1. Controller
The controller within the meaning of Art. 4(7) GDPR for the processing of personal data on sunworker.eu and in the Sunworker apps is Sunworkers Ltd., Sinasi Bei 69, Kings Resort, Block C, Flat/Office A2, 8015 Paphos, Cyprus, registered with the Registrar of Companies of the Republic of Cyprus under HE 464110, represented by its director Andy Staudinger. Email: kontakt@sunworker.eu.
We have not appointed a data protection officer because the conditions of Art. 37(1) GDPR are not met: we are not a public authority, and our core activities consist neither of regular and systematic monitoring of individuals on a large scale nor of large-scale processing of special categories of personal data. Questions about data protection are answered by the management at kontakt@sunworker.eu.
We are established in Cyprus and offer our services in the European Union, mainly in Germany. The General Data Protection Regulation (GDPR) applies, supplemented by the Cypriot data protection law (Law 125(I)/2018) and, for access to the devices of users in Germany, the German Telecommunications Digital Services Data Protection Act (TDDDG).
2. What this is about and whom this notice concerns
Sunworker is an online marketplace on which hospitality businesses and private individuals find and book self-employed hospitality professionals – such as chefs, service staff or bartenders – for individual assignments. The professionals work on their own account and set their hourly rate themselves. We arrange the assignment, process the payment and prepare the invoicing; we are neither an employer nor a staffing agency.
This notice informs everyone whose data we process, in accordance with Art. 13 and 14 GDPR: visitors to the website, registered users in every role (business, professional, private individual) and people whose data others share with us – for example people a business invites into its account, or anyone mentioned in a review.
Most data we receive from you directly. From third parties we receive: information from other users in connection with an assignment (requests, messages, reviews, check-in times); from Stripe, the status of the identity check and whether payouts are possible; when you sign in with Google or Apple, the name, email address and identifier of that account; and coordinates for postcodes and addresses from OpenStreetMap and Google Maps.
Sunworker is intended exclusively for adults. When registering, you confirm that you are at least 18 years old.
3. Legal bases
We process personal data only on a legal basis, which we state for each processing activity: Art. 6(1)(b) GDPR – performance of the user agreement and of the contracts concluded via Sunworker, and pre-contractual steps; Art. 6(1)(c) GDPR – legal obligations, for example to retain invoices, to prevent money laundering or to report to tax authorities; Art. 6(1)(f) GDPR – legitimate interests, which we name in each case; Art. 6(1)(a) GDPR – your consent, which you can withdraw at any time with effect for the future (Art. 7(3) GDPR).
Storing information on your device and accessing it – cookies and similar technologies – is governed by Section 25 TDDDG and Art. 5(3) of the ePrivacy Directive 2002/58/EC. Without consent, we only use technologies that are strictly necessary to provide the service you have expressly requested (Section 25(2) no. 2 TDDDG). Where consent is required – for audience measurement and advertising, the map view and notifications – we obtain it before the technology takes effect (Section 25(1) TDDDG; sections 5, 15 and 17).
We do not ask for special categories of personal data under Art. 9 GDPR, such as health data. The certificate of instruction under Section 43 of the German Infection Protection Act only shows that an instruction took place; it says nothing about anyone’s state of health. Please do not upload medical documents.
4. Visiting the website, hosting and logs
Website. The website sunworker.eu is hosted by Vercel Inc. (section 18). Vercel delivers the pages through a worldwide network of data centres, usually from the nearest location; the website’s server functions run in a fixed region. When you visit, Vercel processes the connection data that is technically necessary.
Programming interface. The application logic that the website and apps access (api.sunworker.eu) runs on a dedicated server that we rent from Prepaid-Hoster.de (Henrik Kramer e.K.). It is located in the maincubes FRA01 data centre, Goethering 29, 63067 Offenbach am Main, Germany.
Log data. With every access, the IP address, date and time, requested address, request method, status code, amount of data transferred, referring page (if sent) and browser identifier are processed. The purposes are delivering the content, fending off attacks and abuse – for example through request limits per IP address – and troubleshooting. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is secure and uninterrupted operation.
Retention. The logs of our API server are continuously overwritten and deleted after 30 days at the latest. Vercel’s runtime logs are deleted after one to at most 30 days, depending on the plan. If we need individual entries to investigate a specific attack, we keep them until the investigation is complete.
All connections to the website and the API are encrypted with TLS.
5. Cookies, consent and browser storage
We distinguish four categories. Necessary cookies are those without which the site does not work; they always run (Section 25(2) no. 2 TDDDG, Art. 6(1)(b) and (f) GDPR). We only use statistics (Google Analytics 4), marketing (Google Ads) and external content (Google Maps maps and YouTube videos without asking, section 17) with your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). On your first visit, a banner asks for it; “Reject all” is shown there on an equal footing with “Accept all”, and as long as you have not consented, everything except the necessary cookies stays off.
Withdrawal and proof. You can withdraw or change your consent at any time with effect for the future – via the cookie settings, which are also linked in the footer of every page (Art. 7(3) GDPR). We store your decision for six months in the cookie sw-consent, a refusal just as long as a consent; after that, and after every new version of this policy, we ask again. As proof under Art. 7(1) GDPR, we log, under a random consent ID, the time, the version of this policy, your selection and a shortened user agent (browser and operating system), but no IP address; if you are signed in, we link the entry to your account (Art. 6(1)(c) GDPR). We keep the log as long as the decision applies and thereafter until the regular limitation period of three years has expired.
Sign-in. sw_access (proof of sign-in, up to one hour) and sw_refresh (renewal of the sign-in, 30 days) keep you signed in; neither can be read by scripts in the browser (httpOnly), and both are deleted when you sign out. sw_role (active role), sw_open (approval status of your roles), sw-venue (selected business) and sw-agency (selected agency) remember for 30 days which area you are working in.
Settings. sw-prefs stores your chosen language and currency for one year so that the site appears in your language on your next visit. sw-consent stores your cookie decision and the consent ID for six months.
Short-lived helper cookies. sw_oauth protects sign-in with Google or Apple (10 minutes); sw_reg_draft and sw_reg_draft_hint keep your registration progress (10 minutes); sw_login_throttle slows down repeated failed sign-in attempts (15 minutes); sw-invite-link carries an invitation to a business (5 minutes); sw_flash shows a notice after an action (1 minute).
Payment pages. When you add a payment method, confirm a payment or, as a professional, set up your payouts, the page loads program code from Stripe. Stripe sets its own cookies and reads device information in order to prevent payment fraud. This happens only on these pages and only because you use the payment function (Section 25(2) no. 2 TDDDG); see section 13.
Statistics: Google Analytics 4. With your consent, we measure how the site is used – which pages are viewed, where visitors come from, where they drop off – in order to improve it. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as our processor. We use Google’s consent mode (Consent Mode v2) in its strict form: Google’s code is only loaded after you have consented; before that, no request is sent to Google. IP addresses are truncated and not stored; Google Signals (cross-device attribution via Google accounts) stays off without marketing consent. Google Analytics retains event data for two months. Cookies: _ga (distinguishing visitors, 2 years) and _ga_* (session state, 2 years).
Marketing: Google Ads. Only with your marketing consent do we measure whether an ad on Google led to a registration or request (conversion tracking) and show visitors of our site Sunworker ads on Google again later (remarketing). The provider is likewise Google Ireland Limited. Cookies: _gcl_au and _gcl_aw (attribution of an ad click, 90 days) and IDE (advertising and measurement, 13 months). Google sets IDE on its own domain doubleclick.net; if you withdraw, we immediately delete the Google cookies on our domain, whereas IDE can only be removed in your browser or in your Google ad settings.
Transfer to the USA. Google may transfer data to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795); in addition, the European Commission’s standard contractual clauses apply (Implementing Decision (EU) 2021/914). Details in sections 18 and 19.
We do not use social media plugins. You can also delete or block cookies in your browser at any time; without the necessary cookies, however, you cannot sign in.
6. Registration, sign-in and account
For an account we process your email address, password, name, the roles you choose, and the time and version of your acceptance of the terms and this privacy notice. The password is not stored in plain text, only as a hash in the Supabase Auth sign-in service. The legal basis is Art. 6(1)(b) GDPR; for proof of which version you accepted, Art. 6(1)(f) GDPR.
To confirm your email address and to reset your password, you receive emails that Supabase Auth sends on our behalf.
Passkeys. If you create a passkey, we only store its public key and an identifier. Your fingerprint, face image or device PIN never leave your device and never reach us.
Sign-in with Google or Apple. If you choose this option, you are redirected to the provider, sign in there and agree to the data being shared. We receive the name, email address and an identifier of that account; with Apple, if you wish, only a relay address. The legal basis is Art. 6(1)(b) GDPR. The provider is itself responsible for processing on its side: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland.
Several people for one business. A business can invite further people into its account who act on its behalf. For this we process their email address, name and the permissions granted to them in order to provide shared access (Art. 6(1)(b) and (f) GDPR).
Account protection. Sign-in attempts are limited; administrative access is additionally protected with a second factor.
7. Profiles and certificates
Professionals provide their activities, hourly rate, experience, languages, travel radius, availability, a profile picture, optionally an introduction video, and certificates such as the certificate under Section 43 IfSG with issue and expiry dates. Businesses provide the name, type and address of the business, a contact person, billing details and a logo. The legal basis is Art. 6(1)(b) GDPR.
Only what makes up a profile for search is public: display name, picture, activities, hourly rate, city and postcode, experience, languages, reviews and the type of certificates with their validity. On the map, the location is rounded to about one kilometre. Being found as a professional is part of the service you agree with us (Art. 6(1)(b) GDPR).
Uploaded documents are never public. They are kept in non-public storage and can only be retrieved via short-lived signed addresses that our server issues to authorised people.
8. Checks before approval
Before an account is approved, we check documents: an identity document for private individuals and professionals, and additionally a business registration or commercial register extract for businesses and professionals. The purpose is to prevent fake accounts, fraud and identity misuse. The legal basis for the business documents is Art. 6(1)(b) and (f) GDPR. You upload a copy of your identity document only with your explicit consent (Art. 6(1)(a) GDPR, Section 20(2) of the German Identity Card Act).
You may black out anything on the copy that is not needed for the check, in particular the access number and serial number. You can withdraw your consent at any time; before the decision, this means that the check cannot be completed and the account cannot be approved.
Only the people handling the check can see the documents; every access is logged. A human decides on approval. Copies of identity documents are deleted 30 days after the decision; we only keep a record that a check took place, when, and with what result.
Professionals who receive payouts also go through the legally required identity check at Stripe (section 13). If you upload your identity document to us for this purpose, we pass the file on to Stripe and then delete it on our side.
9. Search, matching and carrying out assignments
For the radius search we convert postcodes and addresses into coordinates (section 17). Businesses and private individuals see the public profiles of suitable professionals in the search; how results are ordered is explained under How we sort.
When a client sends a request, the professional receives the type, place, date and times of the assignment and the client’s name. The professional decides freely whether to accept or decline. If the assignment goes ahead, both sides receive the information needed to carry it out: names, location, times, the agreed hourly rate and the contact person on site.
Check-in and check-out times are recorded at the start and end of an assignment because the actual duration determines the invoice. Declines, cancellations and no-shows are recorded with their time because the cancellation rules depend on them. The legal basis in each case is Art. 6(1)(b) GDPR.
Location at check-in and check-out. As a professional you can consent to us saving your location when you check in and out – as your own proof that you were at the place of the assignment. This is voluntary; without consent, checking in works just the same. The location is only requested at the moment you check in or out, in the app via the device location and in the browser via its location request; there is no background tracking and no tracking between check-in and check-out. We only save a point rounded to about 100 m, never your exact location. The client only sees that a location was recorded and the time of the check-in or check-out, no coordinates. We delete the location as soon as the assignment is completed or has ended, at the latest after 30 days; if a no-show has been reported, it remains stored as your evidence for an objection until these 30 days have passed. The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time in the settings; we then immediately delete all saved locations of your account. This does not affect the lawfulness of processing before the withdrawal.
We use the availability that professionals enter to show only bookable professionals for a chosen day. Clients can save professionals as “Known professionals” in order to request them again later; only the link is stored (Art. 6(1)(b) GDPR).
10. Private individuals as clients
A private individual’s address is also the billing address and often the venue of the event. The booked professional only receives it once the assignment is confirmed, and only to the extent needed for travel and invoicing (Art. 6(1)(b) GDPR). Before that, the professional sees at most the city and postcode. Addresses and contact details are not shown in messages or applications.
After the assignment, the address appears on the invoice, which is retained for the statutory periods (section 20).
11. Messages
Clients and professionals can exchange messages about an assignment; the conversation is always started by the client. We process the content, attachments, time and read status in order to deliver the messages (Art. 6(1)(b) GDPR).
Phone numbers, email addresses, postal addresses, links to social networks and similar contact details are automatically masked before display. This protects both sides from harassment and fraud and keeps the transaction on the platform, where payment and certificates are stored (Art. 6(1)(f) GDPR).
Messages are automatically checked for insults, threats, fraud and similar violations (section 16). A conspicuous message is not blocked automatically but flagged and reviewed by a human. Reported conversations can only be seen by the people handling the review.
You can edit or delete your own messages within 15 minutes and block a conversation. We delete attachments that have not been accessed for two years.
12. Reviews
After a completed assignment, the client and the professional can review each other. For this we process the overall rating, individual ratings, comment, a reply, a private note and the link to the assignment. The legal basis is Art. 6(1)(f) GDPR: users’ interest in reading genuine experiences before booking, and our interest in a reliable marketplace.
Both reviews stay hidden until both sides have submitted theirs or 14 days have passed, so nobody can adjust their own review to the other side’s. Whoever is reviewed can reply publicly and report a review.
Reviews appear publicly with first name and initial or the name of the business, the role and the month of the assignment – never with price, address or contact details; phone numbers, email addresses, postal addresses and links are masked before display. Anyone who reviews anonymously appears without name and picture, only with the type and city of the business or the role. We publish anonymous reviews in batches: only once there are at least three for the same professional or business, at the latest 30 days after the oldest, all with the same date. Internally the author remains known so that abuse can be investigated. Only the reviewed side sees the private note.
Reviews are checked automatically before publication (section 16). A conspicuous review only appears after a human has checked it. How we check reviews and how you can complain is explained under How we check reviews.
If an account is deleted, its reviews are anonymised: name and picture are removed, the private note is deleted, and rating and text remain without personal reference so that the other side’s reviews are not distorted. A withdrawn review only appears as an empty placeholder. You can object to the publication of a review about you under Art. 21 GDPR; we then weigh the interests in the individual case.
12a. Reports and statements of reasons
Reports without an account. You can report illegal content without an account via the form at sunworker.eu/melden (Art. 16 of Regulation (EU) 2022/2065 on digital services). For this we process your name, your email address, the location of the content, the reason and your explanation, your statement that the information is accurate and complete, the language of the form and a hash of your IP address. We use the hash only to limit abusive mass reports. The purpose is the notice and action procedure; the legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 16 of Regulation (EU) 2022/2065.
We send the confirmation of receipt and the outcome to your email address from our own mail server, which runs on our API server (section 4). The person whose content you report does not learn your name or your email address. We store reports made without an account until six months after the report has been closed.
Statements of reasons. If we hide a message, hide a review or suspend an account, the person concerned receives a statement of reasons (Art. 17 of Regulation (EU) 2022/2065). For each measure we store the facts and circumstances, the ground – the provision of the terms or the legal provision –, whether automated means were involved, whether a report was the reason, who decided, and a reference number. The statement of reasons appears in the account under “Notifications” and is kept for as long as the account exists. The legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 17 of Regulation (EU) 2022/2065.
13. Payments, payouts and invoices
We process payments and payouts via Stripe (Stripe Payments Europe, Limited, The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland). Clients add a payment method. You enter card and account details directly into Stripe’s input fields; they never reach our systems. We only receive information such as the card brand, the last four digits and the result of the payment.
Professionals set up an account with Stripe for payouts. Stripe collects the legally required information – such as name, address, date of birth, identity document, bank details and, where applicable, tax number – and checks it under anti-money-laundering rules. We receive from Stripe the status of the check and whether payouts are possible. As long as payouts are not set up, a professional can receive requests but cannot accept them – so that no assignment arises that cannot be paid.
Insofar as Stripe carries out payments on our behalf, Stripe is our processor. For fraud prevention, identity verification and compliance with anti-money-laundering and regulatory law, Stripe is itself responsible; Stripe’s privacy policy applies to this (stripe.com/privacy). Stripe may transfer data to Stripe, Inc. in the USA (section 19). The legal basis is Art. 6(1)(b) and (c) GDPR, and for fraud prevention Art. 6(1)(f) GDPR.
Invoices. For every completed assignment we issue the professional’s invoice to the client in the professional’s name (invoicing by a third party). In doing so we act on behalf of the professional: the professional is the controller for this invoice, and the basis is our data processing agreement under Art. 28 GDPR. We issue our own invoice for the commission or service fee as controller. Invoices contain names, addresses, where applicable tax number or VAT identification number, date of service, hours and amounts. The legal basis for our own invoice and for the retention we are obliged to carry out ourselves is Art. 6(1)(b) and (c) GDPR.
Reporting obligation as a platform operator. Under Directive (EU) 2021/514 (DAC7) and the national implementing laws, operators of digital platforms must report certain information about providers of personal services – such as name, address, date of birth, tax identification number, bank details and the remuneration paid and fees withheld – once a year to the competent tax authority. We report to the Cypriot tax administration (Tax Department), which forwards the information to the state in which the provider is resident – in Germany, to the Federal Central Tax Office (Bundeszentralamt für Steuern). The legal basis is Art. 6(1)(c) GDPR.
Add-ons and accounting software. You can connect your Sunworker account to an accounting program (currently Lexware Office or sevDesk) or download a DATEV export. If you connect a program, we transfer your documents to it: invoice number, date, amounts, tax rates, the name of the other party and the invoice PDF. We only transfer what you set up: individual documents, all new documents automatically, or older documents as well. In doing so we act on your behalf; the basis is our data processing agreement, which you accept when connecting. The accounting program is your own service provider; processing there is governed by your contract with the provider. We store your API key encrypted and show only its last four characters. If you disconnect, we delete the key; documents already transferred remain in the accounting program.
14. Calendar
You can subscribe to your assignments and blocked days as a calendar feed (iCal). You receive a personal address with a secret key, of which we only store a hash. You can renew the key at any time; the old address then stops working (Art. 6(1)(b) GDPR).
If you wish, you can connect Sunworker to your Google Calendar. Sunworker then creates a separate calendar “Sunworker” in your Google account and enters your assignments there. We only receive permission for this one calendar created by Sunworker (calendar.app.created) and your Google email address; we cannot see your other calendars or appointments. We store the access token encrypted. The legal basis is your consent (Art. 6(1)(a) GDPR).
You can disconnect at any time in your account; we then delete the token and, if you wish, the Sunworker calendar. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Calendar is provided by Google Ireland Limited (section 18).
15. Notifications
We inform you about new requests, acceptances, messages and other events in your account and, while the site or app is open, in real time via an encrypted connection to our server. Only identifiers are transmitted; your device then loads the content from us (Art. 6(1)(b) GDPR).
In the app you can allow push notifications. For this, Firebase Cloud Messaging (Google) creates a device token that we store with your account; the notification contains a short note about the event. The legal basis is your consent via your device’s prompt (Art. 6(1)(a) GDPR, Section 25(1) TDDDG); you can withdraw it at any time in your device settings.
You choose what you want to be notified about in your account settings.
15a. Contact management, newsletter and waiting list
Contact management for all accounts. When you create an account – with an email address or via Google or Apple – we additionally store your email address, your name, your account type (professional, business, private individual or staffing agency), your language and an internal identifier of your account as a contact with Brevo, together with whether, when and how you ordered and confirmed the newsletter. We use this to send you information about your account and the service, for example about changes to features, terms or processes that affect you as a user. The legal basis is Art. 6(1)(b) GDPR (performance of the user agreement) and, where information goes beyond this, our legitimate interest in orderly communication with our users (Art. 6(1)(f) GDPR). You do not receive advertising this way.
If you sign up for our newsletter or for the waiting list, we will inform you by email about news on Sunworker or about when you can use Sunworker. For this we process your email address and any further information you voluntarily provide in the sign-up form. The legal basis is your consent (Art. 6(1)(a) GDPR).
Newsletter with an account. If you have an account, we only send you the Sunworker newsletter with news and tips if you expressly order it when registering or in your account settings – the box is never pre-ticked – and confirm the order via the link in our confirmation email (double opt-in). The legal basis is your consent (Art. 6(1)(a) GDPR, Section 7(2) no. 2 UWG). As proof we store the time of the order, the route (registration or settings), the version of the consent text, your language and the time of confirmation; Brevo additionally logs the confirmation.
Double opt-in. After signing up you receive an email with a confirmation link; only once you click it do we add you to the mailing list. This way nobody can sign up someone else’s email address. We log the time of sign-up and confirmation and the IP address used, so that we can prove your consent (Art. 7(1) GDPR). The legal basis for this is our duty to demonstrate compliance (Art. 6(1)(c) in conjunction with Art. 5(2) GDPR) and our legitimate interest in being able to prove the consent (Art. 6(1)(f) GDPR).
Sending via Brevo. Contact management, sign-up, management of the mailing list and sending are handled for us by the Brevo service of Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France, as a processor on the basis of a contract under Art. 28 GDPR (section 18). The emails come from the sender domain news.sunworker.eu. Brevo stores the data in data centres in France and Belgium; for access from third countries see section 19.
Open and click tracking. We only measure whether an email was opened and which link in it was clicked if you expressly consented to this when signing up (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). Without this consent, tracking is switched off for your address. You can withdraw your consent at any time with effect for the future, for example with a message to us (section 1); we will then switch tracking off for you.
Unsubscribing and storage period. You can unsubscribe from the newsletter and the waiting list at any time via the unsubscribe link in every email – from the newsletter with an account also in your account settings under “Newsletter” – which withdraws your consent (Art. 7(3) GDPR); the lawfulness of the processing carried out until then remains unaffected. Without an account we store your data until you unsubscribe and then keep only your email address on a suppression list so that you receive no further emails from us; the legal basis is our legitimate interest in permanently respecting your unsubscription (Art. 6(1)(f) GDPR). With an account you remain a contact for account and service information after unsubscribing from the newsletter, for as long as your account exists.
Deleting your account and proof of consent. If you delete your account, we also delete your contact at Brevo. We keep the proof of a newsletter consent – time, route, version of the text, language and confirmation, without your email address – until the regular limitation period has expired: three years from the end of the year in which you withdrew the consent or deleted your account (Sections 195, 199 BGB). The legal basis is our obligation to be able to demonstrate the consent (Art. 6(1)(c) in conjunction with Art. 5(2) and Art. 7(1) GDPR) and our legitimate interest in being able to defend ourselves against claims (Art. 6(1)(f) GDPR).
16. Artificial intelligence: text checks, translation, invoices and Sunny
We use the Gemini AI model via Google Cloud Vertex AI in the europe-west3 region (Frankfurt am Main, Germany) for these tasks: checking messages and reviews for insults, threats, fraud and the sharing of contact details, translating profile texts, reviews and messages when you choose to display a translation, reading invoices and our support assistant Sunny.
Only the text in question is sent to the model, not your account. In messages and reviews we make contact details unrecognisable beforehand. Profile texts – such as “About me”, FAQs or the description of a business – are sent to the model for translation as they were written; if they contain a name, the model sees it. Google processes the texts as our processor and, under its contract terms, does not use them to train its own models. We cache translations so that the same text does not have to be translated again.
The legal basis for the checks is Art. 6(1)(f) GDPR – our interest and that of our users in a marketplace free of harassment and fraud; for translation, Art. 6(1)(b) GDPR. What follows from a check result is explained in section 24.
Reading invoices. When a professional uploads their invoice as a PDF, the model reads the invoice number, invoice date and amounts and suggests them for the form. For this, the whole document is sent to the model, with everything it contains – such as names, addresses and tax number. We do not store the suggestion; what counts is what the professional then checks and confirms. The legal basis is Art. 6(1)(b) GDPR.
Sunny. Sunny is an AI assistant, not a human, and answers questions about Sunworker in the support chat on the website, also without an account. Sunny only answers if the answer is based on a source from our knowledge base; otherwise, or if you wish, a human from our support takes over. The model receives your question and up to ten previous messages of the conversation, cleaned beforehand of payment data, contact details, addresses and your name, and for signed-in users also the setup status of the account (steps and missing details, no content). We store the conversation with card and account numbers made unrecognisable, the language, the page on which you started it, your email address if you choose to give it for a handover and, if you are signed in, the link to your account. So that you can continue the conversation, your browser keeps an identifier in local storage (§ 25(2) no. 2 TDDDG). We delete closed conversations after 90 days and open ones after 30 days without activity. The legal basis is Art. 6(1)(f) GDPR – our interest in answering questions quickly and correctly – and, for questions about your account, Art. 6(1)(b) GDPR.
Knowledge base. The sources Sunny relies on come from public Sunworker content such as the help centre, FAQs and the pages of the website, not from accounts. To find matching passages, we convert these texts and your cleaned question into numerical vectors using a language model – via Vertex AI as above or on our own server.
Labelling. We label what an AI produces (Art. 50 of Regulation (EU) 2024/1689 on artificial intelligence): Sunny introduces itself as an AI assistant and every answer bears the sender “Sunny · AI”; translated texts are labelled as automatic translations. Answers from Sunny, translations and reply suggestions that our support has drafted by the AI also carry the identifier of the model used in machine-readable form.
17. Addresses, maps and embedded content
Postcodes and radius. For the radius search, our server asks the Nominatim service of the OpenStreetMap Foundation (St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom) for the coordinates of a postcode or place. Only the search term is transmitted, not your IP address; we cache the results. The legal basis is Art. 6(1)(f) GDPR – an accurate radius search.
Address entry and travel. Our server requests address suggestions and travel times to assignment locations from Google Maps Platform (Places API, Routes API). Google receives the address entered or the start and destination coordinates, not your IP address. The legal basis is Art. 6(1)(b) GDPR.
Maps. We display maps with Google Maps. On the website, a map does not load by itself: as long as you have not consented, a notice takes its place, and only “Load map once” loads that one map. With “Always allow” or the “External content” category in the cookie settings, you consent permanently; the map then loads in the search as soon as you expand it, and on a professional’s profile as soon as the section on the service area becomes visible. When it loads, your device connects to Google: Google receives your IP address and technical information about your browser or device and may set cookies on its own domains, such as NID (6 months); no cookies are set on sunworker.eu as a result. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG); you can withdraw it at any time with effect for the future via the cookie settings. In the app, a map loads when you open a map view. Google is itself responsible for this processing under the Google Maps Controller-Controller Data Protection Terms; the provider is Google Ireland Limited.
Videos. If a professional has linked a YouTube video, it is only loaded when you click play, in privacy-enhanced mode (youtube-nocookie.com); before that, no request goes to Google, not even for a preview image. Without permanent consent, a notice is shown with the video, and clicking play is your consent for that one video. With “Always allow” or the “External content” category, you consent for all videos; a click is still required, and no video starts by itself. When the video plays, Google receives your IP address and may set cookies on youtube-nocookie.com, such as YSC (session) and VISITOR_INFO1_LIVE (6 months). The legal basis is Art. 6(1)(a) GDPR, Section 25(1) TDDDG; you can withdraw your consent at any time via the cookie settings. The provider is Google Ireland Limited.
Icons. The site loads some of its icons from the Iconify service (Iconify OÜ, Estonia) via api.iconify.design and its fallback servers. Iconify receives your IP address; no cookies are set. The legal basis is Art. 6(1)(f) GDPR – a consistent, fast-loading presentation.
Fonts. The fonts used are served from our own domain. No connection to Google Fonts is made when you visit the site.
18. Recipients and service providers
We only pass on data where this is necessary for the purposes stated. Service providers working on our behalf are contractually bound by our instructions under Art. 28 GDPR (processors). Where a provider is itself responsible, we say so.
VercelWebsite hosting
- Provider
- Vercel Inc.
- Address
- 440 N Barranca Avenue #4133, Covina, CA 91723, USA
- Purpose
- Hosting and delivery of the website, server functions, logs.
- Role
- Processor.
- Transfer to third countries
- Transfer to the USA on the basis of the EU-U.S. Data Privacy Framework, supplemented by standard contractual clauses.
Prepaid-Hoster.deServer for our API
- Provider
- Henrik Kramer e.K. (Prepaid-Hoster.de)
- Address
- Kurpromenade 48, 23743 Grömitz, Germany
- Purpose
- Server for our API in the maincubes FRA01 data centre in Offenbach am Main.
- Role
- Processor.
- Transfer to third countries
- No transfer to third countries.
SupabaseDatabase, sign-in, files
- Provider
- Supabase Pte. Ltd.
- Address
- 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513
- Purpose
- Database, sign-in service (Supabase Auth) and file storage (Supabase Storage); accounts, profiles, assignments, messages, reviews, invoices and uploaded files are stored here.
- Role
- Processor; data processing agreement under Art. 28 GDPR.
- Transfer to third countries
- The data centres are operated by Amazon Web Services; since 26 September 2026 the database, authentication service and file storage have been running in the eu-central-1 region in Frankfurt am Main (EU). The data are stored and processed there; no transfer to third countries is intended for this. Only where Supabase accesses data in individual cases for maintenance, troubleshooting and support from Singapore or through sub-processors in the USA do the standard contractual clauses apply (section 19).
StripePayments and payouts
- Provider
- Stripe Payments Europe, Limited
- Address
- The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland
- Purpose
- Payments, payouts, identity verification and fraud prevention (section 13).
- Role
- Partly processor, partly itself responsible.
- Transfer to third countries
- Transfer to the USA on the basis of the EU-U.S. Data Privacy Framework and standard contractual clauses.
TwilioSMS confirmation of your phone number
- Provider
- Twilio Ireland Limited
- Address
- 70 Sir John Rogerson’s Quay, Dublin 2, D02 R296, Ireland
- Purpose
- Sending and checking the confirmation code by SMS (Twilio Verify) with which you confirm your phone number; a confirmed number is required for your account to be approved. Twilio receives only the phone number and the code entered.
- Role
- Processor.
- Transfer to third countries
- Possible transfer to Twilio Inc. in the USA on the basis of the EU-U.S. Data Privacy Framework, supplemented by standard contractual clauses.
BrevoContact management, newsletter and waiting list
- Provider
- Sendinblue SAS
- Address
- 106 boulevard Haussmann, 75008 Paris, France
- Purpose
- Contact management for account and service information, sign-up with double opt-in, management of the mailing list and sending of the newsletter and waiting list emails (section 15a). Data is stored in data centres in France and Belgium.
- Role
- Processor; data processing agreement under Art. 28 GDPR.
- Transfer to third countries
- Storage in the EU. For possible access by Brevo group companies in the USA and India, for example for support and maintenance, and for sub-processors in the USA, the EU-U.S. Data Privacy Framework applies where the recipient is certified, as do the standard contractual clauses (section 19).
Google CloudMaps, text checks, push notifications
- Provider
- Google Cloud EMEA Limited
- Address
- 70 Sir John Rogerson’s Quay, Dublin 2, Ireland
- Purpose
- Google Maps Platform (address suggestions, travel times, maps), Vertex AI (text checks, translation, reading invoices, Sunny and knowledge base) and Firebase Cloud Messaging (push notifications).
- Role
- Processor for Vertex AI and Firebase, itself responsible for Google Maps Platform.
- Transfer to third countries
- Possible transfer to Google LLC in the USA on the basis of the EU-U.S. Data Privacy Framework, supplemented by standard contractual clauses.
GoogleSign-in, Calendar, YouTube
- Provider
- Google Ireland Limited
- Address
- Gordon House, Barrow Street, Dublin 4, Ireland
- Purpose
- Sign-in with Google, Google Calendar and YouTube videos (sections 6, 14 and 17).
- Role
- Itself responsible for processing in your Google account.
- Transfer to third countries
- Possible transfer to the USA as above.
Google Analytics and Google AdsAudience measurement and advertising – only with consent
- Provider
- Google Ireland Limited
- Address
- Gordon House, Barrow Street, Dublin 4, Ireland
- Purpose
- Audience measurement (Google Analytics 4) and conversion tracking and remarketing (Google Ads), each only with your consent (section 5). Processed data: truncated IP address, device and browser information, pages viewed, events and a random client ID.
- Role
- Processor, audience measurement and advertising – only with consent.
- Transfer to third countries
- USA: Google LLC, certified under the EU-US Data Privacy Framework (Decision (EU) 2023/1795); in addition, standard contractual clauses (2021/914).
AppleSign-in with Apple
- Provider
- Apple Distribution International Ltd.
- Purpose
- Only if you choose to sign in with Apple (section 6).
- Role
- Itself responsible.
OpenStreetMapCoordinates for places
- Provider
- OpenStreetMap Foundation
- Registered office
- Cambridge, United Kingdom
- Purpose
- Coordinates for postcodes and places (section 17).
- Role
- Itself responsible.
- Transfer to third countries
- An adequacy decision of the European Commission exists for the United Kingdom.
IconifyIcons
- Provider
- Iconify OÜ
- Registered office
- Estonia
- Purpose
- Delivery of icons (section 17).
- Role
- Itself responsible.
Other usersBetween clients and professionals
Clients and professionals receive from each other the data needed to request, carry out and invoice an assignment (sections 9 to 13). Anyone who receives the other side’s data in this way is itself responsible for processing it and uses it only for the assignment and its invoicing. Public profiles and published reviews are visible to all visitors.
Authorities and advisersTax office, courts, tax advisers
We only pass data to tax authorities, law enforcement or courts if we are legally obliged to do so (Art. 6(1)(c) GDPR) or if it is necessary to establish, exercise or defend legal claims (Art. 6(1)(f) GDPR). Tax advisers and auditors who are bound by statutory confidentiality receive the accounting records.
19. Transfers to third countries
Some service providers are located outside the EU and the EEA or access data from there. We only transfer data there if the conditions of Art. 44 et seq. GDPR are met.
USA. For companies certified under the EU-U.S. Data Privacy Framework – Vercel, Stripe, Google and Twilio – the European Commission’s adequacy decision of 10 July 2023 applies (Implementing Decision (EU) 2023/1795, Art. 45 GDPR), which the General Court of the European Union upheld on 3 September 2025 (Case T-553/23). For recipients without certification, and in addition, the European Commission’s standard contractual clauses apply (Implementing Decision (EU) 2021/914, Art. 46(2)(c) GDPR).
Singapore. The database is located in Frankfurt (section 18); standard contractual clauses apply to access by Supabase Pte. Ltd. in individual cases, for example for maintenance and support. United Kingdom. The European Commission’s adequacy decision applies to the OpenStreetMap Foundation (Art. 45 GDPR). India and USA (Brevo). Brevo stores the newsletter and waiting list data in the EU (section 18). For access in individual cases by Brevo group companies in India and the USA, for example for support and maintenance, and for Brevo’s sub-processors in the USA, the standard contractual clauses apply, and for certified US recipients additionally the EU-U.S. Data Privacy Framework.
You can obtain a copy of the standard contractual clauses on request at kontakt@sunworker.eu.
20. Retention
We only keep personal data for as long as it is needed for the relevant purpose or required by law. Once the purpose no longer applies and no retention period is running, we delete or anonymise the data.
Account and profile: until the account is deleted, which you can request at any time at kontakt@sunworker.eu. We then delete or anonymise the data unless a retention obligation prevents this.
Invoices and accounting vouchers: eight years; books and annual financial statements ten years – in each case from the end of the calendar year in which they were created (Section 147 of the German Fiscal Code, Section 257 of the German Commercial Code, Section 14b of the German VAT Act). Cypriot law requires six years for tax records and seven years for VAT; the longer period applies in each case. After an account is deleted, these records are restricted and only accessible for accounting, tax audits and authorities.
Assignments, messages and reviews: as long as the account exists; beyond that, to defend against claims, until the limitation period expires, usually three years from the end of the year in which the assignment took place. Reviews are anonymised when an account is deleted (section 12). We delete message attachments that have not been accessed for two years.
Other periods: copies of identity documents 30 days after the approval decision; deleted files permanently 30 days after deletion; server logs at most 30 days; reports without an account six months after the report has been closed; conversations with Sunny 90 days after they end, open ones after 30 days without activity; cookies as stated in section 5; Google Calendar token until you disconnect; push token until you turn off notifications or the token becomes invalid; newsletter and waiting list until you unsubscribe, after that only the email address on a suppression list; contact at Brevo until the account is deleted; proof of a newsletter consent three years from the end of the year of withdrawal or account deletion (section 15a).
Backups: we keep daily backups for 7 days, weekly backups for 4 weeks and monthly backups for 3 months. Deleted data is therefore also removed from the backups after about 3 months at the latest.
21. Your rights
You have the right of access to the data stored about you (Art. 15 GDPR), to rectification of inaccurate data (Art. 16 GDPR), to erasure (Art. 17 GDPR), to restriction of processing (Art. 18 GDPR) and to receive the data you have provided to us in a commonly used machine-readable format or have it transmitted to another controller (Art. 20 GDPR).
Right to object under Art. 21 GDPR. Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
Withdrawing consent. You can withdraw any consent – for example for the identity document copy, the Google Calendar connection, push notifications or playing a video – at any time with effect for the future (Art. 7(3) GDPR). The lawfulness of processing carried out until then remains unaffected.
For all requests, an email to kontakt@sunworker.eu is enough. We reply within one month, in complex cases within at most three months, in which case we will let you know beforehand (Art. 12(3) GDPR). If we have reasonable doubts that the request comes from you, we ask for confirmation, for example via the email address stored in your account. Access and a copy are free of charge.
22. Right to lodge a complaint
If you believe that the processing of your data infringes the GDPR, you can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority competent for us is the one where we are established: Commissioner for Personal Data Protection, Kypranoros 15, 1061 Nicosia, Cyprus; postal address: P.O. Box 23378, 1682 Nicosia; phone +357 22 818 456; email commissioner@dataprotection.gov.cy; website www.dataprotection.gov.cy.
You can equally contact the supervisory authority of your habitual residence, your place of work or the place of the alleged infringement – in Germany, for example, the data protection authority of your federal state. It will forward the complaint to the Cypriot authority where necessary.
23. Obligation to provide data
You are under no statutory or contractual obligation to provide us with data. Without the information marked as required in the account, however, we cannot conclude a user agreement, arrange an assignment or process a payment. The information for the identity check for payouts and for reporting to tax authorities is required by law; without it, payouts are not possible. The log data generated when you visit the site is technically necessary.
24. Automated decision-making and profiling
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). In detail:
Ordering of search results. We calculate the order of professionals in the search automatically from availability on the chosen day, distance, average rating, number of reviews and number of completed assignments. This is an ordering, not a decision about a contract: every suitable professional remains findable, and clients choose for themselves. We explain the criteria and their order under How we sort.
Text checks. The automated check of messages and reviews (section 16) only flags; a human decides on consequences such as hiding a review or suspending an account. A review that the procedure flags or cannot check only appears after this review; none is rejected automatically.
Approval and payouts. A human decides on the approval of an account after checking the documents. That a professional without payouts set up cannot accept requests is a fixed rule, not an assessment of the person.
25. Data security
We protect your data with technical and organisational measures under Art. 32 GDPR, including: encrypted transmission (TLS); files in non-public storage, retrievable only via short-lived signed addresses; encrypted storage of access tokens for third-party services; logging of every access to verification documents; two-factor sign-in for administrative access; limits on sign-in and request attempts; and an architecture in which only our own server accesses the database, never the browser.
26. Changes to this notice
We update this notice when our processing or the legal situation changes. The version stated above with number and date applies. We inform registered users of material changes in their account before they take effect.
Version 1.2 of 26 September 2026: sections 18 and 19 – database hosting in Frankfurt.
Version 1.3 of 30 September 2026: sections 9, 13, 16, 18, 19 and 20 – location at check-in and check-out, invoices on behalf of the professional, add-ons and accounting software, text checks in Frankfurt, Twilio as recipient, retention periods for backups.
Version 1.4 of 1 October 2026: section 5 – sw-agency cookie for the selected agency.
Version 1.5 of 8 October 2026: sections 12a, 16, 18, 20 and 24 – reports without an account and statements of reasons, AI functions with translation of profile texts, reading invoices, Sunny, knowledge base and labelling, retention of reports, review checks.
Version 1.6 of 8 October 2026: sections 1, 2, 5, 6, 12, 15a, 18, 19, 20 and 22 – the controller is The Freelancer Crew Andy Staudinger e. K. in Mittenwalde, supervision by the LDA Brandenburg, no sign-in with Facebook, batched publication of anonymous reviews, clients and professionals as controllers in their own right for the other side’s data, newsletter and waiting list via Brevo.
Version 1.7 of 8 October 2026: sections 1, 13, 15a, 18, 20 and 22 – the controller is Sunworkers Ltd. in Paphos (Cyprus), the Cypriot data protection law applies in addition, DAC7 reporting to the Cypriot tax administration, the contracting party for Brevo is Sendinblue SAS in Paris, supervision by the Cypriot data protection authority, retention periods under Cypriot law.
Version 1.8 of 8 October 2026: sections 15a, 18 and 20 – all accounts as contacts at Brevo for account and service information, newsletter with an account only after ordering and double opt-in, unsubscribing in the account settings, retention period of the proof of consent.