Privacy Policy
1. An overview of data protection
General information
The following gives a simple overview of what happens to your personal data when you visit this website and use our services. Personal data is any data with which you could be personally identified.
Data controller
The data controller responsible for processing data on this website and for the associated services is:
Inbal Mizrach
Schefferweg 2,
12249 Berlin,
Germany
Email: hello@reblume.eu
How we collect data
Data you provide to us: Collected when you book an appointment, make an in-person payment, or contact us via email, SMS, WhatsApp Business, or Telegram.
Automatically collected data: Technical data (e.g., IP address, browser type, access time) automatically recorded by our web host when you visit the site, as well as data stored via cookies.
2. Hosting (Framer) & cookies
Web hosting
This website is hosted by Framer Inc. When you access this site, Framer automatically collects server log files to ensure security and site stability (Art. 6(1)(f) GDPR). Data transfers to international servers rely on appropriate GDPR-compliant safeguards.
Cookies & consent manager
This website uses cookies and similar technologies to ensure proper website functionality, manage embedded appointment scheduling, and improve user experience.
Essential cookies: Necessary for basic website operations, security, and loading essential functions. These are processed based on Art. 6(1)(f) GDPR and §25 Abs. 2 TDDDG.
Functional & third-party cookies (Cal.com): When you interact with our embedded booking calendar, Cal.com may set cookies or local storage items to process your booking request, remember appointment sessions, and maintain secure connections.
Cookie consent banner: Upon your first visit, a cookie consent banner allows you to manage your cookie preferences. You can update or withdraw your consent at any time through the cookie settings on this website.
Legal basis for optional cookies: Art. 6(1)(a) GDPR and §25 Abs. 1 TDDDG (Consent).
3. Online booking & calendar scheduling (Cal.com & Google Calendar)
To manage appointments and schedule sessions, we use Cal.com integrated with Google Calendar.
Data processed: When you schedule a session via Cal.com, it collects your name, email address, phone number, and appointment notes. This booking data is synced to our Google Calendar to confirm and reserve your slot.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract or taking pre-contractual steps).
4. Payment processing (Stripe)
We process all client payments on-location using Stripe (Stripe Payments Europe, Ltd. / Stripe, Inc.). Stripe supports payments via major credit/debit cards and PayPal.
Data processed: Transaction details including amount, date, payment method, and name. We do not store or process your full payment card details or PayPal credentials on our own local servers; all transaction data is processed directly and securely by Stripe.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (legal obligation to maintain tax and accounting records).
5. Direct communication & messaging apps
If you contact us via direct communication channels, your details will be processed strictly to manage your request and provide client support.
Channels used:
Email & SMS: Used to respond to booking inquiries and provide client support.
WhatsApp Business: Processed by Meta Platforms Ireland Ltd.
Telegram: Processed by Telegram Group Inc.
Details & Terms:
Data processed: Your name, phone number, username/email, and message content.
Legal basis: Art. 6(1)(b) GDPR (contractual communications) and Art. 6(1)(a) GDPR (your consent if receiving optional broadcast updates). You can opt out of message communications at any time by sending a message stating "STOP".
International transfers: Transfers to third countries (e.g., US servers) are safeguarded under the EU-U.S. Data Privacy Framework or standard contractual clauses (SCCs).
6. Data retention
We retain your personal data only as long as necessary to fulfill the purposes for which it was collected, or as required by German law:
Tax & commercial records: Booking and payment data are retained for up to 10 years in accordance with German statutory obligations (§147 Abgabenordnung) and up to 6 years for commercial correspondence (§257 Handelsgesetzbuch).
Direct inquiries: Non-contractual inquiries via email, SMS, or messaging apps are generally deleted within 6 to 12 months after the request is resolved.
Hosting logs: Web log files are kept strictly per Framer's automated technical retention timelines.
7. Your legal rights under GDPR
As a data subject in the EU/UK, you hold the following rights regarding your personal data:
Right of access (Art. 15 GDPR)
Right to rectification (Art. 16 GDPR)
Right to erasure / Right to be forgotten (Art. 17 GDPR)
Right to restriction of processing (Art. 18 GDPR)
Right to data portability (Art. 20 GDPR)
Right to object (Art. 21 GDPR)
Right to withdraw consent (Art. 7(3) GDPR)
To exercise any of these rights, email us directly at hello@reblume.eu.
Right to complain
You have the right to lodge a complaint with a supervisory authority. The competent authority for Berlin is: Berliner Beauftragte für Datenschutz und Informationsfreiheit.
8. Children’s privacy & policy updates
Children’s privacy: Services are not targeted at individuals under 16 years of age. We do not knowingly collect data from children.
Policy updates: This policy may be updated periodically. Significant changes will be communicated via email or posted directly on this site.