1. Overview
The protection of your personal data is very important to us. We process personal data confidentially and in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and this privacy policy.
This policy explains what data we collect when you visit cromangroup.com, use our contact or newsletter forms, or communicate with us via email, phone, or WhatsApp.
2. Controller
CROMAN Group GmbH i.G.
Karl-Heinrich-Ulrichs-Straße 8B
10787 Berlin
Germany
Represented by the Managing Director: Rashid Mostafa
Email: info@cromangroup.com
Phone: +49 176 6315 8812
For data protection enquiries, please contact our Data Protection Officer or write to info@cromangroup.com with the subject line “Data Protection”.
Data Protection Officer
Milos Zaric, MISOTEC
Website: misotec.dev
3. Hosting and Server Logs
Our website is hosted by Vercel Inc. When you access the site, the hosting provider automatically processes technical data required to deliver the website securely, including:
- IP address
- Date and time of access
- Requested page or file
- Browser type and version
- Operating system
- Referrer URL
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in secure, stable operation of the website).
Retention: Server logs are retained only as long as necessary for security and troubleshooting, then deleted or anonymised.
4. Contact and Partner Forms
When you submit a booking request or partner application via our contact page, we collect the information you provide, such as name, email address, phone number, company details, and message content.
Submissions are stored in our database hosted by Supabase Inc. and processed by our team to respond to your enquiry. We may also send notification and confirmation emails via Resend.
Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures) and Art. 6 (1) (a) GDPR (consent given via the privacy checkbox on the form).
Retention: Enquiry data is kept for as long as needed to process your request and for any subsequent business relationship, unless statutory retention periods require longer storage.
5. Newsletter
If you subscribe to our newsletter, we process your email address and preferred language. Subscription requires your explicit consent via the checkbox on the form and is confirmed through a double opt-in link sent to your email address.
Subscriber data is stored in Supabase. Confirmation and service emails are sent via Resend. Every newsletter includes an unsubscribe link.
Legal basis: Art. 6 (1) (a) GDPR (consent). You may withdraw consent at any time via the unsubscribe link or by emailing us.
Retention: Until you unsubscribe or withdraw consent, plus any records required by law.
6. Email and WhatsApp Communication
If you contact us by email or phone, we process the data you provide to handle your request.
Links to WhatsApp (Meta Platforms Ireland Ltd.) open an external service. If you use WhatsApp, Meta’s own privacy policy applies to data processed on their platform. We only receive the information you choose to send us through that channel.
Legal basis: Art. 6 (1) (b) GDPR and Art. 6 (1) (f) GDPR (legitimate interest in customer communication).
7. Cookies and Local Storage
We do not currently use analytics, advertising, or social-media tracking cookies on this website.
When you acknowledge our cookie notice, your choice is stored in your browser’s local storage so the notice is not shown again. This is strictly necessary for displaying the notice itself.
Our admin area (not publicly accessible) may use session storage for authentication purposes only.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a functional website) and, where applicable, § 25 (2) TTDSG for technically necessary storage.
8. Processors and Third-Party Services
We use the following service providers as data processors:
| Provider | Purpose | Location / safeguards |
|---|---|---|
| Vercel Inc. | Website hosting and delivery | USA / EU; standard contractual clauses where applicable |
| Supabase Inc. | Database for forms and newsletter | USA / EU; standard contractual clauses where applicable |
| Resend Inc. | Transactional and confirmation emails | USA; standard contractual clauses where applicable |
We only share data with processors to the extent necessary to provide our services and only under data processing agreements.
9. Your Rights
Under the GDPR, you have the right to:
- Access your personal data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (“right to be forgotten”) (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing based on legitimate interests (Art. 21 GDPR)
- Withdraw consent at any time without affecting prior processing (Art. 7 (3) GDPR)
To exercise your rights, contact info@cromangroup.com.
You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Friedrichstraße 219
10969 Berlin
www.datenschutz-berlin.de
10. Data Security
We use SSL/TLS encryption to protect data transmitted via this website. Access to stored data is restricted to authorised personnel.
11. Changes to This Policy
We may update this privacy policy to reflect legal or technical changes. The current version is always available on this page.
Last updated: August 2026