Controller
Elite Recovers, Rosenthaler Straße 43-45, 10178 Berlin, Germany, contact@eliterecovers.de. We have not appointed a data protection officer; on our assessment the conditions of Art. 37 GDPR do not apply. Data protection enquiries reach us at privacy@eliterecovers.de.
What we collect, and why
When you send a case report
Your name, email address, and optionally telephone number and country; the type and approximate size of the loss, the period concerned, and your own description of what happened. Legal basis: steps taken at your request prior to a contract, Art. 6(1)(b) GDPR.
When you hold a client account
Your name, email address and a password. The password is never stored: only an Argon2id hash with a server-side secret is kept, from which the password cannot be recovered. Legal basis: performance of the mandate, Art. 6(1)(b) GDPR.
While your case runs
Case records and the investigator's notes, invoices, messages you exchange with us through the portal together with any files you attach, the wallet or bank details you give us for a payout, and ledger entries recording funds received and paid out. Legal basis: performance of the mandate, Art. 6(1)(b) GDPR, and statutory retention duties, Art. 6(1)(c) GDPR.
Automatically, for security
Rejected or failed requests — failed sign-ins, permission denials, malformed requests — are recorded with the source IP address, the browser's user-agent string, the time, and whether a session was present. Legal basis: our legitimate interest in protecting client data against unauthorised access, Art. 6(1)(f) GDPR. These records are deleted after [90] days.
How it is protected
Every field containing personal data is encrypted at rest with AES-256-GCM, individually bound to its own record so a value cannot be moved between records undetected. Email addresses are additionally stored only as a keyed hash, so they can be looked up without being held in readable form. Message attachments are encrypted as files on disk. Passwords use Argon2id with a server-side secret. All traffic is served over TLS.
Access is restricted by role: staff hold only the permissions an administrator granted them, posting funds to a client's balance requires two different members of staff, and opening a client's private messages is itself recorded in an audit log.
Who else processes your data
- Server hosting
- The server on which the application and database run is operated by a hosting provider on our behalf, under a data processing agreement. We name the provider on request.
- Resend
- Delivers transactional email — verification links, password resets, invoices, notifications. Receives the recipient address and the content of that message.
- CoinGecko
- Supplies exchange rates for the indicative fiat value shown beside a balance. Receives only asset symbols and a currency code. No personal data is sent.
We do not use analytics, advertising, social media plug-ins or third-party fonts. Fonts are served from our own server, so no request is made to a third party when you open a page.
Cookies and local storage
See the cookie notice. In short: one session cookie, one language preference, and a text-size preference kept in your own browser. Nothing is used for tracking, and there is no consent banner because none of it requires consent.
How long we keep it
- Case and billing records
- For the statutory retention period: six years for commercial correspondence and ten years for accounting records (§257 HGB, §147 AO), then deleted.
- Security events
- [90] days.
- Session records
- Removed when the session expires; staff sessions last at most 8 hours.
- Case reports that do not become a mandate
- six months after the last correspondence, then deleted.
Your rights
You may request access to your data (Art. 15), correction of it (Art. 16), its deletion (Art. 17), restriction of its processing (Art. 18), a copy in a portable format (Art. 20), and you may object to processing based on our legitimate interests (Art. 21). Where processing rests on consent, you may withdraw it at any time with effect for the future.
To exercise any of these, write to privacy@eliterecovers.de. You also have the right to complain to a supervisory authority; the one responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59-61, 10555 Berlin, Germany.
Is providing data required?
Providing the data described above is necessary for us to assess and pursue a recovery. You are not obliged to provide it, but without it we cannot take on the mandate.
Automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. Every assessment of a case is made by a person.
Changes
This notice was last updated on 25 September 2026. We will publish any change here.