Legal
Privacy Policy
Last updated: August 2026
This English version is provided for convenience only. In case of discrepancies, the German version prevails.
1. Controller
Controller responsible for the processing of personal data:
The Corbu Real Company – Merle SchuettRobert-Koch-Strasse 6670563 StuttgartGermanyPhone: +49 151 29857029
Email: info@corbureal.com
2. Hosting and technical provision
This website is created and technically provided using the Lovable platform.
When the website is accessed, technically necessary connection data may be processed, in particular:
- IP address
- date and time of access
- page or file requested
- browser type and version
- operating system
- referrer URL
- technical status and error data
Processing takes place to provide the website securely, stably and without errors.
The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in the secure and functional provision of our online offering.
Lovable acts as recipient or processor. Privacy information: https://lovable.dev/privacy
The contracting Lovable entity, the processing region, the sub-processors used and the conclusion of a data processing agreement will be verified in the actual project before publication and added here.
IONOS is used exclusively for domain registration and DNS management and not as a website hosting provider.
3. Contacting us
If users contact us by email or contact form, we process in particular:
- first and last name
- business email address
- phone number, if provided
- company
- role or position
- project phase
- type of project
- message and project content
- time of the enquiry
- technically required transmission data
Processing takes place to handle the enquiry, to prepare a possible contract and for business communication.
The legal basis is Art. 6 (1) (b) GDPR. For general business enquiries, processing may additionally be based on Art. 6 (1) (f) GDPR.
Our legitimate interest lies in handling business enquiries and maintaining business contacts.
Mandatory and voluntary fields are clearly marked in the form. The form requires the confirmation “I have read the privacy policy.” It is not pre-selected and does not replace consent as a legal basis.
Separate consent is only required if data is additionally to be used for newsletters or advertising.
4. Free Project Check and digital analyses
When using the Project Check or comparable digital analyses, the following may also be processed:
- answers to analysis questions
- project status and project phase
- information on processes, software and organisation
- company size and industry
- calculated results and classifications
- recommended next steps
- technical time and status information
Processing takes place to carry out the requested check, to provide the evaluation and to recommend a suitable service.
The legal basis is Art. 6 (1) (b) GDPR.
Automated evaluations serve as orientation and do not lead to decisions with legal or similarly significant effect within the meaning of Art. 22 GDPR.
Please do not enter sensitive personal data, health data, private employee information, passwords or confidential access credentials.
5. Airtable
Airtable is intended to be used for the structured management of contact enquiries, Project Check data and project-related business information. Transmission to Airtable takes place exclusively server-side.
The following data in particular may be processed:
- contact data
- company data
- form content
- Project Check answers
- evaluation results
- communication and processing status
Depending on the processing, the legal basis is Art. 6 (1) (b) or (f) GDPR.
Airtable may also process data outside the European Economic Area. International transfers are safeguarded using the transfer mechanisms applicable at the time of processing, for example an adequacy decision or the standard contractual clauses.
Privacy information: https://www.airtable.com/company/privacy – Data Processing Addendum: https://www.airtable.com/company/dpa
Before activation, the data processing agreement, storage region, access rights, two-factor authentication and a deletion and permission concept are reviewed. API keys are not stored in the frontend.
6. Business email communication
We use Microsoft 365 for business email communication and document processing.
The following in particular may be processed:
- contact data
- communication content
- attachments
- appointment and project information
- technical communication data
The legal basis is Art. 6 (1) (b) GDPR or Art. 6 (1) (f) GDPR.
International data transfers are safeguarded using the applicable safeguards under Chapter V GDPR.
Microsoft acts as recipient or processor. Privacy information: https://privacy.microsoft.com/en-gb/privacystatement
7. Appointment booking via Calendly
This website may offer an external link to the appointment booking service Calendly. Calendly is not loaded as an embedded widget, iFrame or popup.
No data is transmitted to Calendly by this website before the link is clicked.
When the external Calendly page is opened, Calendly processes data under its own technical and data protection terms. In the context of a booking, the following in particular may be processed:
- name
- email address
- company
- requested appointment
- time zone
- voluntary information
- technical connection data
We process the booking data we receive in order to arrange appointments and prepare business conversations. The legal basis is Art. 6 (1) (b) GDPR.
Calendly may process data in the USA and other third countries. The transfer is safeguarded by the applicable safeguards under Chapter V GDPR. Privacy information: https://calendly.com/privacy
A Calendly link is identifiable as an external link, opens in a new tab, uses rel="noopener noreferrer" and indicates that the website is being left (“Book an appointment via Calendly – external link”).
8. Use of artificial intelligence in analyses and reports
AI services may be used in a supporting role for expressly marked digital analyses or reports.
Project information entered may be structured, summarised, categorised or processed to create a draft result.
Where OpenAI is used via an API, only the data required for the respective analysis is transmitted. API keys are stored exclusively server-side.
No sensitive personal data, health data, passwords or confidential access credentials are transmitted to AI services.
The legal basis is Art. 6 (1) (b) GDPR where the use of AI is necessary to provide the requested service. In other cases, Art. 6 (1) (f) GDPR may apply.
Automated analyses do not constitute a decision based solely on automated processing with legal or similarly significant effect pursuant to Art. 22 GDPR.
AI may be used to support structuring, evaluation and drafting. Whether and to what extent a personal expert review is included follows from the respective service description.
Before an AI workflow is activated, data processing, data transmission, data minimisation, storage options and the specific API configuration are reviewed.
9. Local storage and cookies
This website does not use analytics, advertising or marketing cookies.
Technically necessary information may be stored locally, for example:
- language selection
- necessary session status
- security information
- interim status of a Project Check that was expressly started
Where storage or access is strictly necessary to provide a digital service expressly requested by the user, this takes place on the basis of Section 25 (2) no. 2 TDDDG.
The subsequent processing of personal data is governed by Art. 6 (1) (b) or (f) GDPR.
No cookie consent banner is used as long as the technical audit confirms that only necessary storage and access take place. The audit covers in particular platform scripts, fonts, Calendly, Stripe, embedded videos, maps, analytics tools, tracking pixels, social media plugins and other external requests. If non-essential services are loaded before consent, effective consent management will be added.
Fonts are served locally; no fonts are loaded from external servers.
10. External links
The website contains links to external offerings, in particular to:
- corbu.on
- corbu.dx
- Calendly
- Stripe Checkout, where applicable
Simply viewing the CORBU website does not transmit data to these providers via ordinary external links. Processing by the respective provider generally only begins once the external link is opened.
11. Recipients of personal data
Personal data is only transmitted to recipients where this is necessary for the respective purposes. Depending on use, these may include:
- hosting and platform providers
- database and automation providers
- email and communication providers
- appointment booking providers
- payment service providers
- AI service providers
- IT, tax and legal advisors
- public authorities where legally required
12. Transfers to third countries
Some service providers may process data outside the European Union or the European Economic Area.
Data transfers only take place if the requirements of Art. 44 et seq. GDPR are met. Depending on the provider, adequacy decisions, the EU-US Data Privacy Framework or standard contractual clauses may be used.
13. Storage period
Personal data is only stored for as long as is necessary for the respective purpose.
Contact enquiries that do not lead to a contract are generally deleted no later than twelve months after the enquiry has been concluded, unless legal obligations or legitimate reasons require longer storage.
Project Check data is generally deleted or anonymised no later than twelve months after completion of the check, provided the user does not commission a follow-up service and no legal obligations prevent deletion.
Where a contract is concluded, the statutory commercial and tax retention obligations additionally apply.
Technical server log data is only stored for as long as is necessary for operation and security. The specific period will be verified against the actual platform configuration and added here.
14. Legal bases
Depending on the processing, we rely in particular on:
- Art. 6 (1) (a) GDPR – consent
- Art. 6 (1) (b) GDPR – contract and pre-contractual measures
- Art. 6 (1) (c) GDPR – legal obligation
- Art. 6 (1) (f) GDPR – legitimate interest
Where processing is based on consent, this consent can be withdrawn at any time with effect for the future.
15. Rights of data subjects
Subject to the statutory requirements, data subjects have in particular the following rights:
- access pursuant to Art. 15 GDPR
- rectification pursuant to Art. 16 GDPR
- erasure pursuant to Art. 17 GDPR
- restriction of processing pursuant to Art. 18 GDPR
- data portability pursuant to Art. 20 GDPR
- objection pursuant to Art. 21 GDPR
- withdrawal of consent given with effect for the future
- complaint to a data protection supervisory authority pursuant to Art. 77 GDPR
A message to info@corbureal.com is sufficient to exercise these rights.
16. Right to object
Where personal data is processed on the basis of Art. 6 (1) (f) GDPR, there is a right to object on grounds relating to the data subject's particular situation.
Personal data will then no longer be processed unless there are compelling legitimate grounds or the establishment, exercise or defence of legal claims requires otherwise.
17. Right to lodge a complaint
Data subjects may lodge a complaint with a data protection supervisory authority. The authority responsible for our registered office is in particular:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-WürttembergHeilbronner Strasse 3570191 StuttgartGermany18. Transactional emails via Resend
We use Resend, a service provided by Plus Five Five, Inc., to send confirmations and transactional emails. This involves processing your name, email address and the communication data required for delivery. Emails are sent solely in connection with your enquiry. The legal basis is Art. 6(1)(b) GDPR. Where data is transferred to third countries, the transfer is based on appropriate safeguards, including the EU Standard Contractual Clauses. A data processing agreement is in place with the provider.
19. Data security
We use appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access and unauthorised disclosure.
The website uses an encrypted HTTPS connection.
