Privacy Policy

Last updated: February 2025

(DSGVO / GDPR compliant – Germany)

1. Controller

Controller within the meaning of Art. 4(7) GDPR is:

CyberLife82
Rintheimer Querallee 2
76131 Karlsruhe
Germany
Email: support@forkliftai.de

2. Description of the Service

Forklift ("we", "our", "the service") is an AI automation tool for eBay sellers. This policy explains how we collect, use, and protect your personal data when you use our website and services.

3. Categories of Personal Data

We process the following categories of personal data:

Account data

  • Email address
  • Encrypted password

eBay integration data

  • OAuth tokens
  • Marketplace preferences
  • Listing-related metadata

Payment data

  • Billing information
  • Subscription status
  • Payments are processed via Stripe. We do not store full card numbers.

Usage data

  • IP address
  • Log files
  • API request logs
  • Error reports

Product data

  • Images and listing content uploaded by users

4. Legal Basis of Processing (Art. 6 GDPR)

We process personal data on the following legal bases:

  • Art. 6(1)(b) GDPR (contract performance): For account management, subscription handling, and eBay integration.
  • Art. 6(1)(c) GDPR (legal obligation): For compliance with tax and commercial retention requirements.
  • Art. 6(1)(f) GDPR (legitimate interest): For security, fraud prevention, system stability, and service improvement.
  • Art. 6(1)(a) GDPR (consent): Where explicitly required (if analytics or optional features are added).

5. Data Sharing and Processors

We use service providers who process personal data on our behalf (e.g. authentication, payments, eBay integration, hosting). Data processing agreements (DPAs) are in place where required. We do not sell personal data.

6. International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), such transfers are based on an adequacy decision of the European Commission, Standard Contractual Clauses (Art. 46 GDPR), or other appropriate safeguards as required by law.

7. Data Retention

We retain personal data as follows:

  • Account data: Until account deletion.
  • Subscription and billing data: According to statutory retention obligations (up to 10 years under German commercial and tax law).
  • Log data: As long as necessary for security and operational purposes.

Users may request deletion of their account at any time.

8. Role Under Data Protection Law

If users process personal data of third parties (e.g., buyers) via the platform, Forklift acts as a processor within the meaning of Art. 28 GDPR. A separate Data Processing Agreement (DPA) may be required.

9. Data Subject Rights

Under GDPR, users have the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)

Requests can be sent to: support@forkliftai.de

10. Security

We implement appropriate technical and organisational measures pursuant to Art. 32 GDPR, including encryption, secure transmission (TLS), and access controls.

11. Cookies and Local Storage

We use browser storage for authentication, session management, and user preferences. We do not use tracking or marketing cookies unless explicitly introduced and consent is obtained where required.

12. Changes to This Policy

We may update this Privacy Policy to reflect legal or operational changes. Material changes will be communicated via email or within the service.