 20 GDPR)
- Objection to processing (Article 21 GDPR)
- Withdrawal of consent with effect for the future (Article 7(3) GDPR)
An informal message to datenschutz@werk-connect.de is enough to exercise your rights.
Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of your data infringes the GDPR (Article 77 GDPR). The supervisory authority responsible for us is Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (the Hessian Commissioner for Data Protection and Freedom of Information).
17. Data security
We take technical and organisational security measures to protect your data against manipulation, loss or unauthorised access. Data is transmitted over an encrypted SSL/TLS connection. Our security measures are improved on an ongoing basis in line with technological developments.
18. Referral programme and payout of credit
Users can earn credit through our referral programme. If you are a client and request a payout of your credit, we process the IBAN you provide for that purpose together with the name of the account holder.
- Purpose — carrying out the payout you requested by SEPA transfer.
- Legal basis — Article 6(1)(b) GDPR (performing the payout you requested) and Article 6(1)(c) GDPR for the legally mandated retention.
- Recipients — your bank details are passed to our own bank in order to execute the transfer.
Your IBAN is stored in encrypted form only and is displayed masked within the app. Records of payouts carried out are retained for the statutory period of up to ten years under commercial and tax retention obligations (in particular section 147 AO and section 257 HGB); erasure before those periods expire is excluded to that extent. The details of the programme are set out in the referral programme terms of participation (available in German).
19. Currency and amendment of this privacy policy
This privacy policy is dated 14 September 2026 (version 1.0). As our platform develops further, or where legal or regulatory requirements change, it may become necessary to amend this privacy policy. The version in force at any given time can always be retrieved on this page.
20. Language of this document
This page is a translation provided for convenience. The authoritative version of this privacy policy is the German Datenschutzerklärung. In the event of any discrepancy between the two, the German text prevails. Both carry the same version number and are updated together.
5. Signing in with Google and Apple
As an alternative to registering with an email address and password, you can sign in using your Google or Apple account. If you choose this route, the respective provider transmits to us the details needed to create the account — as a rule your email address and your name. We do not access any other content of your account with that provider.
The legal basis is Article 6(1)(b) GDPR, as the processing is necessary to create and provide your user account. Using these sign-in methods is optional; registration with an email address and password remains available.