Privacy Policy
With the following privacy policy we would like to inform you about the types of your personal data (hereinafter also referred to as "data") we process, for what purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the provision of our services and in particular on our website and in our mobile application "Hoaalo" (hereinafter collectively referred to as "online offer"). The terms used are not gender-specific.
Note: The Hoaalo app is currently in development. At present we offer, via our website, registration for our waiting list. Processing operations that relate to the app (e.g. user accounts and advertising) are marked as such below and only take effect once the app launches.
Last updated: August 2026
Controller
Tayho Solutions e. K.c/o IP-Management #7328
Ludwig-Erhard-Str. 18
20459 Hamburg, Germany
E-mail: mail@hoaalo.app
Phone: +49 155 60271172
Legal notice: Imprint
Overview of processing operations
The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects.
Types of data processed
- Inventory data
- Contact data
- Content data
- Usage data
- Meta, communication and procedural data
- Log data
- Location data (app)
- Payment data (subscription, app)
Categories of data subjects
- Prospective customers (interested parties)
- Communication partners
- Users
Purposes of processing
- Provision of contractual services and fulfilment of contractual obligations
- Communication
- Direct marketing (waiting list / notifications)
- Security measures
- Reach measurement
- Market research
- Marketing (advertising)
- Profiles with user-related information
- Provision of our online offer and user-friendliness
- Information technology infrastructure
- Feedback
Relevant legal bases
Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or domicile.
- Consent (Art. 6(1)(a) GDPR) — The data subject has given consent to the processing of their personal data for one or more specific purposes
- Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR) — Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract
- Legal obligation (Art. 6(1)(c) GDPR) — Processing is necessary for compliance with a legal obligation to which the controller is subject
- Legitimate interests (Art. 6(1)(f) GDPR) — Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject
National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national data protection regulations apply in Germany. These include in particular the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains special provisions, among others, on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transmission, as well as automated decision-making in individual cases including profiling. State data protection acts of the individual federal states may also apply.
Security measures
We take appropriate technical and organisational measures in accordance with the legal requirements, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing, as well as the varying probabilities of occurrence and the extent of the threat to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.
The measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access, input, disclosure, availability and separation concerning the data. Furthermore, we have established procedures that ensure the exercise of data subjects' rights, the erasure of data and responses to threats to the data. We also take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default.
Securing online connections using TLS/SSL encryption technology (HTTPS): To protect the data of users transmitted via our online services from unauthorised access, we use TLS/SSL encryption technology. When a website is secured by an SSL/TLS certificate, this is signalled by the display of HTTPS in the URL.
Transmission of personal data
In the course of our processing of personal data, it may happen that the data is transmitted to other bodies, companies, legally independent organisational units or persons, or that it is disclosed to them. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we observe the legal requirements and, in particular, conclude corresponding contracts or agreements that serve to protect your data with the recipients of your data.
General information on data storage and erasure
We erase personal data that we process in accordance with the statutory provisions as soon as the underlying consents are revoked or there are no further legal bases for the processing. This concerns cases in which the original purpose of the processing no longer applies or the data is no longer required. Exceptions to this rule exist where statutory obligations or special interests require longer storage or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal prosecution or to protect the rights of other natural or legal persons, must be archived accordingly. Where several statements on the retention period or erasure deadlines of a piece of data exist, the longest period always applies.
Retention and erasure of data: The following general periods apply to retention and archiving under German law:
- 10 years — retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, booking vouchers and invoices (§ 147(3) in conjunction with (1) nos. 1, 4 and 4a AO, § 14b(1) UStG, § 257(1) nos. 1 and 4, (4) HGB)
- 6 years — other business documents: received commercial or business letters, reproductions of sent commercial or business letters, and other documents insofar as they are relevant for taxation (§ 147(3) in conjunction with (1) nos. 2, 3, 5 AO, § 257(1) nos. 2 and 3, (4) HGB)
- 3 years — data required to consider potential warranty and damage claims or similar contractual claims, stored for the duration of the regular statutory limitation period of three years (§§ 195, 199 BGB)
Rights of data subjects
As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:
- Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing
- Right to withdraw consent: You have the right to withdraw consent granted at any time
- Right of access: You have the right to request confirmation as to whether data in question is being processed and to obtain information about this data as well as further information and a copy of the data in accordance with the legal requirements
- Right to rectification: You have the right to request the completion of data concerning you or the rectification of incorrect data concerning you
- Right to erasure and restriction of processing: You have the right to request that data concerning you be erased without delay, or alternatively to request a restriction of the processing of the data
- Right to data portability: You have the right to receive data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request its transmission to another controller
- Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR
Waiting list (registration & double opt-in)
Via the forms on our website, interested parties can register for our waiting list in order to be informed about the launch of the Hoaalo app. Registration takes place using the so-called double opt-in procedure, i.e. after registering you will receive an e-mail asking you to confirm your registration. This confirmation is necessary so that no one can register with someone else's e-mail address. The confirmation link is valid for 24 hours.
The mandatory field is your e-mail address; providing your first name is optional and serves to address you personally. To log the registration process (proof of consent), we store the time of registration and confirmation, your IP address, the browser used (user agent), your language selection and the form via which the registration took place. You can unsubscribe from the waiting list at any time and withdraw your consent with effect for the future, e.g. via the unsubscribe link or by contacting us.
For that purpose, every confirmation e-mail carries a permanently valid, personal link in its footer that leads to a self-service page. There you can change your consent to receiving news at any time and delete your registration entirely, without logging in. The deletion is immediate and final; we do not keep a suppression list of your e-mail address. So that this link can identify you unambiguously, we store a random, personal access key with your registration record. It is used solely for this purpose and is deleted together with the registration.
After confirming, we additionally ask you separately on the confirmation page whether we may send you news about Hoaalo by e-mail. This includes, in addition to updates on the development of the app, promotional content about us, such as references to our own posts and videos on social media channels (e.g. Instagram and YouTube). This answer is voluntary; we store it together with the time it was given on your registration record. If you do not answer, we will not send you any news. You can change your decision at any time via the self-service page mentioned above and withdraw any consent given with effect for the future.
Types of data processed: Inventory data (first name); contact data (e-mail address); usage data (source of registration, language); meta, communication and procedural data (IP address, user agent, timestamps, consent status for news and the time it was given, personal access key for the unsubscribe and preferences link).
Data subjects: Prospective customers (interested parties).
Purposes: Direct marketing; communication; security measures (proof of consent).
Legal bases: Consent (Art. 6(1)(a) GDPR); the proof of consent is based on our legitimate interests (Art. 6(1)(f) GDPR).
Strato (e-mail dispatch)
To send our e-mails (e.g. waiting-list confirmation and notification e-mails as well as account and verification e-mails), we use the service of STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. In doing so, Strato processes contact and meta data (e.g. e-mail address, time of dispatch) on our behalf as a processor. Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Privacy policy: https://www.strato.de/datenschutz/.
Survey "How did you hear about Hoaalo?"
On the waiting-list confirmation page we ask a voluntary question about how you became aware of Hoaalo. We store your answer in a separate record that contains no link to your e-mail address or your registration. We store neither your IP address nor your browser (user agent) — only the answer option you chose, an optional free text and the time of the answer. Because we store the time, attribution via temporal correlation cannot be fully ruled out; we therefore deliberately do not describe this data as anonymous. Please do not enter any personal data into the free-text field.
Types of data processed: Usage data (chosen answer option, optional free text); meta, communication and procedural data (time of the answer).
Data subjects: Prospective customers (interested parties).
Purposes: Reach measurement; market research.
Legal bases: Consent (Art. 6(1)(a) GDPR); answering the question is voluntary and constitutes the consent.
Registration, login and user account (Hoaalo app)
Note: The following processing operations relate to the Hoaalo app, which is in development, and take effect with its launch.
Users can create a user account. As part of the registration, users are provided with the required mandatory information and this is processed for the purposes of providing the user account on the basis of contractual performance. The data processed includes in particular the login information (username, password and an e-mail address). As part of using our registration and login functions and the use of the user account, we store the IP address and the time of the respective user action. This is stored on the basis of our legitimate interests, as well as those of the users, in protection against misuse and other unauthorised use.
The Hoaalo app is intended for persons aged 18 and over. During registration, users therefore confirm, by way of a separate declaration, that they are at least 18 years old. We do not collect or store the exact date of birth for this purpose; we only store the fact and time of this confirmation.
Types of data processed: Inventory data; contact data; content data; usage data; log data.
Data subjects: Users.
Purposes: Provision of contractual services; security measures; organisational and administrative procedures; provision of our online offer and user-friendliness.
Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Two-factor authentication
Two-factor authentication provides an additional layer of security for your user account and ensures that only you can access your account, even if someone else knows your password. For this purpose, in addition to your password, you must carry out a further authentication measure (e.g. enter a code generated by an authentication app). Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR).
Erasure of data after termination
If users have terminated their user account, their data relating to the user account will be erased, subject to a legal permission, obligation or the users' consent. This includes content created by the user, such as activities, challenges and photos, which is deleted in full. Usernames appearing in comments that remain in place (e.g. because they relate to shared activities) are anonymised so that the comment can no longer be attributed to the deleted account. Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR).
Provision of the online offer and web hosting
We process the data of users in order to be able to provide them with our online services. For this purpose, we process the IP address of the user, which is necessary to transmit the content and functions of our online services to the user's browser or device.
Types of data processed: Usage data; meta, communication and procedural data (IP addresses, time information, identification numbers); log data.
Data subjects: Users.
Purposes: Provision of our online offer and user-friendliness; information technology infrastructure; security measures.
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Collection of access data and log files
Access to our online offer is logged in the form of so-called "server log files". Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. Server log files are used, on the one hand, for security purposes and, on the other, to ensure the utilisation and stability of the servers. Erasure of data: Log file information is stored for a maximum of 30 days and then deleted or anonymised. Data that must be retained for evidentiary purposes is exempt from erasure until the respective incident has been finally clarified.
Hetzner
We use the provision of information technology infrastructure and related services (e.g. storage space and/or computing capacity) from the service provider Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Website: https://www.hetzner.com; privacy policy: https://www.hetzner.com/de/legal/privacy-policy/.
Use of cookies
Cookies are small text files or other storage records that store information on end devices and read information from them, for example to store the login status in a user account, the content accessed or the functions used in an online offer. On our website we currently only use technically necessary cookies or storage records (e.g. to store your language selection and, in the protected administration area, for session management). No cookies are set for reach measurement with Umami (see below). In the Hoaalo app, further cookies or comparable technologies may be used, about which we will inform you within the app and, where applicable, by means of a consent request.
Notes on the legal basis: The legal basis on which we process your personal data using cookies depends on whether we ask you for consent. If you consent, the legal basis is your declared consent. Otherwise, the data processed with the help of cookies is processed on the basis of our legitimate interests (Art. 6(1)(f) GDPR). You can withdraw consents you have given at any time and also object to processing in accordance with the legal requirements, including by means of the privacy settings of your browser.
Contact and enquiry management
When you contact us (e.g. by e-mail, telephone or by post) and in the context of existing user and business relationships, the information of the enquiring persons is processed insofar as this is necessary to answer the contact enquiries and any requested measures. We use this data exclusively for the stated purpose of contacting and communicating with us.
Types of data processed: Inventory data; contact data; content data; meta, communication and procedural data.
Data subjects: Communication partners.
Purposes: Communication; organisational and administrative procedures; feedback.
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR).
Web analytics, monitoring and optimisation
Web analytics (also referred to as "reach measurement") serves to evaluate the visitor flows of our online offer and may include behaviour, interests or demographic information about visitors as pseudonymous values. With the help of reach analysis, we can, for example, recognise at what time our online offer or its functions or content are used most frequently, and identify areas that require optimisation. To protect users, IP addresses are not stored but processed in pseudonymised form only (see below). As part of web analytics we do not store any clear-text data of users (such as e-mail addresses or names), but pseudonyms.
Types of data processed: Usage data; meta, communication and procedural data.
Data subjects: Users.
Purposes: Reach measurement; profiles with user-related information.
Security measures: Pseudonymisation of the IP address (no storage in clear text).
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Umami (cookieless)
We use the self-hosted open-source web analytics software Umami for reach measurement. Umami runs on our own infrastructure (stats.tayho.solutions); the measurement requests are delivered via our own domain and forwarded to that server by us. The data collected is processed exclusively by us and is not shared with third parties.
Umami does not set cookies and neither stores information on your device nor reads information from it. For that reason no consent under Section 25(1) TDDDG (formerly TTDSG) is required. Your IP address is not stored: it is only used transiently, together with the browser identifier (user agent) and a secret key, to calculate a pseudonymous identifier which changes daily and cannot be traced back to you. Recorded are, in particular, the pages accessed, the referring page, the time of access, the approximate origin derived from the IP address (country/region), device type, screen size, browser, operating system and language setting.
You can object to the measurement at any time: if the "Do Not Track" setting is enabled in your browser, no data is collected.
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Advertising, subscription model and online marketing (Hoaalo app)
Note: The following processing relates to the Hoaalo app, which is in development, and takes effect with its launch.
The planned Hoaalo app will be advertising-financed. This means that we will display advertising in the app and, for this purpose, transmit data to advertising partners or have it processed by them. Advertising networks generally use device and usage data as well as advertising identifiers (e.g. advertising ID) in order to display advertising, measure its delivery and success, and align advertising with interests. Insofar as this requires access to your device (e.g. storing/reading identifiers) or personal data is processed for advertising purposes, we obtain your consent before processing. You can withdraw consent you have given at any time with effect for the future. The specific advertising partner or advertising network used will be named here upon the launch of the app: [Werbepartner/Netzwerk].
Types of data processed: Usage data; meta, communication and procedural data; where applicable location data; advertising identifiers.
Data subjects: Users.
Purposes: Marketing; reach and success measurement; profiles with user-related information.
Legal bases: Consent (Art. 6(1)(a) GDPR).
In addition, we plan to offer a subscription model in future that will allow the app to be used without advertising. The exact structure of the subscription model has not yet been finalised. Where a subscription is taken out, we will transmit the data required for payment processing (e.g. payment method, billing data) to a payment service provider that has not yet been determined; we will name that provider here before the subscription model launches: [Zahlungsdienstleister]. Processing is based on the performance of the subscription contract concluded with you.
Types of data processed: Inventory data; contact data; payment data.
Data subjects: Users.
Purposes: Provision of contractual services and fulfilment of contractual obligations.
Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR).
Amendment and update
We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.
Definitions of terms
In this section you will find an overview of the terms used in this privacy policy. Where the terms are defined by law, their legal definitions apply. The following explanations, on the other hand, are primarily intended to aid understanding.
- Inventory data: Essential information necessary for the identification and administration of contractual partners, user accounts, profiles and similar assignments, such as names, contact information, and specific identifiers (user IDs)
- Content data: Information generated in the course of creating, editing and publishing content of all kinds, such as texts, images and their associated metadata
- Contact data: Information that enables communication with persons or organisations, such as telephone numbers, postal addresses and e-mail addresses
- Meta, communication and procedural data: Data containing information about how data is processed, transmitted and managed, e.g. metadata about the origin and structure of data, communication data (e.g. IP addresses, timestamps, transmission paths) and procedural data on processes
- Usage data: Information that records how users interact with digital products, services or platforms, e.g. pages visited, dwell time, click paths, device information and IP addresses
- Personal data: Any information relating to an identified or identifiable natural person; an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more specific factors
- Profiles with user-related information: Any kind of automated processing of personal data consisting of using such data to analyse, evaluate or predict certain personal aspects relating to a natural person (e.g. interests in certain content or products, click behaviour)
- Log data: Information about events or activities that have been logged in a system or network, typically including timestamps, IP addresses, user actions and error messages
- Reach measurement: The evaluation of the visitor flows of an online offer, which may include the behaviour or interests of visitors in certain information
- Controller: The natural or legal person, authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data
- Processing: Any operation or set of operations performed on personal data, whether or not by automated means, such as collection, evaluation, storage, transmission or erasure