Privacy Policy
English version of our privacy policy. The German original is available at ombrie.de/datenschutz.
1. Controller
Morus Media GmbH Oberstraße 3 47829 Krefeld Germany
Managing director: Tom Walter
Phone: +49 159 0433 8730 Email: info@ombrie.de
2. General information on data processing
We only process personal data of the users of our website to the extent necessary to provide a functional website as well as our content and services.
Processing is based on the GDPR, in particular Art. 6 (1) lit. b (performance of a contract), lit. c (legal obligation) and lit. f (legitimate interest).
3. Access data and server log files
Our hosting provider collects data on every access to the server on which this service is located ("server log files"). Access data includes:
- IP address
- Date and time of the request
- Name of the requested file
- Amount of data transferred
- Browser type and version
- Operating system
- Referrer URL
This data is stored for security reasons (e.g. to investigate misuse) and automatically deleted after 7–30 days. It is not merged with other data sources.
4. Contacting us
If you contact us by email or via a contact form, the information you provide will be processed to handle your request.
The legal basis is Art. 6 (1) lit. b GDPR (initiation and performance of a contract).
5. Cookies & tracking technologies
Our website uses cookies to improve usability. Cookies are small text files stored on your device. You can disable the storage of cookies in your browser settings.
We use marketing and tracking tools – in particular the Meta Pixel, the TikTok Pixel, Google Ads (see the following sections) and the OpenAI Ads pixel (see section 17). The legal basis is your consent (Art. 6 (1) lit. a GDPR).
6. Meta Pixel (Facebook/Instagram)
We use the Meta Pixel of Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland. It allows us to understand how visitors interact with our website after seeing an ad on Facebook or Instagram.
The legal basis is your consent (Art. 6 (1) lit. a GDPR). Meta may link the collected data to your profile and use it for its own purposes.
More information: https://www.facebook.com/about/privacy
7. TikTok Pixel
Our website uses the "TikTok Pixel" of TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. It allows us to understand the behavior of website visitors who reached us via TikTok ads and helps us measure the effectiveness of our ads and optimize marketing measures.
The legal basis is your consent (Art. 6 (1) lit. a GDPR).
More information: https://www.tiktok.com/legal/page/eea/privacy-policy
8. Google Ads (Google Ireland Ltd.)
We use Google Ads and Google tag/conversion tracking provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland. This lets us measure the success of our ads and record which actions users take on our website after clicking an ad.
The legal basis is your consent (Art. 6 (1) lit. a GDPR). Data may also be transferred to Google LLC in the USA; the transfer is based on the EU standard contractual clauses.
More information: https://policies.google.com/privacy
9. Appointment booking with Calendly
We use the service "Calendly" (Calendly LLC, 88 North Avondale Road, Suite 603, Avondale Estates, GA 30002, USA) for scheduling. When you book an appointment via our website, your details (e.g. name, email address, requested time) are transmitted to Calendly.
The legal basis is Art. 6 (1) lit. b GDPR (performance of a contract). Calendly also processes data in the USA. Data transfer takes place on the basis of the EU standard contractual clauses.
More information: https://calendly.com/privacy
10. Appointment reminders by SMS (Twilio)
Anyone who books an appointment on our booking page can additionally tick a separate, pre-unchecked box and then receives a booking confirmation and reminders before the appointment by text message. The full disclosure is shown right at that box, and the number is always entered by the prospect themselves.
The box is optional and not a required field: the appointment can be booked without it, the service is exactly the same either way, and consent is neither part of our terms of use nor a condition of any contract or purchase. Without that tick we send no text messages. What the opt-in looks like: https://ombrie.de/en/sms-opt-in/
We process the mobile number, the appointment details and the delivery status of the message. The legal basis is Art. 6(1)(b) GDPR (steps prior to entering into a contract) and Art. 6(1)(a) GDPR (consent).
Messages are sent through Twilio Inc., 101 Spear Street, Fifth Floor, San Francisco, CA 94105, USA, acting as our processor. Transfers to the USA are based on the EU Standard Contractual Clauses. More information: https://www.twilio.com/legal/privacy
Message frequency: up to 5 messages per appointment — a booking confirmation, reminders 24 hours, 2 hours and 15 minutes before the appointment, and a confirmation if you cancel. These messages relate solely to the appointment you booked; we never send promotional or marketing content on this channel.
Message and data rates may apply. No costs arise beyond the rates of your own mobile carrier.
You can withdraw your consent at any time and without giving reasons: replying STOP ends the messages immediately and permanently. Replying HELP returns our contact details.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All of the categories described elsewhere in this policy exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
We do not sell, rent or trade mobile phone numbers or SMS consent data. Your number is used solely to deliver the appointment messages described above. Twilio acts only as our technical service provider under a data processing agreement and does not receive your number for its own marketing purposes.
Full program terms: https://ombrie.de/en/sms-terms/
11. Disclosure to third parties / processors
Your personal data will only be transferred to third parties if this is legally permitted or if you have given your consent.
Service providers processing data on our behalf (e.g. hosting providers) are contractually obliged to comply with the GDPR.
This section does not apply to mobile phone numbers and SMS consent. No mobile information is shared with third parties or affiliates for marketing or promotional purposes, and text messaging originator opt-in data and consent are never shared with any third party (see section 10).
12. Fraud prevention and enforcement
To prevent and investigate misuse and fraud (in particular manipulated or purchased reach), we process account, usage and performance data as well as publicly available information relating to the social media content concerned (e.g. views, interactions, comments and publication times). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in preventing fraud and in asserting and defending legal claims) and Art. 6(1)(b) GDPR (performance of the contract).
Where manipulation is established, we may store the account, contact and payment data concerned as well as the social media identifiers used in an internal blocklist in order to prevent renewed registration or payout.
We store evidence and blocklist entries only for as long as necessary to pursue or defend claims (as a rule until the expiry of the applicable limitation periods). A request for erasure may be outweighed by the necessity of establishing, exercising or defending legal claims (Art. 17(3)(e) GDPR).
13. Rights of data subjects
Under the GDPR you have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
14. Deletion of data
We only process and store personal data for as long as necessary for the respective purpose or as required by statutory retention periods.
15. Security
We use technical and organizational measures to protect personal data against loss, misuse and unauthorized access.
16. Changes to this privacy policy
We reserve the right to amend this privacy policy at any time so that it always complies with current legal requirements or to reflect changes to our services.
17. OpenAI Ads pixel (advertising in ChatGPT)
Our website uses the advertising pixel of OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. It allows us to measure whether visitors who reached us via an ad in ChatGPT go on to book an appointment.
If you book an appointment through our website, we transmit your email address, your name, where applicable your mobile number and a pseudonymous visitor identifier to OpenAI – exclusively as a cryptographic hash (SHA-256). The conversion happens in your browser; the plain values do not leave it for this purpose. OpenAI uses the hashes to match the booking to the ad click.
The legal basis is your consent (Art. 6 (1) lit. a GDPR). Data may also be transferred to OpenAI OpCo, LLC in the USA; the transfer is based on the EU standard contractual clauses.
Further information: https://openai.com/policies/eu-privacy-policy/