Skip to content
ReparARTur
For youGamers & streamersBusinessPricesConsultingKnowledgeStatus
Request

Last updated: October 2, 2026

Privacy Policy

1. Controller

Artur Bechtgold · ReparARTur
Theresienstraße 8
90762 Fürth
Deutschland

E-Mail:service@reparartur.de

2. General information on data processing

We process personal data only to the extent necessary to operate this website, handle requests, take pre-contractual steps or perform a contract, communicate with you and secure the website.

The main legal bases are Art. 6(1)(b) GDPR for handling requests and pre-contractual or contractual processes, Art. 6(1)(f) GDPR for the secure and abuse-resistant operation of the website, and Art. 6(1)(c) GDPR where statutory retention or documentation obligations apply.

3. Hosting, website delivery and security data

The website and its server-side functions are provided using Cloudflare services. When you access the website, technically necessary data may be processed, including your IP address, the time and destination of the request, browser and device information, HTTP headers, and security and connection data.

This processing is used to deliver the website, maintain stability, analyze errors, and defend against abuse and attacks. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure, reliable and efficient operation of the service.

The service provider is Cloudflare. Cloudflare operates internationally, so processing may also take place outside the European Economic Area. Cloudflare describes the EU-U.S. Data Privacy Framework and Standard Contractual Clauses, among other mechanisms, as safeguards for international transfers. Further information is available in theCloudflare Privacy Policy.

4. Cloudflare Turnstile

The public request form is protected against automated and abusive submissions using Cloudflare Turnstile. For this purpose, Turnstile processes technical signals such as the IP address, user agent, TLS-related characteristics, site key and associated origin in order to distinguish human use from automated bot traffic.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to prevent spam, automated attacks and abuse of the request form. Turnstile is not used for advertising or marketing purposes. Further information is available in Cloudflare'sTurnstile Privacy Addendum.

5. Repair, consultation and business requests

When you use the request form, we process the information you provide in order to handle your request. Depending on the case, this may include your name, email address, optional phone number, postal code and company or organization, device type, manufacturer, model, requested service, parts preference, fault or request description and, where applicable, insurance, consultation or device-fleet information.

Required fields are necessary so that we can properly classify and respond to your request. Without this information, we may be unable to process the request. Optional information is processed only if you provide it and it is relevant to the particular case.

The legal basis is Art. 6(1)(b) GDPR to the extent that processing is necessary to handle your request, take pre-contractual steps or process a subsequent order.

6. Internal case management via GitHub

A successfully submitted request is turned into a case in a private GitHub repository on the server side. The request and contact data required for processing, together with the processing status, are stored there. The repository is not publicly accessible.

The provider is GitHub. GitHub may process data in different regions, including the United States, and describes Standard Contractual Clauses in particular as a safeguard for international transfers. Further information is available in theGitHub Privacy Statement.

7. Optional image uploads

You may optionally attach images to your request. Supported images are checked on the server side and stored in private Cloudflare R2 storage. They are not given a public URL, and the original file names are not used as storage object names.

For JPEG, PNG and WebP files, the application removes supported metadata such as EXIF/XMP and text or time metadata where this can be done without fully re-encoding the image. Even so, you should not upload images showing passwords, unlock codes, identity documents or other confidential information that is unnecessary for the repair request.

Repair images are retained only for as long as they are needed for the case and are deleted no later than 90 days after upload. The legal basis is Art. 6(1)(b) GDPR.

8. Email communication

After a successful request, an automatic confirmation may be sent to the email address provided. It includes, among other things, the repair ID and personal status link. In addition, an internal notification is sent from anfragen@reparartur.de to service@reparartur.de and forwarded to the internal mailbox configured for ReparARTur.

The contact and case information necessary for communication is processed through the email services involved. The legal basis is Art. 6(1)(b) GDPR and, for internal organization of request handling, additionally Art. 6(1)(f) GDPR. Our legitimate interest is reliable notification and processing of new requests.

9. Repair status and personal status key

A repair ID and a random personal status key are generated for each request. Both are required to retrieve the public processing status. The status page does not display the full request or contact details.

The status key must be treated as confidential and should not be shared with third parties. Status lookups are also rate-limited on the server side to make automated guessing more difficult.

10. Protection against abuse and rate limits

We use server-side rate limits for the request form and status lookup. For the request form, a hash key that is not stored in plain text is derived from technical characteristics including the email address and connection IP for short-term rate limiting. A derived key is also used for the status lookup.

The purpose is to prevent automated bulk requests and abusive access. The legal basis is Art. 6(1)(f) GDPR.

11. No analytics or marketing tools

We currently do not use our own web analytics, advertising, remarketing or social-media tracking tools. There is currently no newsletter or customer account on this website either. Technically necessary security mechanisms provided by Cloudflare and Turnstile are unaffected.

12. Recipients and processors

Personal data is disclosed only to parties required for the relevant purpose. These may include Cloudflare for hosting, Workers, security checks, R2 and email functions, GitHub for private case management, and the provider of the internal destination mailbox.

Where service providers process personal data on our behalf, this is done on the basis of the applicable data-protection agreements. Data is not disclosed for advertising purposes.

13. Retention period

We retain personal data only for as long as necessary for the relevant purpose. Requests that do not result in an order are routinely deleted after communication has concluded once there are no legitimate reasons for further retention. Case data relating to services performed may be retained until applicable statutory limitation, warranty, documentation and retention periods have expired.

Documents subject to commercial or tax-law retention requirements are retained for the period required by law. Optional repair images are deleted no later than 90 days after upload.

14. Your rights

Subject to the applicable legal requirements, you have in particular the right to access your personal data, rectify inaccurate data, request deletion or restriction of processing, and receive data portability.

Where processing is based on Art. 6(1)(f) GDPR, you may object to the processing on grounds relating to your particular situation. To exercise your rights, simply send a message toservice@reparartur.de.

No solely automated decision-making with legal or similarly significant effects takes place.

15. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. For private-sector entities based in Bavaria, the competent authority is in particular:

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Deutschland
Phone: +49 981 180093-0
E-Mail: poststelle@lda.bayern.de

Further information and the complaint form are available atwww.lda.bayern.de.

16. Changes to this Privacy Policy

We update this Privacy Policy if the website, the services used or legal requirements change materially. The version published on this page at the relevant time applies.

ReparARTur

Repair. Upgrade. Keep using.

AreasFor youGamers & streamersBusinessConsulting
Service & informationKnowledgePricesShipping & handoverLocal & regionalInsurance caseRepair bonusStatusFAQImprintPrivacy
Independent repair service. Brand names are used solely to identify devices.
/