This document is available in English only.
Privacy Policy
Draft of 24 September 2026, prepared for legal review before launch. It describes what interlir.net actually does; it does not copy the policy of interlir.com, which covers a different website and different services. Retention periods marked “to be confirmed” are proposals, not yet implemented rules.
1. Controller
The controller for the processing described here is the company named in the Legal notice. You can reach us by email at the address given there.
2. What this policy covers
This policy covers the public website interlir.net, the customer portal (sign-in, business accounts, marketplace, orders, billing, payouts) and the emails we send in connection with them. It does not cover websites we link to.
3. Data we process and why
3.1 Visiting the website
When you open a page, our servers and Cloudflare (see section 5) process your IP address, the requested address, the time, the referrer and browser information in order to deliver the page, protect the site against abuse and diagnose errors. Server logs are kept for up to 30 days (to be confirmed). Legal basis: our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).
We do not use analytics or advertising services and do not set tracking cookies.
3.2 Cookies
The site uses only cookies that are necessary for it to work:
- a session cookie after you sign in, so that you stay signed in;
- a language cookie that remembers the language you chose (kept for one year).
No consent banner is shown because no optional cookies are set.
3.3 Contact form
If you write to us through the contact form, we process your name, email address, message, IP address and the language of the page in order to answer you. Legal basis: pre-contractual measures at your request and our legitimate interest in answering enquiries (Art. 6(1)(b) and (f) GDPR). Enquiries are kept for as long as needed to handle them and then for up to two years for follow-up questions (to be confirmed).
3.4 Account and sign-in
To use the portal you create an account with your email address. Sign-in is provided by Google Firebase Authentication (email link or Google account, see section 5). We store your email address, display name, chosen language, the time of your last visit and a technical user identifier. Legal basis: performance of the contract with you (Art. 6(1)(b) GDPR).
3.5 Business accounts and verification (KYB)
The marketplace is available to businesses only. To open a business account you provide company details (legal name, address, registration and VAT numbers, contact persons) and documents that let us verify the company and its beneficial owners, and, for suppliers, the right to the address space you list. We check VAT numbers against the EU VIES service. Legal basis: performance of the contract, compliance with legal obligations (anti-money-laundering, tax) and our legitimate interest in preventing fraud (Art. 6(1)(b), (c) and (f) GDPR). Verification documents are kept for the duration of the business relationship and for the retention periods required by law (up to 10 years).
3.6 Orders, invoices and payments
When you rent a network we process the order details, invoices and payment status. Card and bank details are entered directly with Stripe (see section 5); we do not store card numbers. Suppliers who receive payouts open a Stripe connected account, for which Stripe collects identity and bank information under its own terms. Legal basis: performance of the contract and legal obligations (Art. 6(1)(b) and (c) GDPR). Accounting records are kept for 10 years under German commercial and tax law.
3.7 Emails and notifications
We send transactional emails (sign-in links, order and invoice notifications, verification results, payout statements) through Resend (see section 5). Notification preferences can be changed in the portal; transactional emails required to perform the contract cannot be switched off.
3.8 Error monitoring
To find and fix errors we use Sentry (see section 5). Error reports may contain the request identifier, the affected URL, browser information and the identifier of the signed-in user. Personal data is minimised before sending. Reports are kept for 90 days. Legal basis: legitimate interest in a reliable service (Art. 6(1)(f) GDPR).
4. Hosting
The platform and its database run on servers of Relcom in Prague, Czech Republic (European Union). Backups are stored in the same region.
5. Processors and recipients
We use the following service providers, each bound by a data processing agreement:
- Cloudflare, Inc. (USA, EU data centres) — DNS, TLS termination and protection against attacks;
- Google Ireland Ltd. (Firebase Authentication) — sign-in;
- Stripe Payments Europe Ltd. (Ireland) and Stripe, Inc. (USA) — payments, invoicing, payouts to suppliers;
- Resend, Inc. (USA) — sending emails;
- Functional Software, Inc. (Sentry, USA) — error monitoring.
Where a provider processes data outside the European Economic Area, transfers are based on the EU Standard Contractual Clauses or an adequacy decision (EU–US Data Privacy Framework).
We share order-related data between the parties to a rental: a tenant sees the supplier company name on its contract, and a supplier sees the tenant company name on its payout statement. We do not sell personal data.
6. Storage periods
Data is deleted when it is no longer needed for the purposes above, unless a statutory retention period applies (accounting records: 10 years; correspondence: 6 years).
7. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interest (Art. 15–21 GDPR). Where processing is based on consent, you may withdraw it at any time with effect for the future. You may lodge a complaint with a supervisory authority, in particular in the member state of your residence or of the alleged infringement. The supervisory authority competent for us is the Berlin Commissioner for Data Protection and Freedom of Information.
8. Obligation to provide data
Providing the data described in sections 3.4–3.6 is necessary to conclude and perform the contract; without it we cannot open a business account or process orders.
9. Changes
We update this policy when the services change. The current version is always available at this address.