Privacy Notice for krisenchat
Effective Date: 30/10/2025
1. General Provisions
1.1.
krisenchat gGmbH
Oranienstraße 6
10997 Berlin
Germany
(hereinafter referred to as "krisenchat") processes personal data based on the principles described in this policy while providing its services to users.
1.2. Scope and Purpose: This Privacy Policy sets out the principles and legal bases under which krisenchat processes personal data when providing counseling and support services to users. It complements our Terms of Use, which outline the rights and obligations of both krisenchat and its users.
1.3. Service Offered: krisenchat enables users to communicate with a counselor either via our Webchat Service or through SMS and WhatsApp. Our service assists users in addressing personal crises, psychological challenges, and related issues.
1.4. Applicability of Provisions and Service Channels (Webchat, SMS, and WhatsApp): Except where otherwise noted, the provisions in this Privacy Policy apply to service provided by krisenchat via our proprietary Webchat platform or through SMS and WhatsApp.
We developed the Webchat platform to ensure a secure, user-friendly environment that gives us greater control over privacy measures, reduces reliance on third-party infrastructure, and fosters a seamless counseling experience. While SMS and WhatsApp use external communication networks, our Webchat application allows for tighter integration of security features and direct oversight of data handling.
Any data processing details that apply exclusively to the Webchat platform will be clearly marked as “(Webchat only)”.
1.5. **Differences for SMS and WhatsApp Services: **For clarity, Section 11, titled “Provision of Services via SMS and WhatsApp ,” provides details about any additional or differing aspects of data processing when you choose to use these communication channels. This includes how your data is handled, stored, and transferred when using SMS or WhatsApp instead of (or in addition to) the Webchat Service.
1.6. **Contact Information:**If you have any questions regarding the use of your data after reading this Privacy Policy, you can reach out to us at:
Email: datenschutz@krisenchat.de
Address: Oranienstraße 6, 10997 Berlin, Germany
2. What Is Personal Data?
Personal information is any information that can identify you in some way. It can include your name, address, birth date, and computer’s IP address. This information is considered to be normal or non-sensitive personal data.
Some personal information is considered by the legislation to be sensitive or special, including data relating to your health, sexuality, religion, ethnicity, or criminal convictions, among others. The law provides additional protection for such data.
3. Data Processing Activities
3.1. Registration or Initial ContactWhen using our service, certain data may be collected to ensure the proper functioning and legal compliance of krisenchat. This includes:
-
Device and Browser Information: Such as your IP address, log data, date, and time of the request (automatically transmitted).
-
Phone Number: Providing a phone number is mandatory for anyone wishing to chat with us, enabling us to share the number with the authorities in case of an emergency. Additionally, users have the option to opt-in to receive an SMS notification when a counselor becomes available.
This data collection ensures both the safety of our users and the efficient delivery of our services, in compliance with Art. 6 (1)(b) GDPR for providing the chat, and Art. 6 (1)(f) GDPR (our overriding legitimate interest in safeguarding life in emergencies)
3.2. Data Exchanged During Service Use
3.2.1. Personal Information
To provide assistance and support services, we collect personal information you voluntarily share during the chat sessions. This may include information about your emotional state, health condition, and life circumstances.
The processing of this data is necessary to fulfill the service, according to Art. 6(1)(b) GDPR, insofar as this data is provided.
3.2.2. Sensitive Personal Data
In the course of using krisenchat, you may voluntarily provide sensitive personal data, such as information about your health or sexuality, including diagnosed physical or mental conditions or symptoms suggesting such conditions.
This sensitive personal data is used by krisenchat to provide our assistance and support services. The processing of sensitive personal data is based on your explicit consent according to Art. 9(2)(a) GDPR. The specific consent provided is outlined at the end of this Privacy Policy.
3.2.3. Usage Information
During the use of krisenchat, additional usage information may be collected, such as:
-
Interaction with media content (e.g., exercises or resources)
-
Messages, images, audio, or video shared during counseling sessions
-
Anonymized data about how you interact with our services
-
Your location (city).
This data processing is necessary to fulfill the requirements to provide the service, according to Art. 6(1)(b) GDPR.
3.3. Analysis and Service Improvement
3.3.1. Functional Improvement
To enhance the functionalities and performance features of krisenchat and to prevent and eliminate misuse and malfunctions, we use the personal data described in sections 3.1 and 3.2. krisenchat has a legitimate interest in ensuring the operability and error-free operation of its service and being able to offer a service that meets market and user needs. The legal basis is legitimate interests, Art. 6(1)(f) GDPR. Sensitive personal data is used only in a pseudonymized form or based on explicit consent under Art. 9(2)(a) GDPR.
3.3.2. Aggregated Analyses
krisenchat creates aggregated group analyses from pseudonymized/anonymized information, from which no conclusions about individual users are possible and through which statistical information and evaluations can be generated. Such information is also used to demonstrate service usage to third parties who cover the service’s costs, such as partner companies and sponsoring institutions. These third parties can never trace back to individual users.
3.4. Research Purposes
krisenchat collaborates with research partners and provides information to medical institutions for research purposes within special projects. Research partners cannot trace back to specific individuals, as all identifying features of users are removed, anonymized, by krisenchat before such disclosure. The legal basis is § 27 BDSG and Art. 9 (2)(j) GDPR.
3.5. Surveys
For quality control, you may be invited to participate in a feedback survey after each completed counseling session or within research projects. Participation in the survey is voluntary. Data collected during a survey is stored with your user information. The processing of your data by Typeform S.L., a company based in Spain, is based on your consent under Art. 6(1)(a) GDPR. The consent is separately obtained from you during the respective survey. By using the service, you agree here to receive the email to participate in the survey.
3.6. Exercise Reminders and Tracking (Webchat only)
With your consent, we collect data to send you notifications and track your exercise dates. This helps you perform exercises regularly and monitor your progress.
3.7. Uplifting Messages (Webchat only)
If you choose to send uplifting messages to other users, we collect them, anonymize them, and share their content. Counselors will review and approve messages before they are added to our database.
3.8. Message Reception (Webchat only)
Users can request random uplifting messages from the database. The sender's identity remains completely anonymous.
3.9. Legal Obligations
When krisenchat is requested by authorities or within legal disputes to provide information to authorities, courts, or other third parties, krisenchat complies with this request to the extent that krisenchat is legally obliged to do so. The legal basis for such disclosure of personal data is Art. 6(1)(c) GDPR.
4. Protection of Children's Data
We rely on Article 9 (2)(a) GDPR (your explicit consent) to process any health-related information you share.
Because this service is preventive counselling, Recital 38 GDPR allows children under 16 to give consent themselves; no parental permission is required.
You can withdraw consent at any time with future effect.
5. Data Storage
For data storage, krisenchat uses service providers with physical server locations in Germany.
All data is stored within the EU, and appropriate safeguards are in place to protect your data. For more information, read section 13 (Data Security).
6. Third-Party Data Processors
6.1. Technical Third Parties
We share some of your data with trusted partners who help us deliver our services.
Below are the third parties we work with to make the Webchat work and what they do:
| | | |
|---|
| Supplier | Purpose | Data Location | Compliance Framework |
| Hanko | Authentication services | Germany | Not a third-country transfer |
| Twilio | Phone number verification | USA | EU-U.S Data Privacy Framework |
| Pusher | Real-time communication | Ireland (EU) | Servers in Europe |
| Sentry | Error tracking | Germany | Not a third-country transfer |
| Vercel | Hosting and server management | Germany | Not a third-country transfer |
| Datadog | Logging and analytics | Germany | Not a third-country transfer |
| Cloudflare R2 | Media content delivery | Germany | Not a third-country transfer |
| Whatsapp Ireland (Only when chatting via Whatsapp) | Messaging Integration | Ireland (EU) | Servers in Europe |
All third parties are contractually obligated to handle your data securely and in compliance with GDPR and they provide appropriate safeguards.
7. Data Retention
The personal data stored by krisenchat is deleted as soon as it is no longer needed for the purpose for which it was collected, and/or krisenchat is not legally obligated to retain it longer. Generally, your personal data is deleted upon your request to terminate the service use, unless other purposes require further storage. In such cases, the data is deleted after the purpose has ended. If the user of an active chat doesn’t contact krisenchat for 6 months after the last contact, we will delete/anonymize its data.
8. Your Rights
You have the right to:
-
Access the personal data we process about you (Art. 15 GDPR)
-
Rectify incorrect or incomplete personal data (Art. 16 GDPR)
-
Erase your personal data (Art. 17 GDPR)
-
Restrict the processing of your personal data (Art. 18 GDPR)
-
Data Portability, receiving your personal data in a structured, commonly used format (Art. 20 GDPR)
-
Object to the processing of your personal data (Art. 21 GDPR)
-
Withdraw Consent at any time without affecting the lawfulness of processing based on consent before its withdrawal (Art. 7(3) GDPR)
If you wish to exercise any of your rights, please contact us directly via email or in writing at the address below. After withdrawal, your personal data may continue to be processed to the extent legally permissible. For complaints, the Berlin Commissioner for Data Protection and Freedom of Information is the responsible supervisory authority.
9. Controller
krisenchat gGmbH
Oranienstraße 6
10997 Berlin
Germany
Email: datenschutz@krisenchat.de
Managing Directors: Kai Lanz, Melanie Eckert
krisenchat has appointed a Data Protection Officer (DPO). For questions about data protection, you can contact the DPO or the Privacy Coordinator directly at:
External DPO: Michael Panienka - mp@panienka.de
Privacy Coordinator: Mike LaVigne - mike.lavigne@krisenchat.de
10. Consent to Data Processing
We require your explicit consent to process certain types of personal data, including sensitive personal data (e.g., health information). By actively providing your consent when using our services, you agree to the following:
10.1. Purposes for Which Consent is Obtained
Providing Counseling Services: You consent to krisenchat processing your personal data, including sensitive information about your health or sexual life, to provide personalized counseling services and support during your sessions.
Creating Recommendations and Therapeutic Content (Webchat only): You consent to the processing of your data to develop general recommendations and tailor therapeutic exercises that may benefit you during and after your sessions.
Exercise Reminders and Tracking (Webchat only): With your consent, we process your data to send you notifications and track your exercise dates, helping you perform exercises regularly and monitor your progress.
Sending Uplifting Messages (Webchat only): If you choose to send uplifting messages to other users, you consent to us processing and anonymizing these messages for sharing within our community.
Feedback Surveys: You consent to the use of your data for participating in voluntary feedback surveys aimed at improving our services.
Service Improvement and Research: You consent to krisenchat processing and anonymizing your personal data for the purpose of enhancing our services, usability, and contributing to mental health research. This includes sharing anonymized data with research institutions and universities.
10.2 Withdrawal of Consent
If you have given us consent to process your personal data, particularly the special categories of personal data described above, this is done voluntarily. You can withdraw your consent at any time with effect for the future. To exercise your right of withdrawal, you must inform us in the address or email indicated on item 9 via a clear declaration (e.g., a letter sent by post or email) of your decision to withdraw your consent. If you use this option, we will promptly (e.g., by email) send you a confirmation of receipt of such a withdrawal.
10.3 Consequences of Withdrawal
In the event of a withdrawal, the processing of your data up to that point remains lawful. After the withdrawal, your personal data may continue to be processed to the extent legally permissible, for example, within the framework of statutory retention periods or in legal disputes before courts or authorities.
11. Provision of Services via SMS and WhatsApp
In addition to our Webchat Service, krisenchat’s counseling services are also available via SMS and WhatsApp. All provisions regarding data processing, user rights, data retention, lawful bases, and data protection measures described elsewhere in this Privacy Notice apply equally to these communication channels. This section provides specific details unique to the SMS and WhatsApp modalities.
11.1 Data Collection and ProcessingWhen you contact krisenchat through SMS or WhatsApp, we collect and process certain personal data to enable the delivery of our services. This includes:
-
Phone Number: Used to establish and maintain contact with you and to send you SMS notifications about counselor availability, potential wait times, or session readiness. This helps you know when a counselor is ready to begin or continue your session and ensures you receive timely support.
-
Date and Time of Requests: Recorded to manage session timing and service delivery.
-
Message Content: Any information you voluntarily provide, which may include details about your emotional well-being, health, or other personal circumstances.
The processing of this personal data is necessary to fulfill our services in accordance with Art. 6(1)(b) GDPR.
11.2 Sensitive Personal DataAs with our Webchat, you may choose to share sensitive personal information (e.g., health-related data) via SMS or WhatsApp. Such data is processed only with your explicit consent, in accordance with Art. 9(2)(a) GDPR. You can withdraw your consent at any time without affecting the lawfulness of any processing carried out before the withdrawal.
11.3 Use of Third-Party Service Providers
-
**WhatsApp Ireland Ltd. (Ireland):**WhatsApp is an electronic communication service under the Telecommunications Act (TKG) and the GDPR. It acts as a data controller for personal data processed to provide its communication service. WhatsApp is therefore responsible for ensuring compliance with GDPR and the confidentiality of all communication content and metadata. For more information, please consult WhatsApp’s own privacy policies.
-
**Twilio Germany GmbH (Germany):**For SMS and WhatsApp integration, krisenchat uses Twilio as a data processor to facilitate communication and ensure message delivery. Twilio processes data on our behalf under the strict instructions and agreements required by the GDPR (EU-US Privacy Framework).
11.4 Data Storage and TransfersData transmitted via SMS or WhatsApp may be stored on servers operated by these third-party communication service providers. While WhatsApp’s primary data centers may be located outside the EU (e.g., in the U.S.), appropriate legal mechanisms (such as Standard Contractual Clauses and additional safeguards) ensure that your personal data is adequately protected.
11.5 Retention of Your DataThe general data retention periods outlined in this Privacy Notice also apply to SMS and WhatsApp communications. Your personal data is deleted or anonymized once it is no longer needed for the purposes it was collected, and no legal obligations require further retention. If you request termination of the service, we will delete/anonymize the data related to your communications, unless other legitimate purposes require continued storage.
11.6 Your RightsAll user rights described elsewhere in this Privacy Notice—such as the right to access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent—apply equally to data processed via Webchat, SMS and WhatsApp. If you wish to exercise these rights, please contact us using the information provided in the “Controller” section of this Privacy Notice.
By choosing to use our services via SMS or WhatsApp, you acknowledge that these platforms process your data as described and accept the additional data protection provisions specific to these channels. If you have any questions or concerns, please contact us at datenschutz@krisenchat.de
12. Cookies and Tracking Technologies
12.1 What are cookies?
Cookies are small text files stored on your device when you visit our site. They perform technical functions, allow us to analyse usage and, if you agree, let us deliver marketing content that matches your interests.
12.2 Legal framework
Our cookie practice follows § 25 TTDSG and the GDPR. Essential cookies are set without consent because they are strictly necessary (§ 25 (2) TTDSG). Any other cookie is placed only after you have given clear, informed consent (§ 25 (1) TTDSG, Art. 6 (1)(a) GDPR). Consent can be withdrawn at any time under Art. 7 GDPR.
12.3 How we manage consent (Usercentrics CMP)
****We use the Usercentrics Consent Management Platform provided by Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany.
When you first enter krisenchat.de page, a cookie banner will appear. Usercentrics places a consent cookie and logs a hashed IP address, browser and device details, the language detected, your selections for each cookie group and a time stamp. These data are stored on servers in Germany and Belgium.
Processing is necessary to display the banner, store your choices and demonstrate compliance (Art. 6 (1)(c) GDPR) as well as to protect our legitimate interest in secure consent administration (Art. 6 (1)(f) GDPR).
Consent logs are retained by Usercentrics for up to three years, and the consent cookie remains in your browser until you delete it or update your settings.
12.4 Categories, purposes and services
EssentialRequired for core functions such as load balancing, security and storing your consent.
• gstatic.com (static resources)
• Usercentrics Consent Management Platform (records your choices)
Functional / PerformanceImprove speed, stability or usability; set only with consent.
• Cloudflare (content delivery and security)
• Contentful (content delivery)
• Google Tag Manager (tag orchestration)
• Google Fonts (web‑font delivery; we serve locally whenever technically feasible)
• New Relic / nr-data.net (performance monitoring)
• Stripe and PayPal (payment integration)
• reCAPTCHA (bot defence)
Marketing & AnalyticsHelp us understand reach and show donation campaigns that match your interests; require consent.
• Facebook Pixel
• Google Ads, Google Ads Conversion Tracking, Google Ads Remarketing
• Conversion Linker
A service list, showing each cookie’s name, provider, purpose and typical lifetime, is available at any time via the “Cookie Settings” link in the footer of this page.
12.5 How consent is obtained
On your first visit we display a banner from Usercentrics. You can
• “Alle akzeptieren” (accept all),
• “Ablehnen” (reject all non‑essential), or
• “Einstellungen speichern” (save a granular selection).
Until you choose, only essential cookies are active.
12.6 How to change or withdraw consent
You can revisit your choices at any time by clicking “Cookie Settings” in the footer section of every page (this reopens the Usercentrics panel). You may also delete cookies via your browser settings. Withdrawal affects future processing only and has no negative impact on core site functions.
12.7 Third‑party cookies on external channels
When you reach us through third‑party platforms such as WhatsApp or SMS, those providers may place their own cookies or similar technologies. We do not control these cookies, and their use is governed by the provider’s privacy policy. Please review:
• WhatsApp: WhatsApp Privacy Policy
• SMS providers: see the privacy notice of your telephone or messaging provider.
12.8 Third‑country transfers Several providers (Google LLC, Meta Platforms Inc., Stripe Inc., New Relic Inc.) process data in the United States. They are certified under the EU‑US Data Privacy Framework, which the European Commission recognises as providing an adequate level of protection (Art. 45 GDPR). Where a service is not DPF‑certified we rely on the Standard Contractual Clauses adopted by the Commission (Art. 46 GDPR) plus additional safeguards.
13. Donations via Donorbox, Stripe and PayPal
13.1 Purposes and legal basesWe use your name, e-mail address and payment details (amount, currency, transaction ID) to confirm the donation, charge your chosen payment method and, at your request, issue a tax receipt. This processing is necessary for performing the donation contract (Article 6 (1)(b) GDPR) and for meeting statutory bookkeeping obligations (Article 6 (1)(c) GDPR, German Tax Code § 147).
If you voluntarily tick the “Subscribe” box in the Donorbox form we also store your e-mail address to send campaign updates and impact stories. That processing relies on your consent (Article 6 (1)(a) GDPR), which you can withdraw at any time via the unsubscribe link contained in every message.
13.2 Data flow, recipients and international transfersThe online donation form is hosted for us by Donorbox, Inc., which acts as a processor under the European Commission’s Standard Contractual Clauses.
Card payments are executed by Stripe Payments Europe Ltd. (Ireland) together with Stripe, Inc. (USA). Transfers within the Stripe group are secured by the same Clauses and by Stripe’s self-certification under the EU-U.S. Data Privacy Framework.
If you choose PayPal, the payment is handled by PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg), protected by PayPal’s Binding Corporate Rules or SCCs.
We do not sell, rent or otherwise disclose your donation data to additional third parties.
13.3 RetentionAccounting records relating to donations are stored for ten years in accordance with § 147 of the German Tax Code. E-mail addresses held solely for the mailing list are kept until you unsubscribe or request deletion.
13.4 SecurityAll donation data is transmitted over TLS, stored encrypted at rest and protected by the same technical and organisational measures described in Section 13 of this Privacy Notice.
All other information, especially your rights under Articles 15–22 GDPR, how to exercise them, and how to contact our Data-Protection Officer—remains exactly as set out in Sections 8, 9 and 15.
14. Use of Mailchimp for Newsletter Communications
We offer the option to subscribe to our newsletter, which includes updates and donation campaigns related to our work. The newsletter signup form is located in the footer of our website and is available on most pages.
14.1 What Data We Collect
When you sign up for our newsletter, we collect and process the following personal data:
This processing is based on your consent under Art. 6(1)(a) GDPR.
14.2 Use of Mailchimp (Intuit Inc.)
To manage and send our newsletters, we use Mailchimp, a marketing platform provided by Intuit Inc., based in the United States. Your personal data is stored and processed on Mailchimp’s systems for this purpose.
14.3 International Data Transfers
Intuit Inc. is certified under the EU-U.S. Data Privacy Framework (DPF), which was adopted by the European Commission on July 10, 2023, as an adequacy decision pursuant to Art. 45 GDPR. This means your data is considered to be subject to an adequate level of protection when transferred to the U.S. You can verify Intuit’s certification status here: https://www.dataprivacyframework.gov
14.4 Analytics and Tracking
Mailchimp uses tracking technologies to analyze how recipients interact with our emails (e.g., opens, clicks, bounces). This helps us improve our communications. We do not use this information to profile individuals or make automated decisions.
15. Data Security
15.1 Commitment to Data Security
At krisenchat, we prioritize the security of your personal data. We have implemented Technical and Organizational Measures (TOMs) to protect your information against unauthorized access, loss, or disclosure.
15.2 Technical Measures:
**Encryption:**All personal data transmitted through our Webchat service is encrypted using industry-standard protocols such as Transport Layer Security (TLS). Additionally, sensitive data is encrypted at rest using Advanced Encryption Standard (AES) to ensure it remains secure both during transmission and storage.
**Access Controls:**Access to personal data is restricted to authorized personnel only. We employ role-based access controls (RBAC) to ensure that employees can access only the data necessary for their roles. Permissions are regularly reviewed and updated to maintain the principle of least privilege.
**Secure Authentication:**Users must authenticate using secure methods, including two-factor authentication (2FA), to prevent unauthorized access to their accounts and data. Our authentication systems are regularly tested and updated to address potential vulnerabilities.
**System and Network Security:**We utilize firewalls, intrusion detection systems (IDS), and web application firewalls (WAFs) to protect our systems from cyber threats. Regular vulnerability assessments and penetration testing are conducted to identify and mitigate security risks.
**Data Backup and Recovery:**We maintain regular backups of all personal data, stored securely in separate, encrypted locations. Our disaster recovery plans ensure that data can be quickly restored in the event of a system failure or data loss incident.
15.3 Organizational Measures:
**Data Protection Officer (DPO):**krisenchat has appointed both an External DPO and an Internal Compliance Manager to oversee data protection strategies, ensure compliance with GDPR and ePrivacy Directive, and serve as points of contact for supervisory authorities and data subjects (Article 39 GDPR).
**Employee Training and Confidentiality:**All employees and volunteers undergo mandatory data protection training upon joining and receive annual refresher courses. They are required to sign confidentiality agreements to reinforce their commitment to safeguarding personal data (Article 32 GDPR).
**Incident Response Plan:**In the event of a data breach, we follow a structured Data Breach Response Plan to promptly contain and mitigate the breach, notify the Berlin Data Protection Authority within 72 hours as required by Articles 33 and 34 GDPR, and inform affected users without undue delay.
**Regular Audits and Monitoring:**We conduct regular internal and external audits to assess the effectiveness of our data protection measures. Continuous monitoring systems are in place to detect and respond to potential security incidents in real time (Article 32 GDPR).
**Data Minimization and Retention:**We adhere to the principle of data minimization (Article 5 GDPR) by only collecting data that is necessary for our services. Personal data is retained solely for the purposes outlined in this Privacy Notice and is securely deleted or anonymized when no longer needed (Article 5(1)(e) GDPR).
15.4 Compliance and Accountability
Our commitment to data security is embedded in our organizational culture and operational practices. We regularly review and update our security measures to align with evolving legal requirements and technological advancements. By adhering to Data Protection by Design and by Default (Article 25 GDPR), we ensure that data protection is integrated into every aspect of our services.
For more detailed information about our data security practices, please contact us directly at datenschutz@krisenchat.de
16. Contact Us / Lodge a Complaint
If you want to exercise any of your rights or have any questions or concerns about how we handle your personal data, please contact us:
Address: Torstraße 75, 10119 Berlin, Germany
Email: datenschutz@krisenchat.de
You can also contact our Data Protection Officers (DPO):
External DPO: Michael Panienka - mp@panienka.de
Privacy Coordinator: Mike LaVigne - mike.lavigne@krisenchat.de
For complaints, you can contact the supervisory authority:
Berlin Data Protection Authority
Address: Alt-Moabit 59-61, 10555 Berlin (Entrance: Alt-Moabit 60)
Tel: +49 30 138890
Email: mailbox@datenschutz-berlin.de
Website: https://www.datenschutz-berlin.de/
17. Updates to This Notice
We may update this Privacy Notice periodically to reflect changes in our data processing practices or legal requirements. Significant updates will be prominently displayed on our website. The effective date of the revised notice will be indicated at the top of this document, and we encourage you to review it regularly to stay informed about how we protect your personal data.
\
—-END—-
********
Appendix: Third-Party Services Details From the Webchat dataflow, we know that, for Webchat, Hanko, Pusher and Vercel have access to users ip addresses.
A. HankoPurpose: Hanko enables passkey-based sign-in; no biometric templates leave your device.
Data Collected: User ID, IP address, device information.
Data Location: Germany
Privacy Policy: https://www.hanko.io/privacy
B. TwilioPurpose: Verifies user phone numbers via SMS.
Data Collected: Phone number, verification timestamps, metadata.
Data Location: EU
Privacy Policy: https://www.twilio.com/legal/privacy
C. PusherPurpose: Enables real-time updates for incoming messages.
Data Collected: IP addresses, device information.
Data Location: EU
Privacy Policy: https://bird.com/en-us/legal/privacy
D. VercelPurpose: Hosts our web services and collects server logs.
Data Collected: Server requests, IP addresses, technical data.
Data Location: Germany
Privacy Policy: https://vercel.com/legal/privacy-policy
E. DatadogPurpose: Provides logging and analytics.
Data Collected: Server logs, usage data.
Data Location: Germany
Privacy Policy: https://www.datadoghq.com/legal/privacy/
F. Cloudflare R2Purpose: Stores and delivers media content such as audio and video exercises.
Data Collected: May collect data as per their privacy policies.
Data Location: Germany
Privacy Policy: https://www.cloudflare.com/privacypolicy/
Frequently Asked Questions (FAQ)
1. What is krisenchat?
krisenchat is a safe and supportive platform where you can talk to trained counselors if you're feeling upset, stressed, or going through a tough time. You can use our Webchat, SMS, or WhatsApp services to reach out for help.
2. What kind of information do you collect?
We collect information that helps us support you better, such as:
Personal Info: Your phone number and the messages you send.
Sensitive Info: Details about your feelings, health, or personal challenges (only if you choose to share them).
3. Why do you need my information?
Your information helps us:
Provide you with personalized support and advice.
Improve our services to better help others.
Ensure that our chats are safe and secure.
4. Is my information safe with krisenchat?
Yes! We take your privacy seriously and use strong security measures like:
Encryption: Protects your data when it's sent and stored.
Access Controls: Only authorized people can see your information.
Regular Security Checks: To keep our systems safe from hackers.
5. Will you share my information with others?
We only share your information with trusted partners who help us run krisenchat, like service providers for messaging and data storage. These partners are required to keep your information safe and private. We do not share your data with anyone else without your permission.
6. What are cookies and how do they affect me?
Cookies are small files that help our website remember your preferences and make your experience better. There are two types:
Essential Cookies: Necessary for our website to work properly (like keeping you logged in).
Non-Essential Cookies: Help us understand how you use our site so we can improve it. You can choose to accept or reject these cookies using the Cookie Banner when you visit our website.
7. Can I delete or change my information?
Yes! You have the right to:
Access: See what information we have about you.
Correct: Update any incorrect or incomplete information.
Delete: Remove your information from our records.
Restrict: Limit how we use your information.
Move: Transfer your data to another service if you want.
Object: Tell us to stop using your data for certain things.
To do any of these, just contact us at datenschutz@krisenchat.de.
8. How long do you keep my information?
We only keep your information as long as we need it to help you and to improve our services. If you stop using our service for 6 months, we will delete or anonymize your data to protect your privacy.
9. How do I know when the Privacy Notice changes?
We may update our Privacy Notice from time to time. When we do:
Website Banners: You’ll see a notice on our website.
Effective Date: The top of our Privacy Notice will show the date it was last updated. Please check it regularly to stay informed.
10. Who can I talk to if I have questions about my privacy?
If you have any questions or concerns about your data or privacy, you can reach out to us at:
Email: datenschutz@krisenchat.de
Address: Oranienstraße 6, 10997 Berlin
You can also contact our Data Protection Officers:
External DPO: Michael Panienka - mp@panienka.de
Privacy Coordinator: Mike LaVigne - mike.lavigne@krisenchat.de