Free Social Media
This is Onreef's Privacy Policy. Protecting your personal data is a central concern for us. This Privacy Policy explains which personal data are processed when using Onreef. These provisions apply to all Onreef services.


1. Registration and Use

1. When registering, the operator processes the information required to establish and administer the membership.
2. When Onreef is used, technical data are also generated insofar as they are required for operation, security and provision of the functions.
3. Processing serves in particular to provide Onreef, enable registration and protect against misuse.


2. Information and Content

1. Users may voluntarily provide additional information and post their own content on Onreef.
2. Which information and content are visible to others depends on the selected settings and the respective publication. Publicly shared content may also be visible outside Onreef.
3. Users' own information and content can generally be changed or deleted.


3. Messages and Encryption

1. Messages, including transmitted files, are protected by highly secure end-to-end encryption. Only senders and intended recipients can read the content; the operator has no access to it.
2. The technical data required for transmission, delivery, security and operation are processed.
3. If messages are reported or voluntarily forwarded for review, the content transmitted in this process may be reviewed.


4. Applications and API

1. Approved users may connect Onreef with linked applications or interfaces. The data and permissions associated with the respective access are processed in this process.
2. Connections receive access only to the approved data. Access is limited accordingly to protect privacy.
3. Where applications from third-party providers are connected, those providers are responsible for their own data processing. Granted access rights can be revoked again.


5. Purposes and Legal Bases

1. The operator processes data insofar as this is necessary to provide and use Onreef, for security, support or performance of contracts.
2. Depending on the purpose, processing is based on the user agreement, legal obligations, legitimate interests in reliable operation, or consent. Consent is obtained only if it is required for the respective purpose.


6. Support and AI

1. The operator may use AI and automated systems to support functions and answer user inquiries.
2. The AI systems provided by the operator are operated on its own servers to protect users. User data are not passed on to external providers or used for training.
3. Automated conversation partners are identified as AI or bots. AI-generated answers may contain errors.


7. Cookies and Storage

1. Onreef uses technically necessary cookies and comparable forms of storage, in particular for login, session, language, security and selected settings.
2. Anonymised and privacy-friendly analytics methods are used to improve and technically evaluate Onreef.
3. Optional cookies or comparable functions are used only if the requirements necessary for them are met.


8. Recipients and Transfers

1. Technical service providers as well as email or payment providers may be used for individual functions. They receive only the data required for their respective task.
2. Data may also be processed in other countries in this context. Where required, adequacy decisions, Standard Contractual Clauses or other safeguards provided for by law are used.
3. Requests from authorities or comparable bodies are reviewed. Data are disclosed only to the minimum extent required where there is a legal basis and a binding obligation; unjustified requests are rejected. Requests, the requesting authority or comparable body, and their nature and scope may be transparently documented publicly. Differing, inconvenient or critical opinions are expressions of free speech and, by themselves, are not grounds for a measure.


9. Retention and Deletion

1. Data are stored only for as long as they are required for use of Onreef, security, contracts or legal obligations.
2. Upon deactivation, the technical association is retained for later reactivation.
3. Upon permanent deletion, the association with the membership is permanently removed. Physical deletion may take place with a delay as part of technical deletion cycles; data required by law may be retained for a correspondingly longer period.


10. Rights and Complaints

1. Under applicable law, users may in particular request access, rectification, erasure, restriction or data portability, object to processing, and withdraw consent with effect for the future.
2. Where there are justified doubts about identity, suitable proof may be required.
3. Users may also lodge a complaint with the competent data protection supervisory authority.
4. Users may object to processing based on legitimate interests on grounds relating to their particular situation.


11. Security and Protection

1. The operator implements appropriate technical and organisational measures to protect data against loss, misuse and unauthorised access.
2. These include, in particular, access restrictions, encryption, backups and security reviews.
3. The protective measures are further developed in line with technical possibilities. No system can guarantee absolute security.


12. Updates and Language

1. The operator may revise this Privacy Policy.
2. Users are informed in advance of substantive changes and, where required, their consent is obtained. Consent may be given, among other ways, via "Register" or "Login".
3. Purely editorial changes do not require renewed consent.
4. The contractual language and authoritative legal texts on Onreef are in German. Other language versions may be provided; in the event of ambiguities or contradictions, only the German version is authoritative and binding. The controller and contact details are set out in the Legal Notice.