General Data Privacy Policy (GDPP)

1 General

Expatrio Global Services GmbH (hereafter referred to as „Expatrio“) takes your privacy and the protection of your data very serious. We ask you to read this General Data Privacy Policy (“GDPP”, also the “Policy”) carefully as it contains important information about what to expect when Expatrio collects, processes and uses personal information about you. By using Expatrio’s services, you are deemed to have read, understood and given your consent to the terms of this Policy. For some dedicated services such as the X-patrio Blocked Account, a Special Data Privacy Policy (“SDPP”) applies in addition to this GDPP.

This Policy applies to information X-patrio collects on www.expatrio.com and its sub-domains (“Website”) about:

  • visitors to Expatrio’s Website,
  • users who register with us, and
  • our clients.

You can access this Policy on our Website at any time under the “Privacy Policy”.

Please note that this Policy only describes the data collection, processing and usage of your personal data that takes place in the context of the usage of www.x-patrio.com and related functions, as laid out in the General Terms and Conditions (GTC).

2 Responsible Party and Revocation

The party responsible for the collection, processing and use of data within the meaning of the General Data Protection Regulation (“GDPR”) is Expatrio as the operator of the Website . The collection, storage, as well as the use of such information shall therefore only take place within the framework of the applicable laws.

You can revoke any of the consents to the collection, processing and use of personal data provided in this Policy in writing or by e-mail with effect for the future until further notice. In this case, we will cancel further processing and use of personal data, as well as block or delete these, unless we are obligated by regulations to further processing, and in particular, to further storage. Please note that the revocation of the consents given may lead to restricted access of X-patrio’s services or termination of X-patrio’s services and Website use. Please address your cancellation in writing to Expatrio Global Services GmbH, Friedrichstraße 194, 10117 Berlin, or by e-mail to service@expatrio.com.

3 Subject of the Data Protection

We collect, process and use your personal data only in accordance with this Policy and the relevant data protection laws. According to the GDPR, personal data are any details of personal or factual circumstances of an identified or identifiable natural person such as name, address, e-mail address or telephone number and, if applicable, also usage data. Usage data is the data that is required for using our Websites, and includes information on the beginning, end and extent of use of our Website and registration information. Additionally, content data, such as scanned passports and picture uploads may be affected. Based on the features offered by the service X-patrio, special categories of personal data within the meaning of the GDPR may also be affected. Further data, such as health data if required for insurance products and data to comply with legal obligations (e.g. the German Anti Money Laundering Act "GwG") may be requested.
Your personal data may be processed on servers outside the European Union (“EU”) and the European Economic Community (“EEC”), that is outside the scope of Directive 95/46/EC of the European Parliament and of the Council, dated October 24, 1995, on the protection of individuals with regard to the processing of personal data and on the free movement of such data (OJ. EC No. L 281 p. 31).

4 Collection and Use of Personal Data

This data is needed individually for the following purposes and only be used on the basis of the applicable statutory provisions (GDPR and Sections 11 ff. TMG.), if the use is expressly permitted on the basis of these regulations:

4.1 Data Collection from all Visitors to the Website

When accessing the X-patrio Website, your internet browser automatically transmits data for technical reasons. The following data will be stored separately from other data that you might transmit to us:

  • Date and time of access, 
  • Browser type/version, 
  • Operating system used, 
  • Uniform Resource Locator (URL) of the previously visited website, 
  • Internet protocol (IP) address,
  • Amount of data sent. 

Some of this data will be aggregated exclusively for statistical and technical reasons, which means that we will not be able to identify you individually. 

4.2 Data Collection from Users registering with Expatrio

In addition to the aforementioned and in order to be able to take full advantage of X-patrio’s services, you may have to voluntarily register, create an account and/or submit certain personal data along the process.
This applies to the following categories of data:

  • Name and full address, 
  • Landline telephone number and/or mobile telephone number,
  • E-mail address,
  • Birth data, 
  • Social media profile(s).

4.3 Data Usage of Unregistered and Registered Users

When you use the services of Expatrio as described in the GTC, the personal data that you have entered will only be used:

  • for the provision of services offered on www.expatrio.com
  • for special categories of personal data, only if you have consented herein, 
  • for the purpose of sending news about products and services that you may be interested in; as far as this is required by law, and of course only if you have given the appropriate consent
  • to respond to requests and questions from third parties to proceed your requests and purchases.

4.4 Data Processing and collection when Using the Website

4.4.1 Cookies

The Website makes use of so called cookies. Cookies are small text files that are stored on your computer and saved by your browser. Cookies on your computer do no harm and do not contain viruses. Cookies are used to make our offer more user-friendly, effective and safer. Most of the cookies we use are so called "session cookies". They are automatically deleted after your visit. Other cookies remain in your device memory until you delete them. These cookies allow us to again recognize your browser, the next time you visit. You can set your browser so that you are informed about the use of cookies and enable cookies in individual cases only, activate the acceptance of cookies for specific cases or a general rule, as well as the automatic deletion of cookies when you close the browser. Upon deactivation of cookies, the functionality of this site may be limited.

4.4.2 Zendesk

The Website uses Zendesk, a customer service platform provided by Zendesk Inc., (“Zendesk”). For the provision of help center services, in particular for processing submitted requests and manage correspondence with our Users, we make use of Zendesk’s customer service platform. Zendesk uses cookies. The information generated by the cookies about your use of the platform is transmitted to a servers outside Germany. Zendesk will use this information to evaluate your use of the platform, compile reports on platform activity for platform operators and provide other services related to platform usage and internet usage. In addition, Zendesk may also transfer this information to third parties where required by law or if such third parties process the information on Zendesk's behalf. The Zendesk privacy policy and cookie policy can be found at: https://www.zendesk.com/company/privacy/ and https://www.zendesk.com/company/customers-partners/cookie-policy/?cta=cookie

4.4.3 Google Analytics, Google Tag Manager, Leverate Media

The Website uses Google Analytics and Google Tag Manager, a web analytics service provided by Google Inc. (“Google”). Google Analytics and Google Tag Manager use “cookies”. The information generated by the cookies about your use of this Website (including your abbreviated IP address) is transmitted to a Google server in the US and stored there. Google will use this information to evaluate your use of the Website, compile reports on Website activity for Website operators and provide other services related to Website usage and Internet usage. In addition, Google may also transfer this information to third parties where required by law or if such third parties process the information on Google’s behalf. Concomitant, we are sharing relevant data with Leverate Media GmbH (https://leverate.de/en/privacy/) in accordance with point 4.6 of this Privacy Policy.
If you do not agree to the aforementioned Website analysis, you can disable Google Analytics with the help of a browser add-on. The add-on can be installed here: https://tools.google.com/dlpage/gaoptout?hl=en.

4.4.4 Calendly

The Website also uses the functions of Calendly, a scheduling assistant for calls and/or meetings provided by Calendly LLC (“Calendly”). Calendly uses cookies. The information generated by the cookies about your use of the platform is transmitted to a servers outside Germany. Calendly will use this information to evaluate your use of the platform, compile reports on platform activity for platform operators and provide other services related to platform usage and internet usage. In addition, Calendly may also transfer this information to third parties where required by law or if such third parties process the information on Calendly's behalf. The Calendly privacy policy can be found at: https://calendly.com/pages/privacy.

4.4.5 Tapfiliate

The Website also uses the functions of Tapfiliate, an affiliate management tool provided by Tapfiliate B.V. ("Tapfiliate"). Tapfiliate uses cookies. The information generated by the cookies about your use of the platform is transmitted to a servers outside Germany. Tapfiliate will use this information to evaluate your use of the platform, compile reports on platform activity for platform operators and provide other services related to platform usage and internet usage. In addition, Tapfiliate may also transfer this information to third parties where required by law or if such third parties process the information on Tapfiliate's behalf. The Tapfiliate privacy policy can be found at: https://tapfiliate.com/privacy/privacy-policy/.

4.4.6 MANGOPAY

The Website also uses MANGOPAY as an online payment technology. MANGOPAY provides the payment technology underlying X-patrio’s Blocked Account, therefore we are sharing relevant data with MANGOPAY in accordance with point 4.6 of this Privacy Policy. The MANGOPAY privacy policy can be found at: https://www.mangopay.com/privacy/

4.4.7 DR-WALTER

The Website also cooperates with DR-WALTER GmbH in order to provide all kinds of insurance policies (primarily so-called "Incoming Insurances") for its users. To provide cross-company customer support for Expatrio and DR-WALTER users, we are sharing relevant data with DR-WALTER in accordance with point 4.6 of this Privacy Policy. The DR-WALTER privacy policy can be found at: https://www.dr-walter.com/en/data-protection.html

4.5 Social Plugins

Referral buttons (so-called social plug-ins / like-buttons) are provided on www.x-patrio.com by and allow users to share content with the social network facebook.com and instagram.com and their users.

4.5.1. Facebook

The operator of this network is Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, U.S.A. (hereafter referred to as “Facebook”). The data protection friendly “Shariff” technology is used on www.x-patrio.com (see: http://www.heise.de/ct/ausgabe/2014-26-Social-Media-Buttons-datenschutzkonform-nutzen-2463330.html), which causes usage information (the user-recommended content, including date and time as well as the IP address of the user) to be transmitted to Facebook only in each individual case when the user operates the referral button. Facebook, not X-patrio, is responsible for the further handling of this information on Facebook. The purpose and scope of any further uses of the information by Facebook, and the respective rights and settings options for protecting the privacy of the user can be found in the Facebook data protection guidelines (available at http://www.facebook.com/policy.php). If transferring of data to Facebook is not desired, the user must refrain from operating the referral button.

4.5.2. Instagram

Plugins of the social network Instagram are also integrated into our webpages (provider:. Instagram, LLC ("Instagram")). By means of the use of Instagram, the web pages you visited will be linked with your Instagram account and made known to other users. This data is also thereby transmitted to Instagram. We point out that we, as providers of the sites, have no knowledge of the content of the transmitted data and their use by Instagram. For more information, please see the privacy statement of Instagram at https://help.instagram.com/155833707900388.

4.6 Disclosure to Third Parties and Data Protection on Third Party Websites

We do not sell or trade your personally identifiable information. A disclosure of personal data to third parties without your consent only takes place in the following cases:

  • If it serves the investigation of an unlawful use of Expatrio or it is necessary for litigation, personal information will be forwarded to law enforcement agencies and, where appropriate, to injured third parties. This, however, will only be done if there is concrete evidence of an unlawful or improper use.
  • A transfer can also take place if this serves the enforcement of the GTC or other agreements. Expatrio is also legally obliged to provide information to certain public bodies, upon request. These are law enforcement authorities pursuing fines for proven offences and the tax authorities.
  • Occasionally, we rely on contractually bound external companies and external service providers in order to provide our services, for example customer services or the hosting of www.expatrio.com. In such cases, the information is passed on to these companies or individuals to enable further processing. These trusted external service providers are carefully selected by us and checked regularly to ensure that your privacy is maintained. They may use your data exclusively for the purposes specified by us. Moreover, they are contractually bound by us to treat your information in accordance with this Policy and German data protection laws.
  • www.expatrio.com may contain links to the pages of other providers. Since Expatrio has no influence on these websites, the user is advised to inquire about the information on data protection possibly offered there. X-patrio takes no responsibility for the content of linked pages.

5 Data Security

We are committed to maintaining the security of personal data at all time. In order for the data to be transferred as securely as possible, Expatrio uses an encryption with TLS 1.2 or a later version (transport layer security). This type of encrypted data transmission particularly applies to all personal data. However, the transmission of information via the Internet is not completely secure and therefore we cannot guarantee the security of data transmitted via the Internet to our Website. We secure our Website and other systems against loss, destruction, access, modification or distribution of your data by unauthorized persons, using latest technical and organizational standards.

6 Deleting your Data

If your data is no longer required for the aforementioned purposes, they will be deleted, as far as permitted by applicable law as Expatrio might be obliged to store certain data. When you delete your user account, your profile will be deleted completely and permanently. If data must be retained for legal reasons, it will be inaccessible. The data is then no longer available for further use.

7 Information and Right of Access

You have the right to receive information about the data stored by us related to you, upon request. Furthermore, you have the right to correct, block and delete inaccurate data. To do so, please contact service@expatrio.com or by post at the following address: Expatrio Global Services GmbH (X-patrio), Friedrichstraße 194, 10117 Berlin.

8 Deemed Consent

You are deemed to have understood and given your consent to the terms of this Policy:

  • you voluntarily, or in reasonable circumstances, provide the data to Expatrio for the purpose and use of our services; or 
  • in any other circumstances deemed to given under the BDSG; and 
  • through your continued dealing and use of the Website.

9 Changes to the Policy

We keep our privacy policy under regular review and hence Expatrio reserves the right to change this Policy. If Expatrio changes this Policy, you will find the changes and the current version of the privacy policy on our Website. This privacy policy is the 4th version and was last updated on February 26th, 2019:

Version Updated Updates
1.0 12/09/2017 n/a
2.0 24/05/2017 Added Tapfiliate tool in the tracking section
Applied General Data Protection Regulation
3.0 21/01/2019 Address update
Added Leverate Media GmbH
4.0 26/02/2019 Added MANGOPAY SA