Draft. The final version is being reviewed by a lawyer.
Privacy policy
Controller
The controller for the processing of personal data on this website is Regalis GbR, Graureiherweg 20, 59519 Möhnesee-Körbecke, Germany.
The company is represented by its partners, Doris von Sayn-Wittgenstein, Martin Schaefer. You can reach us by email at [email protected] and by telephone on +49 (0) 2924 879 26 40.
We have not appointed a data protection officer. As matters stand today, we are not required to do so.
Hosting and server logs
This website is hosted by Cloudflare. The provider supplies the servers and the network and processes data on our behalf.
When a page is called up, technical log data arises. This includes the shortened or processed IP address, the date and time, the address requested, the referring page and details of browser and operating system.
This data serves the operation and security of the site and the defence against attacks. The legal basis is our legitimate interest under Article 6(1)(f) of the General Data Protection Regulation.
Log data is kept for a short time only and is then deleted or anonymised.
When you call up the start address, we forward you to one language version. The country of the request decides which one, and Cloudflare derives it from the IP address. The endpoint /api/geo returns only that country code and the matching language. On our servers nothing is stored and nothing is logged. Your choice of language is kept in the cookie named lang for one year.
Cookies and storage in your browser
We use technically necessary cookies only. We set no advertising or analytics cookies.
The cookie named lang stores your choice of language. It makes sure you see the website in the language you picked.
After you sign in we set a session cookie. It identifies your access and is invalidated when you sign out.
While you fill in a form, your browser stores your entries locally. This temporary copy never leaves your device. It is deleted once the form is sent and it also ends when you close the tab.
A conversation with the digital assistant also stays in your browser only. It lasts as long as the tab and is discarded when you close it.
For the language hint your browser remembers the suggested language and your decision about it. That entry also lasts as long as the tab and ends when you close it. No cookie is set for it, and the entry is not transmitted.
Contact form and email
If you write to us through the contact form, we process your name, email address, telephone number, subject and message.
We use these details to deal with your enquiry. The legal basis is Article 6(1)(b) of the General Data Protection Regulation for pre-contractual enquiries, otherwise point (f).
To fend off misuse we store a shortened check value of your IP address. It is not intended to allow any conclusion about you as a person.
Call back requests
Through the call back form we process your name, your company, your telephone number, the time window you prefer and, if you wish, your industry.
We use these details only to call you back and discuss your request. The legal basis is Article 6(1)(b) of the General Data Protection Regulation for pre-contractual enquiries, otherwise point (f).
To fend off misuse we store a shortened check value of your IP address. It is not intended to allow any conclusion about you as a person.
Internally we note who handled the call. Once your request is settled, we delete the entry.
Booking an intro call
On the intro call page you can book an appointment. For this we process your name, your telephone number and the time you picked.
The company, the email address and a line about the topic are optional. You can book without an email address as well.
We use these details to call you at the appointment and to prepare the conversation. The legal basis is Article 6(1)(b) of the General Data Protection Regulation for pre-contractual enquiries, otherwise point (f).
To fend off misuse we store a shortened check value of your IP address. It is not intended to allow any conclusion about you as a person.
If you gave an email address, we send a confirmation. It carries the appointment as a calendar file for your calendar program.
The calendar file names the start, the length and your contact person. You reach the file only through the link with your character string.
The cancellation link contains a random character string. Of that string we store a check value only.
Anyone without the link can neither see nor cancel your appointment. The reference number alone is not enough for that.
Internally we note the status of the appointment and, where needed, a short remark. Once the matter is settled, we delete the entry.
Requests from employers
In the employer questionnaire we collect details about the company, the contact person, the job, the terms and the accommodation.
The personal data is chiefly the contact details of the contact person. We process them in order to initiate and carry out the placement.
The legal basis is Article 6(1)(b) of the General Data Protection Regulation. In addition we rely on our legitimate interest in orderly processing.
Details about the job are passed on to candidates who come into consideration. Contact details of the contact person are released only after agreement with you.
Candidate profiles and documents
When you create a candidate profile, we process your details on person, residence, training, work experience, languages, driving licence and job wishes.
We also process the documents you upload. These include your CV, school reports, certificates and, if you wish, a photo.
A short video introduction is voluntary. Only Regalis and the employers you are presented to can see the video. You can delete it in your profile at any time.
Once a placement case is opened, we also process proposed and confirmed interview times. The papers that belong to the case are included, such as the offer and the employment contract.
This data serves the review of your profile and the placement with employers. The legal basis is Article 6(1)(b) of the General Data Protection Regulation.
Please do not upload documents containing health data or other specially protected details unless we expressly ask you to.
Documents are stored separately from the remaining data. Access is limited to signed-in users with the necessary rights.
Expiry dates of documents
For a document you can enter an expiry date, for example on a language certificate or a driving licence. This entry is optional.
We use the date for a reminder only. When a document expires soon, you see it in your profile, and we get in touch.
We do not read the content of your documents automatically for this. We use no text recognition.
The legal basis is Article 6(1)(b) of the General Data Protection Regulation. The date is deleted together with the document.
The CV print view
In your profile you can turn your details into a CV for printing. It is created in your browser only.
No data is transferred to us or to third parties in the process. We do not learn whether or when you use the view.
Whether you print the page or save it as a file is up to you in the print dialogue of your device. The file stays with you.
Quick application
The quick application is a short form for a first contact. We process your first and last name, your telephone number and your preferred way to be reached. We also process your country of residence, the job you want, the occupational group and your level of German.
The email address is optional here. If you give one, we also create an access for you and send you a sign-in link.
Without an email address no access is created. Your details are then handled only by Regalis and the responsible local partner.
The legal basis is Article 6(1)(b) of the General Data Protection Regulation. If you complete your profile later, the same purpose applies to those further details.
Internally we mark these entries as a quick application. That shows us which details are still missing for a placement.
Disclosure to employers
We pass your profile to employers only if you have expressly consented in the form. The legal basis is Article 6(1)(a) of the General Data Protection Regulation.
What is passed on are the details needed for the job and the documents you have provided.
You can withdraw your consent at any time with effect for the future. A short message to our email address is enough.
Partners in the countries of origin
For approaching and supporting candidates we work with partners in the countries of origin, at present in Türkiye and in Uzbekistan. Candidate data is therefore transferred to countries outside the European Union. If further countries of origin are added, we update this statement.
There is no adequacy decision of the European Commission for Türkiye or for Uzbekistan. A level of protection equal to that in the European Union cannot be assured in every case.
The transfer is necessary to prepare and carry out the placement. We base it on Article 49(1)(b) of the General Data Protection Regulation and on contractual arrangements with our partners.
If you do not want this transfer, please tell us. In many cases a placement is then not possible.
Referral code and agents
Local partners and other people who recommend us receive a referral code from us. It sits in a personal link and appears in the form in the field named referral code.
We do not store the code on your device. We set no cookie for it and keep nothing in your browser. The code travels in the address of the page and stays visible in the form.
If you enter a valid code, we assign your registration or your request to that agent. What we store is the code and the time.
The purpose of the assignment is the commission statement with the agent. The legal basis is our legitimate interest under Article 6(1)(f) of the General Data Protection Regulation.
The agent learns that something has arrived through the code. The message to them names the reference number only. If a local partner with their own access looks after you, they see your profile as part of that task.
How often a personal link was opened is counted per day and per code. That figure holds no details about individual people. We do not store your IP address for this. We briefly process only a check value of it, so that single calls do not distort the count.
Of the agents themselves we process the name, contact details, country, code and the details for the statement. The basis is the agreement with the agent in question.
Candidates can also create a referral code in their own access and pass it on. We then store the code and its link to the profile. The check page shows no name for such a code.
The field is voluntary. Without a code we handle your details in just the same way.
Applying as a referral partner
Through the form for referral partners you can apply to become an agent. For this we process your name, your email address, your telephone number and your description of your contacts.
Naming a company is optional. We do not need names or contact details of third parties at this point.
We use these details to review the application and to talk to you. The legal basis is Article 6(1)(b) of the General Data Protection Regulation.
If we approve the application, we list you as an agent. The section on the referral code then applies in addition.
If you apply with an address we already know, no second entry is created. If we decline, we delete the application.
Campaign parameters in the address
Addresses from adverts, letters or posters sometimes carry additions such as utm_source or utm_campaign. These additions name the channel and the campaign, not you as a person.
When you send a form, we store them together with your enquiry. That shows us which channel leads to enquiries.
We store nothing on your device for this. The additions only travel in the address while you move around our website.
No user profile is built from them. We still set no advertising or analytics cookies.
The legal basis is our legitimate interest in advertising that pays for itself, under Article 6(1)(f) of the General Data Protection Regulation.
Short links
For letters, posters and business cards we use short addresses that start with /go/. Opening one redirects you to the matching page of this website.
We only count how often a short link was opened on a given day. That figure holds no details about individual people.
We do not store your IP address for this. So that single calls do not distort the count, we briefly process a check value of your IP address. It is deleted after a short time. Nothing is placed on your device.
The legal basis is our legitimate interest in measuring the success of our advertising, under Article 6(1)(f) of the General Data Protection Regulation.
Anonymous notices of open jobs
On the candidate pages we show notices of open jobs. This happens only where the employer has agreed in the questionnaire.
Visible are then the occupational group, the industry, the federal state and the German level required. We also show the number of people wanted as a size band, the preferred start as a month and whether accommodation through the company is possible. The company name, the town, the pay and the reference number stay out of it.
The legal basis is the employer's consent under Article 6(1)(a) of the General Data Protection Regulation. It can be withdrawn at any time with effect for the future.
For employers we also state the number of candidates per occupational group. We do so only from a minimum number upwards, so that no conclusion about individual people is possible.
Introducing our local partners
We introduce our local partners on the website. This covers the name, photo, town, languages, industries and a short text.
This happens only with their written consent. The legal basis is Article 6(1)(a) of the General Data Protection Regulation.
Every partner can withdraw that consent at any time with effect for the future. We then take the introduction off the website.
Signing in without a password
For access to your profile or your requests we send a sign-in link by email. For the sign-in link we store your email address and a check value of the link. A passkey is possible as a second way.
To fend off misuse we store a shortened check value of your IP address with it. We do not store the address itself. When the link expires, that check value goes as well.
The link is valid for a short time only and works once. After you sign in we store the session with the time and the browser identifier.
This processing is needed for the secure operation of your access. The legal basis is Article 6(1)(b) and point (f) of the General Data Protection Regulation.
Signing in with a passkey
A passkey is an access that your device unlocks with a fingerprint, your face or a PIN. You need no password for it.
For this we store the public key, an identifier of the key, the method, a counter value and the transport paths. We also store the label you gave the device and the times of creation and of last use.
The secret part of the passkey stays in your device and never reaches us. Each sign-in creates a short task for your device. Of that task we keep only a check value for five minutes.
We keep these details until you delete the passkey or your access. The legal basis is Article 6(1)(b) and point (f) of the General Data Protection Regulation.
Changing the address you sign in with
At your request we change the email address you sign in with. That helps after a change of provider or of employer.
After the change only the new address leads to your access. If the new address is already taken, we decline.
We end open sessions in the process. That way nobody keeps an open access through the old address.
We write to the old and to the new address. That makes it noticeable if the change did not come from you.
We record the step in our internal log. The legal basis is our legitimate interest in secure access, under Article 6(1)(f) of the General Data Protection Regulation.
Viewing and ending your sessions
Inside your access you can see your open sessions. We show the start, the last use and a rough note about the device.
The note about the device comes from the browser identification your browser sends anyway. It helps you spot a session that is not yours.
You can end all other sessions with one click. That is useful if you have lost a device.
The legal basis is our legitimate interest in secure access, under Article 6(1)(f) of the General Data Protection Regulation.
Sending email
For confirmations, sign-in links and internal notifications we use an email delivery service. It processes the recipient address and the content of the message on our behalf.
We have a data processing agreement with this service. It may not use the data for its own purposes.
Newsletter
For the newsletter we process your email address, the chosen language, the time of the sign-up and of the confirmation and a check value of your IP address.
Signing up takes two steps. Only the link in the confirmation email adds you to the list.
The legal basis is your consent under Article 6(1)(a) of the General Data Protection Regulation.
Every message carries an unsubscribe link. After you unsubscribe we note the time and stop writing to you.
Digital assistant
On this website you can use a digital assistant. It answers questions about our services and about the process.
The answers are generated automatically. They can contain mistakes and do not replace information from our staff.
To answer you, we pass your input and the conversation so far to our service provider Anthropic. The company is based in the United States of America.
Data therefore reaches a country outside the European Union. We base the transfer on a data processing agreement with the standard contractual clauses of the European Commission.
Regalis does not store the content of these conversations. We only count the number of requests and the amount of text processed per day.
The conversation stays only for as long as your browser tab is open. Once you close the tab, it is gone.
Please do not enter sensitive data there. That includes health data, identity document numbers and details about other people.
For an application or a staffing need please use the forms. There your details are protected and traceable.
The legal basis is our legitimate interest in giving quick information, under Article 6(1)(f) of the General Data Protection Regulation. This assessment is a draft and still needs legal review.
Protection against automated access
To protect the forms against misuse we may use a bot protection service from Cloudflare. It checks technical features of the access without building a user profile.
It is used only when this function is switched on. The legal basis is our legitimate interest in secure forms under Article 6(1)(f) of the General Data Protection Regulation.
Storage periods
We store personal data only as long as it is needed for the purpose in question.
Contact enquiries with no further course are deleted once the matter is settled. Candidate profiles stay stored for as long as you want a placement.
If we hear nothing from you, we review the profile after two years and delete it when there is no further interest. At your request we delete it sooner.
Data that we must keep because of statutory retention duties is excluded from deletion.
Recipients of the data
Within Regalis, only those people have access who need it for their task.
The hosting provider and the email delivery service act as processors. Employers and partners receive data only within the scope described.
Your rights
You have the right to information about the data stored about you. You can ask for incorrect data to be corrected.
You can ask for erasure or for the restriction of processing, unless retention duties stand in the way.
You have a right to data portability. You can withdraw consent at any time with effect for the future.
You can object to processing based on legitimate interests. For all such matters a message to [email protected] is enough.
Right to complain
You can complain to a data protection supervisory authority. The authority at your place of residence or the one at our registered office is competent.
For Regalis this is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia.
Status of this policy
This version is a draft. We are agreeing the final version with our lawyer.
We adapt the policy when our processing or the legal requirements change. Version: September 2026.