Privacy Policy
1. Name and Contact Details of the Data Controller
2. Processing of Personal Data When Visiting This Website
When you access this website, the web server automatically collects and temporarily stores the following data:
- IP address of the requesting device
- Browser type and version
- Date and time of access
- Referrer URL (previously visited page)
- Operating system and configuration
This data is technically necessary to correctly deliver the website content, ensure stable operation, and maintain the security of IT systems.
The IP address is stored for security reasons (e.g., to detect and prevent attacks) for a maximum of 7 days and then anonymized.
The use of certain platform functions (in particular the upload and analysis feature) requires your prior explicit consent in accordance with Art. 6(1)(a) GDPR and, where special categories of personal data within the meaning of Art. 9(1) GDPR are concerned, additionally your consent under Art. 9(2)(a) GDPR. If you wish to use the traffic light evaluation, we process the documents you upload solely to provide you with the evaluation. This processing is necessary to fulfill the user agreement concluded between you and Bescheidklar (Art. 6(1)(b) GDPR).
The processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as the processing of genetic data, biometric data for the unique identification of a natural person, health data, or data concerning a person’s sex life or sexual orientation, is generally prohibited. Such data is processed by the platform only if you have given your explicit consent and provided these data voluntarily as part of the uploaded documents.
Legal bases:
- Art. 6(1)(f) GDPR (legitimate interest in the secure and functional operation of the website)
- Art. 6(1)(b) GDPR (processing necessary for contract performance)
- Art. 6(1)(a) GDPR (consent)
- Art. 9(2)(a) GDPR (consent to the processing of special categories of personal data)
3. Uploading and Processing of Documents via the Platform
a. General Information
When you upload a document (e.g., a social benefit decision) via the platform, initial technical processing takes place locally in your browser. This constitutes processing within the meaning of Art. 4(2) GDPR but is carried out not by us as the controller, but solely on your device. The legal basis is Art. 6(1)(b) GDPR (processing of pre-contractual measures at the request of the data subject).
This local pre-processing is necessary to technically enable the traffic light evaluation and to ensure user convenience. Obtaining prior consent at this stage would disproportionately complicate the process and significantly reduce the willingness to upload a document. Uploading remains entirely voluntary.
Uploading a document alone does not yet constitute a user agreement. It is a pre-contractual measure within the meaning of Art. 6(1)(b) GDPR carried out at your request and technically necessary to enable the evaluation function.
A user agreement is only concluded once you have explicitly consented to the processing of data, including special categories of personal data pursuant to Art. 9 GDPR, and accepted the Terms of Service (AGB).
Transmission and automated analysis of the document only take place once you have actively given consent by checking the corresponding boxes and clicking “Confirm.”
“I expressly consent to the processing of my document containing special categories of personal data for the traffic light evaluation. The processing is carried out exclusively in an automated manner via European servers operated by Microsoft Azure OpenAI and is not stored permanently. Further information can be found in the Privacy Policy and AI Explanation. You can withdraw your consent at any time.”
b. Processing for Contract Performance under Art. 6(1)(b) GDPR
If you wish to use the traffic light evaluation, we process the documents you upload solely to provide you with the evaluation. This processing is necessary to fulfill the user agreement concluded between you and Bescheidklar (Art. 6(1)(b) GDPR).
c. Personal Data of Third Parties
When using the traffic light evaluation, uploaded documents may contain personal data of third parties (e.g., names of caseworkers, landlords, children, associations, or other individuals). These data are analyzed automatically and linguistically to provide the document recipient (uploader) with orientation. No human review takes place, meaning the evaluation is effectively anonymized. Processing takes only a few seconds.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest of the uploader in obtaining an initial linguistic assessment). The recipient of the document has lawfully obtained it (e.g., via official delivery) and is therefore responsible for handling it. Unauthorized use lies outside Bescheidklar’s responsibility. The interests of third parties are outweighed by the legitimate interest of the uploader. The evaluation does not constitute a legal review but a linguistic orientation (e.g., whether the decision is an approval or rejection). The goal is to support particularly vulnerable groups — such as functional illiterates, migrants, or people in difficult life situations — in accessing their rights. This is done in accordance with Article 47 of the EU Charter of Fundamental Rights and Article 19(4) of the German Basic Law (Grundgesetz).
d. Specific Processing of Personal Data
We use affiliate links to partner programs to finance our services and provide you with relevant recommendations. When you click on such a link, the respective partner provider may recognize that you came from our website. Processing is based on Art. 6(1)(f) GDPR, as we have a legitimate interest in the economic and user-friendly design of our online offering.
4. Website and Platform Hosting
Website hosting is provided by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. IONOS processes data exclusively within the EU under a GDPR-compliant data processing agreement.
The platform itself is hosted on servers operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hetzner processes data exclusively within the EU/EEA. No transfer of personal data to third countries takes place. A data processing agreement under Art. 28 GDPR has been concluded with Hetzner to ensure GDPR-compliant processing.
5. AI-Based Evaluation via Microsoft Azure OpenAI
For the automated, language-based evaluation of uploaded documents, we use the 'Azure OpenAI' service provided by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA.
The Azure OpenAI models we use operate exclusively in Microsoft’s Azure data centers located within the European Union. There is both physical and logical separation from the OpenAI infrastructure in the USA. OpenAI itself has no access to the processed data. All processing takes place entirely within the EU; data do not leave the European legal area.
If, in exceptional cases, a data transfer to the USA is required (e.g., for support purposes), this will take place under the EU-U.S. Data Privacy Framework (DPF). Microsoft is certified under the DPF. The current certification can be viewed at: https://www.dataprivacyframework.gov/
Please note that even under an adequacy decision, a residual risk may remain, particularly due to possible changes in legislation or existing access rights of U.S. authorities. Should the adequacy decision be revoked, we will rely on other appropriate safeguards (e.g., EU Standard Contractual Clauses).
A data processing agreement under Art. 28 GDPR has been concluded with Microsoft to ensure the lawful handling of data.
6. Rights of Data Subjects
As a data subject, you have the following rights:
- Access to your stored personal data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of data (“right to be forgotten”, Art. 17 GDPR), unless legal retention obligations apply
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to data processing (Art. 21 GDPR)
To exercise your rights, simply send an informal email to info@bescheidklar.de. You also have the right to lodge a complaint with a data protection supervisory authority.
7. Cookies, Tracking, and Affiliate Marketing
BESCHEIDKLAR uses cookies and similar technologies to provide certain functionalities and analyze website usage.
a) Google Analytics
We use the web analytics service Google Analytics, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies to analyze website usage. Information about your use of this website may be transmitted to Google servers in the USA. Google is certified under the EU-U.S. Data Privacy Framework (DPF).
The data processed through Google Analytics are collected only on the basis of your consent in accordance with Art. 6(1)(a) GDPR. You can withdraw your consent at any time via our cookie banner.
b) Affiliate Networks
We participate in affiliate programs (including CHECK24, Tarifcheck, auxmoney). When you click on an affiliate link, the respective partner provider may use cookies or similar technologies to track the source of visits and attribute sales to our account. Processing occurs solely on the basis of your consent pursuant to Art. 6(1)(a) GDPR.
Withdrawal Option
You can withdraw your consent at any time via the cookie settings on our website.
8. No Legal or Contractual Obligation to Provide Data
The provision of personal data is not legally or contractually required. However, without the technical data mentioned in Sections 2 and 3, the operation of the site is not possible. Uploading a document is entirely voluntary.
9. Technical and Organizational Measures (TOMs)
To protect personal data, BESCHEIDKLAR implements technical and organizational measures in accordance with Art. 32 GDPR. These measures are based on the VdS Guideline 3473 ('Cyber Security for Small and Medium-Sized Enterprises'), which defines practical requirements for an information security management system.
Implemented measures include in particular:
- Encryption: All data transmissions occur via TLS/SSL-encrypted connections.
- Access control: Access to servers and systems is restricted to authorized persons; permissions are granted based on the principle of least privilege.
- Separation of data and services: Applications and data are operated logically and technically separately.
- Data processing agreements: GDPR-compliant agreements exist with all external service providers.
- Anonymization: IP anonymization is enabled for Google Analytics.
- Consent management: An opt-in mechanism is used via a cookie banner for Google Analytics and affiliate cookies.
- Logging: System access is logged and reviewed regularly.
- Updates and patches: Servers, applications, and security components are regularly updated.
By adhering to the VdS 3473 guideline, a practical, verifiable, and continuously improved level of security is ensured.
Last updated: September 15, 2025
Author: Hendrik Klaaßen