Skip to content
relaisio

Legal

Privacy policy

This is a courtesy translation. The German version is legally binding.

This policy applies to the website relais.io. The application at app.relais.io has its own privacy policy, linked there.

Controller

Forwardly UG (haftungsbeschränkt), Zum Bäumchen 11, 53809 Ruppichteroth, Germany. Represented by Max Zeiger. Contact: see legal notice.

Hosting

The website is delivered as a static site via Cloudflare Workers (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; for users in the EU: Cloudflare Germany GmbH, Rosental 7, 80331 Munich). On each request Cloudflare processes technically necessary data: IP address, date and time, requested address, browser and operating system identifiers. The legal basis is our legitimate interest in secure and fast delivery (Art. 6(1)(f) GDPR). Cloudflare is certified under the EU-US Data Privacy Framework; standard contractual clauses apply in addition.

Location detection and homepage variants

When you open the homepage, Cloudflare determines your country from your IP address, and for visitors from Germany also your federal state. The server then serves one of several content variants of the homepage – at the same address, without a redirect. Country and federal state exist only in the request. Your federal state is never logged, never stored, and never shared with any third party or combined with other data. Your country additionally feeds into an aggregated, anonymous count, described in the “Reach measurement” section below. This creates no profile, no identifier and no recognition of individual visitors, and nothing is stored on your device. The legal basis for delivering suitable content is our legitimate interest (Art. 6(1)(f) GDPR). Because nothing is stored on or read from your device, § 25 TDDDG does not apply. Cloudflare processes this as our hosting provider, see the “Hosting” section. If a link on this website leads to app.relais.io, two values are appended to the address: the language of the page (lang) and the identifier of the variant delivered (v, for example “de-b2c”). Neither contains any personal data. app.relais.io uses the language to pre-set the interface as long as the account has no language of its own, and records the variant at sign-up to see which variant leads to sign-ups. This sets no cookie, assigns no identifier and requires no consent.

Reach measurement

Every time one of the four homepages is requested (/, /en/, /es/, /fr/), our server stores a single, aggregatable data point: the variant delivered (de-b2c, de-b2b, eu, world, or none), the language, your country as a country code, whether the request was recognised as a search engine or other bot, and what was delivered – a variant, the regular page, or a redirect. Not stored or shared with any third party are your IP address, your browser or device identifier, a cookie, any other identifier, your federal state, or the path requested. There is no connection between two requests from the same person; this creates no recognition and no profile. This count is kept in Workers Analytics Engine, a Cloudflare service (dataset “relais_variants”). Cloudflare is already our hosting provider, see the “Hosting” section – no additional recipient is involved. Analytics Engine assigns its own timestamp to each data point. Nothing is stored on or read from your device for this; § 25 TDDDG therefore does not apply. The count serves to see how often each homepage variant is delivered, and to evaluate the homepage's content direction accordingly. The legal basis is our legitimate interest in this evaluation (Art. 6(1)(f) GDPR); we rely on this as a precaution, even though the individual values may already not be personal data at all, given the lack of any identifier or link between requests.

Cookies and analytics

This website sets exactly one cookie: lang. It stores the language you choose via the language switcher – German, English, Spanish or French. It is set only when you actively choose a language, not merely by visiting the site. It is valid for one year, carries the SameSite=Lax attribute and is not accessible to third parties. It contains no identifier and no personal data; it allows no recognition beyond the chosen language. The server reads this cookie to deliver the homepage in the chosen language instead of redirecting automatically. The legal basis is § 25(2) no. 2 TDDDG: the cookie is strictly necessary to provide the service you expressly requested – the website in your chosen language. No consent is required for this. If you don't want the cookie, delete it in your browser or choose the language directly via the address: /en/, /es/ or /fr/. Beyond this, the website sets no cookies. It uses no third-party tracking, no advertising cookies, and creates no profile or individual recognition of visitors. The anonymous, server-side count of homepage variants is described in the “Reach measurement” section.

Fonts and content

Fonts are served from our own server. No third-party content is embedded.

Forms and contact

The website contains no forms. If you email us, we process your details to handle the request (Art. 6(1)(b) or (f) GDPR) and delete them once they are no longer required.

Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR), and to lodge a complaint with a supervisory authority; the one responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia.

Last updated

September 6, 2026.