Privacy Policy
Last updated: July 2026
Note: This English text is a convenience translation. The German version is authoritative.
1. Controller
The controller responsible for data processing on this website is:
2. General information
This policy explains which personal data are processed when you visit the website, contact us, book an appointment, submit a repair request or use the RMA portal.
3. Encryption
This website uses SSL/TLS encryption. An encrypted connection is shown by “https://” and the lock icon in your browser.
4. Hosting, server and security
The website, the RMA portal and the appointment booking system (EasyAppointments) run under a web hosting contract with Site B.V., Landdrostdreef 124, 1314 SK Almere, Netherlands. The domain is registered with STRATO; incoming email to our own mailboxes is also handled through STRATO.
This is shared hosting. Data may therefore be stored or backed up across multiple servers or data centres of the provider for redundancy; processing exclusively on a single server is not guaranteed. Appointment data may additionally be transferred to the connected Google Calendar (see section 7).
Necessary technical data such as IP address, access time, requested page, browser, operating system, referrer and server or network data may be processed. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable and fast operation of the website.
Data processing agreements under Article 28 GDPR are in place with Site B.V. and with STRATO as hosting and domain providers. Transfers to third countries take place only under the applicable legal conditions and safeguards.
5. Server logs
Necessary access and security data (including IP address, access time, requested page, referrer, browser used) are stored in our hosting provider's server logs. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the secure and stable operation of the website and abuse prevention. We do not currently generate our own visitor statistics from these logs. See section 17 for retention.
6. Contact
When you contact us by email, phone, WhatsApp or Microsoft Teams, we process your contact details and message to handle the request. The legal basis is Article 6(1)(b) GDPR for contractual or pre-contractual matters and otherwise Article 6(1)(f) GDPR.
When you contact us through WhatsApp, phone numbers, communication metadata and message content may be processed by WhatsApp Ireland Limited. Please do not use WhatsApp for highly confidential information.
Microsoft Teams
Communication data may be processed by Microsoft Ireland Operations Limited when Microsoft Teams is used.
7. Appointment booking (EasyAppointments, self-hosted)
The embedded appointment calendar is loaded as soon as the page is opened. It connects your browser only to our own, self-hosted EasyAppointments instance in our web hosting account at site.de - not to a separate external cloud service from a third-party booking provider, and not directly to Google. Necessary technical data may be transferred in the process.
For a booking, we process details such as name, email address, appointment, appointment type and optional messages, initially stored in a dedicated database in our hosting account. Your booking request is manually confirmed by us before the appointment becomes binding.
Our EasyAppointments instance is connected to Samman IT's own Google Calendar account (not a customer account). This connection reads busy times from our calendar to avoid double bookings, shows you as a visitor only free or busy time slots (no titles, participants or other content of our private appointments), and may add new bookings to our calendar for appointment management. In doing so, we only transmit the details necessary for appointment organisation (time, service type, internal booking number) to Google Calendar - not the fault description, device or serial numbers, address details, uploaded files or other RMA information.
This processing is necessary to organise and carry out your appointment booking; the legal basis is Article 6(1)(b) GDPR.
8. Cookies and local storage
When you sign in to the RMA customer portal, a technically necessary session cookie “rma_session” is set (HttpOnly, Secure, SameSite=Lax). It only keeps you signed in during your session and expires automatically after at most two hours or when you sign out.
The appointment booking (section 7) technically requires a session cookie “ea_session” when opened, used to hold booking-flow state (e.g. the appointment currently being booked) between steps and to protect forms against tampering. It is deleted when you close your browser or the session expires.
No consent is required for either of the above cookies under § 25(2) No. 2 TDDDG, since they are strictly necessary to provide the telemedia service you explicitly requested (sign-in or appointment booking).
Beyond that, this website sets no cookies and stores no choice in your browser's localStorage. Should we add optional services in the future that require consent (e.g. tracking tools), we will add a separate consent mechanism for them and update this policy accordingly.
9. Repair request and non-binding quote
For a repair request, we process the company, contact and address details you enter, selected services, device and serial number details, fault descriptions, accessories, handover and return information, and optional photo or PDF uploads. The optional “Request a non-binding quote” choice is processed to prepare an offer.
The legal basis is Article 6(1)(b) GDPR for pre-contractual steps and processing your request. Required fields are needed so that we can review and answer the request.
10. RMA customer portal
The RMA portal processes information such as the RMA number, company postal code, processing status, notes, carriers, tracking numbers, invoices and approved files. This is necessary to carry out and document the repair order under Article 6(1)(b) GDPR.
A running history is kept for each case, such as old and new quote amounts, rejection or acceptance of a quote, and status changes, each with a timestamp. Earlier entries are not overwritten but added as separate history entries.
Direct links and access details must not be shared with unauthorised persons. Access may be logged and limited to prevent abuse.
11. Automated system emails
To send emails related to processing your repair request (e.g. our internal notification about new requests, status changes, quotes, and the order confirmation), we optionally use the email service provider Mailjet (operated by Sinch Email SAS). Some of these emails are sent automatically (in particular the internal notification about new requests and the order confirmation after a contract is concluded); others are sent only after manual review and approval by us. According to Mailjet, data storage takes place in data centres in Frankfurt am Main (Germany) and Saint-Ghislain (Belgium); Mailjet may use further subprocessors, including outside the EU/EEA, for which appropriate safeguards such as EU Standard Contractual Clauses apply. This processes the recipient's email address, name and the respective message content. The legal basis is Article 6(1)(b) GDPR for carrying out the repair order. A data processing agreement under Article 28 GDPR is in place with Mailjet / Sinch Email SAS. If the service is not configured, no automated emails are sent; send attempts are then only logged internally.
12. Cloudflare Turnstile
Cloudflare Turnstile, a service of Cloudflare, Inc., is used to protect the repair form and RMA login against automated attacks. Necessary signals about your browser and device (among other things, to detect automated access) are transferred to and evaluated by Cloudflare in the process; a transfer to the USA is possible. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is protecting forms, accounts and systems against abuse. Where information is stored on or read from your device, this happens only to the extent technically necessary. A data processing agreement under Article 28 GDPR is in place with Cloudflare, Inc.
13. Files and uploads
Uploaded files are used only to process the request or order. Please do not upload unnecessary personal or highly sensitive data. Files are made available only to authorised persons.
14. Local icons
FontAwesome files are hosted locally. No connection to FontAwesome servers is made.
15. External links
External services such as LinkedIn, WhatsApp or Microsoft Teams are opened only through simple links or after active consent. The RMA customer portal may also show simple tracking links to carrier websites (e.g. DHL, UPS, DPD, GLS, Hermes, FedEx). The provider’s privacy terms apply after opening an external link.
16. Recipients and international transfers
Depending on how the website is used, data may be transferred especially to Google (calendar synchronisation through our self-hosted EasyAppointments instance, limited to time, service type and internal booking number, see section 7), WhatsApp / Meta, Microsoft, to Cloudflare, Inc. (Turnstile form security check, possibly with transfer to the USA) and, for optional automated email delivery, Mailjet / Sinch Email SAS (data storage according to the provider in Frankfurt am Main and Saint-Ghislain, possibly further subprocessors). Transfers outside the EU or EEA take place only when the applicable legal requirements are met.
17. Retention
Personal data are stored only as long as needed for the relevant purpose. They are then deleted or restricted unless legal retention, evidence or limitation periods apply. In detail:
Server logs: generally up to 30 days, longer in case of a concrete suspicion of abuse until the matter is resolved.
Appointment data (EasyAppointments): until the appointment has passed plus a reasonable follow-up period, then deleted unless linked to repair or invoicing records.
Repair requests and RMA orders: for the duration of processing and warranty, then in line with German commercial and tax retention periods (generally 6 years under § 257 HGB, or 10 years under § 147 AO for invoicing-relevant records such as invoices).
Uploaded files (photos, PDFs): for as long as the associated RMA case file; invoicing-relevant attachments are subject to the same periods as invoices.
Quote and status history (including rejected or superseded quotes): for as long as the associated RMA case file, see above.
Email logs (delivery records, error messages): generally up to 12 months for tracking and troubleshooting, then deleted unless an ongoing matter is affected.
18. Your rights
Subject to the legal requirements, you have rights including access, correction, deletion, restriction, data portability and objection. Consent can be withdrawn at any time with future effect.
19. Right to complain
You may lodge a complaint with a data protection authority. The competent authority includes:
The Hessian Commissioner for Data Protection and Freedom of Information
Postfach 3163, 65021 Wiesbaden, Germany
Email: poststelle@datenschutz.hessen.de
Phone: +49 611 1408-0
20. Changes
This Privacy Policy may be updated when technical, legal or organisational changes occur.