Privacy Policy
Last updated: August 2026
The German version of this document is legally binding. This translation is provided solely for your understanding.
1. Data Protection at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you could be personally identified. For detailed information on data protection, please refer to our Privacy Policy set out below.
Data Collection on This Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator, Cinderella Cleaning GmbH. Its contact details can be found in the Legal Notice (Impressum) of this website and in Section 3 of this Privacy Policy.
How do we collect your data?
Some data is collected when you provide it to us — for example, data you enter into one of our request or contact forms.
Other data is collected automatically, or after you have given your consent, when you visit the website. This mainly concerns technical data (e.g. server log files) as well as, if you have consented, data from integrated analytics and third-party services.
What do we use your data for?
Part of the data is collected to ensure the error-free provision of the website. Other data is used to process your enquiries, prepare quotes and, if you have consented, to display customer reviews and analyse website usage.
What rights do you have regarding your data?
You have the right, at any time and free of charge, to obtain information about the origin, recipients and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time with effect for the future.
For this purpose, as well as for further questions on the subject of data protection, you may contact us at any time using the address given in Section 3 of this declaration.
2. Hosting
External Hosting
This website is hosted by Vercel Inc., an external hosting provider. The personal data collected on this website is stored on the servers of the hosting provider. This may primarily include IP addresses, server log files, meta and communication data, and data submitted via our request forms.
The hosting provider is used for the purpose of fulfilling contracts with our prospective and existing customers (Art. 6 (1) lit. b GDPR) and in the interest of a secure, fast and efficient provision of our online offering by a professional provider (Art. 6 (1) lit. f GDPR).
A data processing agreement is in place with our hosting provider. Vercel Inc. is based outside the EU/EEA; any transfer of data to a third country takes place solely on the basis of appropriate safeguards (in particular EU standard contractual clauses or, where applicable, the EU-US Data Privacy Framework).
3. General Information and Mandatory Notices
Data Protection
We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this Privacy Policy.
When you use this website, various personal data is collected. This Privacy Policy explains what data we collect, what we use it for, and how and for what purpose this happens.
Please note that data transmission over the internet (e.g. when communicating by email) may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.
Controller
The controller responsible for data processing on this website is:
Cinderella Cleaning GmbH
LinienstraĂźe 158
10115 Berlin
Email: info@cinderella-cleaning.de
This address also serves as the contact point for all data protection matters and enquiries — there is no separate data protection mailbox and no in-house data protection officer.
Storage Period
Unless a more specific storage period is stated within this Privacy Policy, your personal data will remain with us until the purpose for the data processing no longer applies. If there are statutory retention obligations — in particular under commercial and tax law — the data concerned will only be deleted after these periods have expired. Beyond this, there is no fixed, calendar-based deletion period, as no automated deletion routine has been set up for this purpose.
Legal Bases of Processing
Where we obtain the consent of the data subject for processing operations involving personal data, Art. 6 (1) lit. a GDPR serves as the legal basis. When processing data required to fulfil a contract or to carry out pre-contractual measures, Art. 6 (1) lit. b GDPR serves as the legal basis. Where processing is necessary to safeguard a legitimate interest of ours or of a third party, and the interests, fundamental rights and freedoms of the data subject do not outweigh that interest, Art. 6 (1) lit. f GDPR serves as the legal basis.
Recipients and Data Transfers to Third Countries
In the course of our business activities, we use service providers who, as processors or on their own responsibility, gain access to personal data (see Sections 2, 4 and 5 of this declaration). Where data is transferred to countries outside the EU/EEA as a result — in particular to the USA — this only takes place on the basis of appropriate safeguards, such as EU standard contractual clauses or, where the respective provider is certified, the EU-US Data Privacy Framework.
Revocation of Your Consent to Data Processing
Many data processing operations are only possible with your express consent. You may revoke consent already given at any time — for cookie and third-party consents via the "Cookie Settings" in the footer of this website, and for other consents informally by email to the address given in Section 3.2. The lawfulness of any data processing carried out prior to the revocation remains unaffected by the revocation.
Right to Object (Art. 21 GDPR)
Where data processing is based on Art. 6 (1) lit. e or f GDPR, you have the right, at any time and for reasons arising from your particular situation, to object to the processing of your personal data.
Right to Lodge a Complaint with the Competent Supervisory Authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or the place of the alleged violation.
Right to Data Portability
You have the right to have data that we process automatically on the basis of your consent or in fulfilment of a contract handed over to you or to a third party in a common, machine-readable format.
Access, Deletion, Rectification and SSL/TLS Encryption
Within the scope of the applicable statutory provisions, you have the right at any time to free information about your stored personal data, its origin and recipients, and the purpose of the data processing, and, where applicable, a right to rectification or deletion of this data. For this purpose, as well as for further questions on the subject of personal data, you may contact us at any time using the address given in Section 3.2.
For security reasons and to protect the transmission of confidential content, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address bar of your browser changes from "http://" to "https://" and by the lock icon in your browser bar.
4. Data Collection on This Website
Cookies and Consent Management
On your first visit to this website, you will be asked for your consent via a cookie banner. Your selection is stored in a single entry in your browser's local storage and can be changed or revoked at any time via the "Cookie Settings" link in the footer of this website. The banner distinguishes four categories: Necessary, Analytics, Marketing and External Media. With the exception of the Necessary category, all categories are disabled by default until you actively consent.
The legal basis for storing the cookie decision itself and for accessing information on the end device is § 25 (1) TDDDG (German Telecommunications-Digital-Services-Data-Protection Act) in conjunction with Art. 6 (1) lit. a GDPR. For the technically necessary category, the legal basis is § 25 (2) TDDDG in conjunction with Art. 6 (1) lit. f GDPR.
Request and Contact Forms
This website offers four ways to contact us: the request form for private customers (including an optional detail step on the apartment's features and any special requests), the request form for commercial customers, and the application form for cleaning staff. Depending on the form, we collect information such as name, email address, phone number, address, details of your cleaning needs (e.g. area, frequency, number of rooms, desired additional services), details of your company (for commercial enquiries), and information on language skills, experience and availability (for applications).
This data is processed to handle your enquiry, to prepare a quote or to process an application, and in case of any follow-up questions. The legal basis is Art. 6 (1) lit. b GDPR, insofar as the processing serves to carry out pre-contractual measures, and otherwise Art. 6 (1) lit. f GDPR (legitimate interest in processing incoming enquiries and applications). Incoming form submissions are additionally subjected to an automated abuse check based on the sender's IP address (see Section 4.3).
The data submitted via these forms is stored in a table in Google Sheets, operated on our behalf by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) as processor. A data processing agreement is in place with Google; any transfer to the USA is based, where applicable, on the EU-US Data Privacy Framework or EU standard contractual clauses. We do not pass on this data to other third parties without your consent.
Server Log Files and Abuse Protection
To protect against automated abuse (e.g. spam submissions), we record the requesting IP address on form submissions and evaluate the number of submissions per IP address within a short time window in order to block excessively frequent automated submissions. The legal basis is Art. 6 (1) lit. f GDPR (legitimate interest in a functional website free from abuse).
Error Logging
On technical faults, as well as on requests to a page that does not exist, the website automatically transmits the following information: the requested path, the referring page, browser and operating system, a shortened error message, a shortened technical detail, the language of the website, and the software version in use. No IP address is stored for this purpose, no cookies are set, no user ID is assigned and no profiling takes place; the IP address is used only for the abuse check described above, held briefly in memory, and is not written down in this context. You may optionally use a free-text field to describe what you were looking for, and may voluntarily leave a phone number or email address so that we can get back to you; only what you enter yourself is transmitted — please do not include any details about third parties here. The contact field is expressly optional, serves solely so that we can get back to you about the reported problem, and is subject to the same deletion promise as the other information in this section. The data transmitted in this way is stored in the same Google Sheets table already named above, operated on our behalf by Google Ireland Limited as processor; no further service provider is involved. The legal basis is Art. 6 (1) lit. f GDPR (legitimate interest in a functional website and in detecting faults during the switchover of the website). The entries collected for this purpose will be deleted on 31 August 2026; the table itself will remain, only the collected entries will be removed.
5. Analytics Tools and Third-Party Tools
Google Tag Manager with Consent Mode v2
This website uses Google Tag Manager provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Google Tag Manager is a solution that allows us to manage website tags through a single interface. Google Tag Manager itself does not set any cookies and does not collect any personal data; it merely triggers other tags, which may themselves collect data.
We use Google Tag Manager in what is known as Consent Mode v2: until you make your choice in the cookie banner, all consent signals (including those for analytics and marketing) default to "denied". Only once you give your consent in the Cookie Settings are the corresponding signals set to "granted" and transmitted to Google. The legal basis is Art. 6 (1) lit. a GDPR. You can revoke your consent at any time via the "Cookie Settings" in the footer.
TrustDino Review Widget and Instagram Embed
To display customer reviews, we embed the review widget of the provider TrustDino (Trustdino GmbH, Fritz-Reuter-StraĂźe 45, 17489 Greifswald). The widget is only loaded after you have consented to the "External Media" category in the Cookie Settings; until then, only a placeholder with a load button is displayed in its place.
Once you consent and load the widget, a connection is established to TrustDino's servers; in doing so, your IP address and further technical browser data are transmitted to TrustDino. The legal basis is your consent, Art. 6 (1) lit. a GDPR. You can revoke this consent at any time via the "Cookie Settings"; the widget will then immediately be replaced again by the placeholder, without the page needing to be reloaded.
To display our posts, we also embed an Instagram post from the provider Instagram, operated by Meta Platforms Ireland Limited. This embed, too, is only loaded after you have consented to the "External Media" category in the Cookie Settings and have activated the load button of the placeholder provided for this purpose; until then, there is no connection whatsoever to Meta and no data is transmitted.
Once you consent and load the post, a connection is established to Meta's servers; in doing so, at least your IP address and further browser and device information are transmitted to Meta. If you are logged in to Meta at that time, Meta may associate this data with your Meta account. The legal basis is your consent, Art. 6 (1) lit. a GDPR; you can revoke this consent at any time with effect for the future via the "Cookie Settings". A transfer to a third country (USA) cannot be ruled out; where it takes place, it does so only on the basis of appropriate safeguards (in particular EU standard contractual clauses or, where applicable, the EU-US Data Privacy Framework).
Vercel (Hosting)
For information on our hosting provider Vercel Inc. and the associated data processing, please see Section 2 of this Privacy Policy.
