Privacy Policy

Data Protection Statement CHECKRESI

Version: August 2026

1. Controller

The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:

CHECKRESI
Rosensteingasse 88/35
A-1170 Vienna, Austria

Email: hello@checkresi.com

For any data protection-related inquiries, you may contact us at any time using the email address stated above.

2. General Information on Data Processing

We process personal data exclusively in accordance with the applicable data protection regulations, in particular the General Data Protection Regulation (GDPR) and the applicable national data protection laws.

Personal data is processed only to the extent necessary to provide our services, fulfil contractual obligations, on the basis of your consent, or on the basis of legitimate interests.

3. What Data We Process

When using our platform, the following categories of personal data may in particular be processed:

Master Data

  • First and last name
  • Company name
  • Email address
  • Web addresses
  • Username
  • Passwords

Usage Data

  • Time and duration of use
  • Functions used
  • Device information
  • Browser information
  • IP addresses
  • Log data

Payment Data

  • Transaction data
  • Billing information
  • Payment status

We generally do not store complete credit card or payment details ourselves.

Check and Evaluation Data

  • Responses to questionnaires
  • Individual evaluation results
  • Historical check results

4. Processing of Special Categories of Personal Data

The information collected as part of our questionnaires may allow conclusions to be drawn about an individual’s mental health status, subjective perception of stress or resilience.

Such data may therefore constitute special categories of personal data within the meaning of Article 9 GDPR.

Processing is carried out exclusively:

  • on the basis of your explicit consent pursuant to Article 9(2)(a) GDPR;
  • for carrying out the checks and evaluations requested by you;
  • for providing specific content and recommendations.

Providing consent is voluntary.

You may withdraw your consent at any time with effect for the future. The lawfulness of processing carried out prior to the withdrawal of consent shall remain unaffected.

5. Purposes of Data Processing

We process personal data in particular for the following purposes:

  • Providing the platform
  • Conducting checks
  • Creating specific evaluations
  • Displaying charts and results
  • Providing recommendations, exercises and information
  • Managing user accounts
  • Communicating with users
  • Processing payments
  • Fraud prevention and IT security
  • Improving and further developing our services
  • Operating Partner and Affiliate programs
  • Using anonymised data for statistical or scientific evaluations

6. Legal Bases for Processing

The processing of personal data is carried out in particular on the following legal bases:

  • Article 6(1)(a) GDPR (consent)
  • Article 6(1)(b) GDPR (performance of a contract)
  • Article 6(1)(c) GDPR (compliance with a legal obligation)
  • Article 6(1)(f) GDPR (legitimate interests)

Where health data is processed:

  • Article 9(2)(a) GDPR (explicit consent)

7. Recipients of Personal Data

Personal data may be transferred to the following categories of recipients:

  • Hosting and cloud service providers
  • IT and software service providers
  • Payment service providers
  • Affiliate and Partner platforms
  • Analytics and tracking service providers
  • Tax advisors and accounting service providers
  • Authorities and courts, where legally required

Data shall only be transferred to the extent necessary.

8. Payment Processing via Paddle

For the processing of paid services, we use Paddle as a payment service provider and Merchant of Record.

In particular, the following data may be processed:

  • Name
  • Email address
  • Billing information
  • Payment information
  • Transaction data

Data processing is carried out independently by Paddle.

Further information can be found in Paddle’s Privacy Policy.

9. Affiliate and Partner Program (Partnero)

We use Partnero to manage our Partner and Affiliate program.

In particular, the following data may be processed:

  • IP addresses
  • Referrer information
  • Click and conversion data
  • Technical identification characteristics
  • Usage data

The processing is carried out for the attribution of referrals, commissions and Partner activities.

Where consent is required for the use of tracking technologies, processing shall only take place after the relevant consent has been obtained.

10. Hosting and Technical Infrastructure

Our platform is operated using external technical service providers.

Personal data may therefore be processed on servers operated by our hosting and cloud service providers.

Hosting provider:  Hetzner Online GmbH (Germany). For the storage and management of our data, we also use the database platform Supabase.

With all processors engaged by us, the contracts required by law pursuant to Article 28 GDPR shall be concluded.

11. Transfers of Data to Third Countries

Where personal data is transferred to recipients outside the European Union (EU) or the European Economic Area (EEA), such transfers shall only take place in compliance with the requirements of Articles 44 et seq. GDPR.

This may include, in particular:

  • Adequacy decisions of the European Commission
  • Standard Contractual Clauses of the European Commission
  • Other legally recognised safeguards

12. Automated Evaluations

The results of our checks are generated automatically on the basis of the answers provided by you.

These automated evaluations are used exclusively for informational, preventive and self-reflection purposes.

No automated decisions producing legal effects or similarly significant effects within the meaning of Article 22 GDPR are made.

The content and recommendations provided are intended solely for informational and preventive purposes and do not constitute medical, psychological, therapeutic or business consulting, advice or diagnosis.

13. Data Retention Period

We store personal data only for as long as necessary for the respective purposes or where statutory retention obligations apply.

In particular, the following principles apply:

  • Account data: until the user account is deleted
  • Check and evaluation data: for as long as the user account exists or until a deletion request is submitted
  • Billing and tax-related data: in accordance with statutory retention obligations
  • Records of consent: for as long as necessary to fulfil statutory documentation and evidentiary obligations

14. Your Rights

Under the GDPR, you have, in particular, the following rights:

  • Right of access (Article 15 GDPR)
  • Right to rectification (Article 16 GDPR)
  • Right to erasure (Article 17 GDPR)
  • Right to restriction of processing (Article 18 GDPR)
  • Right to data portability (Article 20 GDPR)
  • Right to object (Article 21 GDPR)
  • Right to withdraw consent previously given

You may contact us at any time to exercise your rights.

15. Right to Lodge a Complaint

If you believe that the processing of your personal data violates data protection law, you have the right to lodge a complaint with a data protection supervisory authority.

In Austria, this is in particular:

Austrian Data Protection Authority (Datenschutzbehörde)
Barichgasse 40–42
A-1030 Vienna
Austria

16. Data Security

We implement appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access or unlawful processing.

Our security measures are continuously improved in accordance with technological developments.

17. Changes to this Privacy Policy

We reserve the right to amend this Privacy Policy where necessary due to legal, technical or organisational changes.

The current version shall be published on our website and/or within our platform.