Privacy Policy

# Privacy policy
 
Last updated: 27 July 2026
 
This English translation is provided for convenience. In the event of any
discrepancy or difference in interpretation, the German version shall prevail.
 
## 1. Privacy at a glance
 
### General information
 
The following information explains what happens to personal data when you visit
our website or use Bull Business Suite. Personal data means any information
that can be used to identify you personally.
 
### Controller
 
The controller responsible for data processing is:
 
Bull Advertising Günce  
Owner: Tahsin Günce  
Am Stausee 24  
55585 Niederhausen  
Germany
 
Phone: +49 162 9127922  
Email: info@bulladvertising.de  
Support: support@bulladvertising.de
 
### How do we collect data?
 
We process information you provide to us, for example through the contact form,
by email or through the Google form used to register for a software test.
Technically necessary connection data is also generated when you visit the
website. Optional external services are loaded only after you have given your
consent.
 
### Why do we use data?
 
We process data to provide and secure the website, respond to enquiries, take
steps prior to entering into a contract, organise software tests and, with your
consent, provide Google Maps and the visitor counter.
 
## 2. General information and your rights
 
### Legal bases
 
Depending on the processing activity, we rely in particular on:
 
- Article 6(1)(a) GDPR (consent);
- Article 6(1)(b) GDPR (contract and pre-contractual measures);
- Article 6(1)(c) GDPR (legal obligation); and
- Article 6(1)(f) GDPR (legitimate interests, in particular the secure and
  economical operation of our website and the handling of enquiries).
 
### Retention period
 
We retain personal data only for as long as necessary for the relevant purpose.
It is then deleted unless statutory retention obligations or legitimate reasons
require continued storage.
 
### Withdrawal of consent
 
You may withdraw consent at any time with effect for the future. The lawfulness
of processing carried out before withdrawal remains unaffected.
 
### Right to object
 
Where processing is based on Article 6(1)(f) GDPR, you may object on grounds
relating to your particular situation.
 
### Access, rectification, erasure and restriction
 
Subject to the statutory requirements, you have the right to access,
rectification, erasure, restriction of processing and, where applicable, data
portability.
 
### Right to lodge a complaint
 
You may lodge a complaint with a data protection supervisory authority. The
authority particularly competent for our registered place of business is:
 
The State Commissioner for Data Protection and Freedom of Information of
Rhineland-Palatinate  
Hintere Bleiche 34  
55116 Mainz  
Germany  
Phone: +49 6131 8920-0  
Email: poststelle@datenschutz.rlp.de  
Website: https://www.datenschutz.rlp.de/
 
## 3. Hosting and provision of the website
 
Our website is hosted by:
 
ALL-INKL.COM – Neue Medien Münnich  
Owner: René Münnich  
Hauptstraße 68  
02742 Friedersdorf  
Germany
 
When the website is accessed, the hosting provider processes technically
necessary server log data. This may include the IP address, date and time,
requested resource, referrer URL, browser type, operating system and transfer
status. Processing serves the secure and reliable provision of the website and
the prevention of misuse. The legal basis is Article 6(1)(f) GDPR. Server logs
are generally retained only for as long as necessary for operation and
security, in accordance with the provider's information and our hosting
configuration.
 
Where required, we have concluded a data processing agreement with the hosting
provider.
 
### SSL/TLS encryption
 
This website uses SSL/TLS encryption. An encrypted connection can generally be
identified by `https://` and the padlock symbol in your browser.
 
## 4. Contacting us
 
### Contact form and email
 
If you contact us through the contact form or by email, we process the
information and contact details you provide in order to handle your enquiry and
any follow-up questions.
 
For contractual or pre-contractual enquiries, the legal basis is Article
6(1)(b) GDPR. In other cases, processing is based on our legitimate interest in
efficiently handling your enquiry under Article 6(1)(f) GDPR or, where
requested, on your consent under Article 6(1)(a) GDPR.
 
The data is deleted once the enquiry has been finally resolved and no statutory
retention obligations or other legitimate reasons require continued storage.
 
## 5. Registration for software tests using Google Forms
 
For registration for the Bull Business Suite test phase, we provide a link to a
Google Forms form. For users in the European Economic Area, the provider is
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
 
The form stores your name, postal address and email address. We process this
information to register test participants, provide the download link, handle
enquiries and administer the test phase.
 
The legal basis is Article 6(1)(b) GDPR where processing is necessary for
pre-contractual measures or the requested software test. Where consent is
requested, Article 6(1)(a) GDPR also applies.
 
When you open and complete the Google form, Google processes its own connection,
device and usage data. Processing in third countries, particularly the United
States, cannot be ruled out. According to Google, transfers are based on
applicable safeguards, in particular the EU-US Data Privacy Framework where the
recipient is certified, or the European Commission's Standard Contractual
Clauses.
 
We delete the data received from the form once it is no longer required to
organise and evaluate the software test, unless statutory retention obligations
or legitimate reasons require continued storage.
 
Further information: https://policies.google.com/privacy
 
## 6. Cookies, consent and external content
 
Technically necessary cookies or similar storage access may be used where
strictly necessary to provide a service expressly requested by the user.
Non-essential cookies and third-party services are loaded only after consent.
The legal bases are Section 25 TDDDG and Article 6(1)(a) GDPR.
 
You may withdraw consent at any time with effect for the future. Depending on
the consent solution used, you can change your privacy settings on the website
or delete the relevant cookies and revisit the page without reactivating the
service.
 
## 7. Google Maps
 
We use Google Maps exclusively through a two-click solution. The map is not
loaded and no connection to Google Maps is established when the page is first
opened. A connection to Google is established only after you activate the map.
 
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4,
Ireland. Its parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain
View, CA 94043, USA.
 
After activation, your IP address, access time, browser and device data and your
interactions with the map may be processed. If you are signed in to a Google
account, Google may associate the use with your account.
 
The legal bases are your consent under Article 6(1)(a) GDPR and, where
information is stored on or read from your device, Section 25(1) TDDDG. Data may
be transferred to the United States. Information about the safeguards used by
Google is available in Google's privacy policy:
 
https://policies.google.com/privacy
 
## 8. Visitor counter from besucherzaehler-kostenlos.de
 
After you have given consent, we load an external visitor counter from
`besucherzaehler-kostenlos.de`. The service helps us determine the number of
page views. JavaScript is loaded from the provider's servers, which means that
the provider may receive your IP address, time of access, requested domain and
technical connection data.
 
According to the provider, the IP address is anonymised and retained in a log
file for a limited period. The service also sets a session cookie to determine
whether a visit has already been counted. According to the provider, the cookie
does not contain directly identifying content and is normally deleted when the
browser is closed.
 
The visitor counter is loaded only after your consent. The legal bases are
Article 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw consent at any
time with effect for the future.
 
Provider information: https://www.besucherzaehler-kostenlos.de/
 
## 9. Data protection in Bull Business Suite
 
### Local business data
 
Bull Business Suite is a locally installed desktop application. Customer,
project, material, quotation, order, invoice and calculation data is generally
stored in a local application database on the user's device. Bull Advertising
does not receive automatic access to this business data.
 
The local database is not currently encrypted independently. Its protection
therefore depends in particular on the security of the Windows user account,
the device, any drive encryption, access permissions and secure backups. The
user is responsible for access control and backups of local business data.
 
### Local licence and trial management
 
The licence or trial period is currently validated locally. For this purpose,
the application stores a randomly generated installation identifier and
protected licence or trial-status data locally in application files and the
Windows Registry. This data is used for licence validation, prevention of
misuse and protection against circumvention of the trial period.
 
The installation identifier is not generated from hardware characteristics.
Under the current local validation process, the identifier, licence key and
trial status are not transmitted automatically to Bull Advertising.
 
### Update checks
 
During an update check, the application retrieves an update file from
`bulladvertising.de`. This necessarily generates connection data on the web
server, such as the IP address, time and application identifier transmitted by
the software. The comparison between available and installed versions takes
place within the application. Business data, local documents and SMTP
credentials are not transmitted.
 
The legal bases are Article 6(1)(b) GDPR, where the update function is part of
the user relationship, and Article 6(1)(f) GDPR. Our legitimate interest is the
secure provision, maintenance and updating of the software.
 
### Sending email from the software
 
Email credentials are entered by the user. The SMTP password is stored locally
in encrypted form using the protection mechanism of the current Windows user
account. When an email is sent, the message, recipient, document attachment and
other delivery data are transmitted directly through the email provider
configured by the user. Bull Advertising does not automatically receive these
messages. The user is responsible for the data-protection-compliant use of the
chosen email provider.
 
### Optional support diagnostic packages
 
A support diagnostic package is generated locally only at the user's express
request. It contains technical status information such as application version,
operating system, language, architecture, configuration status and a technical
database health check. The application is designed not to include business
databases, customer data, documents, attachments, passwords, tokens or complete
error logs in this package.
 
Transmission occurs only if the user actively sends the package to us. We use a
received package solely to process the support request and delete it when it is
no longer required, unless legal or security-related reasons require continued
storage.
 
## 10. Changes to this privacy policy
 
We update this privacy policy when legal requirements, our website or software
functions change. The current version is published on our website.

 

Bull Advertising Günce