Data Protection Statement CHECKRESI
Version: August 2026
The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:
CHECKRESI
Rosensteingasse 88/35
A-1170 Vienna, Austria
Email: hello@checkresi.com
For any data protection-related inquiries, you may contact us at any time using the email address stated above.
We process personal data exclusively in accordance with the applicable data protection regulations, in particular the General Data Protection Regulation (GDPR) and the applicable national data protection laws.
Personal data is processed only to the extent necessary to provide our services, fulfil contractual obligations, on the basis of your consent, or on the basis of legitimate interests.
When using our platform, the following categories of personal data may in particular be processed:
We generally do not store complete credit card or payment details ourselves.
The information collected as part of our questionnaires may allow conclusions to be drawn about an individual’s mental health status, subjective perception of stress or resilience.
Such data may therefore constitute special categories of personal data within the meaning of Article 9 GDPR.
Processing is carried out exclusively:
Providing consent is voluntary.
You may withdraw your consent at any time with effect for the future. The lawfulness of processing carried out prior to the withdrawal of consent shall remain unaffected.
We process personal data in particular for the following purposes:
The processing of personal data is carried out in particular on the following legal bases:
Where health data is processed:
Personal data may be transferred to the following categories of recipients:
Data shall only be transferred to the extent necessary.
For the processing of paid services, we use Paddle as a payment service provider and Merchant of Record.
In particular, the following data may be processed:
Data processing is carried out independently by Paddle.
Further information can be found in Paddle’s Privacy Policy.
We use Partnero to manage our Partner and Affiliate program.
In particular, the following data may be processed:
The processing is carried out for the attribution of referrals, commissions and Partner activities.
Where consent is required for the use of tracking technologies, processing shall only take place after the relevant consent has been obtained.
Our platform is operated using external technical service providers.
Personal data may therefore be processed on servers operated by our hosting and cloud service providers.
Hosting provider: Hetzner Online GmbH (Germany). For the storage and management of our data, we also use the database platform Supabase.
With all processors engaged by us, the contracts required by law pursuant to Article 28 GDPR shall be concluded.
Where personal data is transferred to recipients outside the European Union (EU) or the European Economic Area (EEA), such transfers shall only take place in compliance with the requirements of Articles 44 et seq. GDPR.
This may include, in particular:
The results of our checks are generated automatically on the basis of the answers provided by you.
These automated evaluations are used exclusively for informational, preventive and self-reflection purposes.
No automated decisions producing legal effects or similarly significant effects within the meaning of Article 22 GDPR are made.
The content and recommendations provided are intended solely for informational and preventive purposes and do not constitute medical, psychological, therapeutic or business consulting, advice or diagnosis.
We store personal data only for as long as necessary for the respective purposes or where statutory retention obligations apply.
In particular, the following principles apply:
Under the GDPR, you have, in particular, the following rights:
You may contact us at any time to exercise your rights.
If you believe that the processing of your personal data violates data protection law, you have the right to lodge a complaint with a data protection supervisory authority.
In Austria, this is in particular:
Austrian Data Protection Authority (Datenschutzbehörde)
Barichgasse 40–42
A-1030 Vienna
Austria
We implement appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access or unlawful processing.
Our security measures are continuously improved in accordance with technological developments.
We reserve the right to amend this Privacy Policy where necessary due to legal, technical or organisational changes.
The current version shall be published on our website and/or within our platform.