4REACT

Privacy.

1. Controller and contact

4REACT UG (haftungsbeschränkt)
Represented by Jan Niklas Wilhelm (Managing Director)
Wetzlarer Str. 24, 14197 Berlin, Germany
Email: data-privacy@4react.com

We have not appointed a data protection officer and are not legally required to. Please send any question about your data to the address above.

2. Hosting, delivery and server logs

This website, the intranet, the artist app and our short links run on the network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, with Cloudflare Germany GmbH, Rosental 7, 80331 Munich. When a page is requested, technically necessary connection and security data is processed: IP address, time, requested address, browser and device information. The legal basis is our legitimate interest in secure, reliable delivery (Art. 6(1)(f) GDPR). Cloudflare acts as our processor (Art. 28 GDPR); transfers to the USA rely on the EU-US Data Privacy Framework and the EU standard contractual clauses. Our accounting data is held in a database restricted to the European Union.

If the website fails in your browser, it reports the error message and the address of the page, without anything you typed, so we can fix it (Art. 6(1)(f) GDPR). These reports are kept in our activity log.

3. Contact form and inquiries

When you send an inquiry, we process your name, email address, company, optional telephone number, the kind of inquiry, the artist you ask about, a stated fee or budget, your message, the time and a one-way hash of your IP address (a pseudonymised value, deleted together with the inquiry). We use it to answer you, to prepare a possible contract and to prevent misuse (Art. 6(1)(b) and (f) GDPR). The inquiry is mailed to our team and we send you a confirmation; both go through Microsoft Ireland Operations Ltd. (Microsoft 365), our processor; transfers to Microsoft Corporation in the USA rely on the EU-US Data Privacy Framework and the EU standard contractual clauses. Team members who have switched on notifications on their phone receive a notice that an inquiry arrived, without its content.

If we send you a link to add details, the link contains a single-use code; the answers are added to your inquiry. The link itself is deleted ninety days after it expired or was used.

An inquiry that does not lead to business is deleted automatically three years after the last activity on it. If it leads to a contract, the related records are kept for the statutory periods: commercial correspondence six years, accounting records and invoices eight years, books and annual accounts ten years (§ 147 AO, § 257 HGB).

4. Cloudflare Turnstile

Forms on this website and the sign-in screens are protected against automated misuse by Cloudflare Turnstile. Technical signals such as IP address, browser and device information are processed by Cloudflare based on our security interest (Art. 6(1)(f) GDPR). Any storage on your device is limited to what is strictly necessary for this protection (§ 25(2) No. 2 TDDDG).

5. Cloudflare Web Analytics

We count how often pages are read using Cloudflare Web Analytics, provided by Cloudflare as our processor. It sets no cookies and builds no profile across websites or visits. A small script transmits the address of the page, the referring page, page load timings and general device and browser information; Cloudflare uses your IP address only to produce aggregate counts and does not store it. The legal basis is our legitimate interest in knowing which pages are read (Art. 6(1)(f) GDPR). You can object at any time (section 13); a browser set to block tracking scripts will also prevent it.

6. Consent management

Your choices for analytics, marketing and external media are stored in your browser so they can be respected on later visits (§ 25(2) No. 2 TDDDG, Art. 6(1)(c) GDPR). We ask again after twelve months. You can change your choice at any time with “Cookie settings”; a withdrawal takes effect immediately, and the page reloads without the services you switched off.

7. Google Analytics

Google Analytics is loaded only after your consent. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Usage, device and event data and your IP address are processed (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). Data may be transferred to Google LLC in the USA on the basis of the EU-US Data Privacy Framework. Google Analytics stores cookies (_ga, _ga_<ID>) on your device for up to two years unless you delete them earlier. Consent is voluntary and can be withdrawn at any time.

8. Meta Pixel

With your consent, the Meta Pixel of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland, measures campaigns and processes page views, interactions, device, browser and online identifiers; Meta may link the data to your Meta account (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). Data may be transferred to Meta Platforms, Inc. in the USA on the basis of the EU-US Data Privacy Framework. For the collection on this website and the transmission to Meta, we and Meta Platforms Ireland Limited are joint controllers (Art. 26 GDPR) under Meta's controller addendum; Meta is responsible for its further processing and for answering requests about it. The cookie _fbp is stored for up to ninety days. Consent is voluntary and can be withdrawn at any time.

9. Spotify, Apple Music and Amazon Music

Players of these services load only with your consent. Loading transmits your IP address, device and usage data to the provider, which may set cookies and link the data to your account (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). Providers: Spotify AB (Sweden), Apple Distribution International Ltd. (Ireland), Amazon Europe Core S.à r.l. (Luxembourg); transfers to affiliates in the USA may occur on the basis of the EU-US Data Privacy Framework or standard contractual clauses.

10. Short links (go.4react.com)

When you open one of our short links, we forward you and count the visit to measure our campaigns. We store: the time of the visit, country, region and city derived from the IP address, the network provider, time zone and browser language, device type, operating system and browser, the referring page and campaign parameters of the link. To count repeated visits once, we store a salted one-way hash of your IP address and browser that includes the date, so it cannot be matched across days and is not used to identify you; the IP address itself is not stored. No cookies are set. The legal basis is our legitimate interest in measuring campaigns (Art. 6(1)(f) GDPR). The per-visit records are deleted after 400 days; only totals per link remain.

11. Accounts: intranet, artist app, finance and links

For people with an account (our team, artists and their representatives), we process: name, email address, role and permissions, password hash, second-factor settings, signed-in sessions and trusted devices (device name, browser, last use), an activity log of changes and sending actions, and, where switched on, push notification addresses of your devices. For artists we additionally process dates, travel and hotel details, fees and settlements where the membership allows it, rider preferences and answers to approval requests. Dietary requirements and allergies are stored only with your explicit consent (Art. 9(2)(a) GDPR), which you can withdraw in the app at any time; they are then deleted. So that travel sheets can be read without a connection, the artist app keeps the sheets sent for the next fourteen days on your device, encrypted with a key that stays on that device; they are deleted after the date, when you sign out, and when your account no longer has access to sheets.

Legal bases: performance of your contract with us (Art. 6(1)(b) GDPR), for employees § 26 BDSG, legal obligations (Art. 6(1)(c) GDPR) and our legitimate interest in secure access and traceable changes (Art. 6(1)(f) GDPR). Push notifications are delivered through the push service of your device (Apple, Google, Mozilla or Microsoft), which sees only an encrypted message. Account data is deleted when the account ends, except where records must be kept (for example invoices and settlements); sessions end after eight hours and trusted devices after ninety days without use.

12. Recipients

Processors bound under Art. 28 GDPR: Cloudflare (hosting, databases, storage, security, analytics), Microsoft (email). Where you are invoiced by us: Stripe Payments Europe, Ltd., Ireland (invoices and payments). Our bank, Qonto (Olinda SAS, France), receives payment data as an independent controller. Contracts are signed on our own signature platform, operated for us. The address search in our forms sends only the typed address fragment from our server to Photon (komoot GmbH, Germany). Tax advisers and authorities receive data where the law requires it. Other recipients are named in the sections above.

13. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20 GDPR). You can withdraw any consent at any time with effect for the future (Art. 7(3) GDPR), without giving reasons and without any disadvantage.

Right to object (Art. 21 GDPR): where we process data on the basis of our legitimate interests (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation; we then stop unless there are compelling legitimate grounds or the data is needed for legal claims.

The quickest way to use any of these: the request form. It records your request in our register the moment you send it, with that day as the day it arrived, and you get a confirmation by mail. Writing to the address above reaches the same people and works just as well.

You may lodge a complaint with a supervisory authority, in particular the Berlin Commissioner for Data Protection and Freedom of Information. We answer requests within one month.

14. Obligation to provide data and automated decisions

You are not obliged to provide personal data. Without the details required to answer an inquiry or perform a contract, we cannot do so. We do not make decisions based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR.

15. Security and changes

We protect data with appropriate technical and organisational measures, including encryption in transit, multi-factor sign-in and role-based access. We update this notice when our processing changes; the version and date are stated at the top.