As the provider of the Taxkiwi.com Services, we are responsible for the processing of your personal data, as defined in the EU General Data Protection Regulation (“GDPR”). Our contact details are as follows:
Taxkiwi.com, Taxkiwi GbR, headquartered in Bessemerstrasse 82, 12103 Berlin, and its partnership with Taxkiwi Pty Ltd, and its Customer Care branch WTR Partner LLC in Delaware, USA provides the Taxkiwi.com site and its related services, support@Taxkiwi.com.
You can reach our data protection team at the e-mail address above. In addition, we have Taxkiwi.com appointed a Data Protection Officer (“DPO”) who acts on behalf of Taxkiwi.com in supporting our compliance efforts in relation to the processing of personal data. Our DPO can be reached at the above postal address (Attn: DPO).
B. Third Party Links
Our website may, from time to time, contain links to or from partner websites or other third-party sites. These sites and any services that may be accessible through them have their own privacy policies. As we are not responsible for the privacy practices of these sites, we recommend that you review their privacy policies before submitting personal data to them.
C. General Purposes and Legal Bases
When we use the term “personal data”, we are referring to any information that can be used, directly or indirectly, to identify you personally. We process your personal data in accordance with the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG) if at least one of the following Taxkiwi.com :
Performance of Contractual or Pre-Contractual Measures. The data processing is needed for the performance of a contract to which you are party or in order to take the steps requested by you prior to entering into a contract (Art. 6 (1) lit. b GDPR). Data processing that falls under this category is done when requested by you and can include performing transactions, customer support, requirement analysis and processing your tax-related data needed for your tax declaration in order to fulfill our Service Agreement with you.
Consent. Where you have agreed to the processing of your personal data for one or more specific purposes, such data processing by us is permitted on the legal basis of your consent (Art. 6 (1) lit. a, Art. 9 (2) lit. a GDPR). Your consent is revocable at any time. Where you revoke your consent, we will not process your personal data based on your consent following your revocation.
Legitimate Interests. The data processing is needed for the purposes of the legitimate interests pursued by us Taxkiwi.com, the controller, or a third party, except where those interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data (Art. 6 (1) lit. f GDPR). Data processing that falls under this category can include marketing or market and opinion analysis, ensuring IT security, assessment and optimization of processes, enforcement of claims or defenses in legal proceedings and developing our Services and Taxkiwi.com.
Legal Compliance. The data processing is necessary for compliance with a legal obligation to which we are subject (Art. 6 (1) lit. c GDPR). We are subject to several legal obligations that necessitate certain data processing activities. This includes verification of your identity, prevention of fraud and upholding our control and reporting obligations.
Processing on Behalf of Taxkiwi.com. In several instances, we engage service providers and processors to process personal data on our behalf under Art. 28 GDPR. The data processing that falls under this category is carried out pursuant to a separate agreement with the respective processor. We ensure that this agreement contains sufficient protection and guarantees for the protection of your personal data and your rights with respect to that data, in each case in compliance with the GDPR.
D. Personal Data We Collect and How We Process It
We process your personal data to provide you with our best Services. We collect your personal data either through your voluntary input or automatically when you user our Taxkiwi.com or visit our website (including using tacking technologies, as discussed in Tracking Technologies in Section E). This section discusses the specific categories of personal data that we process.
Device and Technical Data. Certain technical data is automatically collected and transmitted to us by your browser when you access our website. Such information includes data about your internet browser, operating system, IP address, time of the page request, referrer URL, device information, session information, size of the requested file and any status or error codes. The information is logged in server log files, which we process to ensure the functionality of our website, gather statistical information about the use and development of our website, and for general data security and error analysis purposes. With respect to ensuring the functionality of our website, the basis for our data processing is Art. 6 (1) lit. b GDPR (i.e. contractual or pre-contractual measure). With respect to monitoring for data security and error analysis, the basis for our processing is Art. 6 (1) lit. f GDPR (i.e. legitimate interests).
Registration Data. There is no registration, sign up or login on Taxkiwi.com. We do not store these data. The system creates a link and send this link to the provided email address from the client. The client can easy continue with his or hers application by using this link to continue. It the link is not being used within 30 days, the link and its data will be removed.
Please note that we use technical services (e.g. servers) provided by Google LLC. We pay careful attention to the highest technical security standards and all data is stored in Europe. For technical reasons, however, it may Taxkiwi.com that the infrastructure is maintained or partly provided from the USA. As we process sensitive data, we strive for maximum transparency in this respect as well.
Tax Data. Following the forms, you will be asked a series of questions through our Taxkiwi.com designed to capture the tax-relevant information needed to fill out your tax declaration digitally. These questions ask you for information about your name, employment status, address, religious affiliation, occupation, employer, income statements, secondary residence, competent tax office, tax identification number, training and education, business expenses, professional associations, income from capital asset and other income, insurance, medical expenses, donations, church tax, household expenses, and tax loss carry forwards. As already mentioned, such tax-relevant information may include “sensitive personal data” such as data related to your health, religious affiliation or trade union membership, for which we need your consent to process in order to provide the Services, as this information is required to calculate your tax return amount. Your tax data is also stored to further streamline and simplify your declaration for next year. Our legal basis for processing your tax data as described in this section is thus Art. 6 (1) lit. b GDPR (i.e. performance of a contract), and our legal basis for processing any sensitive personal data is Art. 6 (1) lit. b GDPR (i.e. performance of a contract) and Art. 6 (1) lit. a, Art. 9 (2) lit. a GDPR (i.e. consent). Taking into consideration the statutory deadlines for filing your tax return (§ 46 II No. 8 EStG, § 169 II No. 2 AO), we store your tax data fully encrypted in our database located in Europe for a period of ten years following transmission to the tax authority. After that the data is anonymized completely.
Transaction Data. To submit any services generated through the Taxkiwi.com to any authorities, you must enter into a Service Agreement with Taxkiwi.com in accordance with our Terms and Conditions. Pursuant to this Service Agreement, you may be required to pay a one-time submission fee with respect to each tax declaration submitted, depending on the amount of your calculated for the requested services. For users in Germany, the submission fee is payable by direct debit and is processed via our external payment service provider Stripe. Stripe will receive your name and bank details to process payment and will notify us upon receipt of payment. We won’t store your payment information but we do process your transaction information (i.e. when you paid, when payment was processed and the amount of your payment) for reporting purposes for ten years in combination with your registration data. Our legal basis for processing your transaction data is Art. 6 (1) lit. b GDPR (i.e. performance of a contract) and our legal basis for its retention is Art. 6 (1) lit. c GDPR (i.e. compliance with our legal obligations (§ 257 HGB, § 147 AO, § 169 AO)) as we are required under law to store relevant financial and accounting documents. Please note that we also use Stripe for repayment and invoicing, and to handle relevant security and fraud prevention measures. For more information about Stripe’s data processing, please refer to their privacy notice.
Identification. For legal reasons, we are required to confirm your identity prior to final submission of your services. We verify your identity by having you submit a copy of proof of address. You will have the opportunity to review your prepared services, confirm the accuracy of your details inputted and authorize us to submit the requested services to the authority. For other legal reasons, we are obliged to be able to provide information on any person who has instructed a transfer of tax documents to the authority. Thus, we are processing your identification data and storing it for the legally stipulated period of five years after the end of the year in which the documents were transmitted in order to verify your identity and your authorization of us is Art. 6 (1) lit. c GDPR (i.e. compliance with our legal obligations (§ 87d (2) AO)).
ELSTER Data Processing. We submit your tax declaration using ELSTER, which is the software the tax authorities provide for purposes of processing electronic filings based on Art. 6 (1) lit. b, Art. 6 (1) lit. a, Art. 9 (2) lit. a GDPR. As the transmission of your tax declaration involves data privacy related obligations of the tax authorities, we are obliged to inform you of the following regarding ELSTER:
“The ELSTER software is used to collect personal data within the meaning of Art. 4 (1) of the GDPR and Art. 9 (1) of the GDPR. In addition to the pure data required for tax assessments, the software collects information on the type of operating system of the user and transmits this to the tax authorities. This data is needed for ensuring the proper processing of the data and for preventing errors in such processing. The data is used in the context of Art. 6 (1) lit. e GDPR in conjunction with Art. 6 (3) lit. b GDPR in accordance with federal and state tax laws by the tax authorities and only for the purpose stated.”
You can read more about the data processing that is done via ELSTER by the tax authorities in their informational brochure available here. ELSTER PDF. After your tax declaration is submitted to and received by the tax office, you can view the .pdf version of your tax declaration (“Elster PDF”) directly in the Taxkiwi.com when you are logged into your account. We process your Elster PDF for this purpose and store it if your user account is active. If you do not want your Elster PDF to be available to you in the Taxkiwi.com, you can let us know and we will delete this data (in which case you will no longer be able to retrieve your Elster PDF through us). Our legal basis for processing this information is Art. 6 (1) lit. b, Art. 6 (1) lit. a, Art. 9 (2) lit. a GDPR (i.e. performance of a contract).
Retrieval of Electronic Tax Assessment. We retrieve your electronic tax assessment via the ELSTER portal for statistical and control purposes – namely, to assess any discrepancies between the amount of your refund as calculated using the Taxkiwi.com and as finally determined by the tax office in order to improve the Services and further refine the Taxkiwi.com. This data will not be passed on to any third parties and is kept fully encrypted in our database located in Europe. Our legal basis for processing this data is Art. 6 (1) lit. f GDPR (i.e. legitimate interests), Art. 6 (1) lit. a, Art. 9 (2) lit. a GDPR (i.e. consent). The storage and archiving of your electronic tax assessment is governed by Sections 2 and 3 above.
Support. If you have any questions about our Services, reach out to our customer support team! You can reach support by clicking “Contact our Support Team” on our website. We can’t provide you with any tax advice (so please contact a tax advisor with any tax-related questions), but we’re here to answer any questions you have about how to use the Taxkiwi.com, errors or bugs in the Taxkiwi.com, etc. If your Taxkiwi.com crashes, you can elect to send us a complete error log, containing both technical information and any sensitive tax data that may have been entered, in which case you consent to the transmission of such data in order for us to most effectively trouble any problems. The error log and support requests are saved to your user account. Of course, you have the possibility to delete saved error logs. An error log will be deleted or completely anonymized at the latest 12 months after transmission. Our legal basis for processing error logs is Art. 6 (1) lit. a, Art. 9 (2) lit. a GDPR (i.e. consent) and our legal basis for processing your other support requests is Art. 6 (1) lit. b GDPR (i.e. performance of a contract).
Marketing and Communications Data. If you have used the Services previously or if you have subscribed to our newsletter via our website, we may send you certain marketing e-mails including information about updates to our Services or special offers from us. Our legal basis for processing this data is Art. 6 (1) lit. f GDPR (i.e. legitimate interests) for existing customers and Art. 6 (1) lit. a GDPR (i.e. consent) for newsletter subscribers. If you do not wish to receive any marketing e-mails from us, you can opt-out anytime by using the “unsubscribe” link in any e-mail we send you or by sending us an e-mail at support@Taxkiwi.com.
E. Tracking Technologies
First-Party Cookies. We use first-party cookies to provide, protect and improve our Services, such as by personalizing content, tailoring, and measuring ads and providing an optimized user experience. For example, we use certain cookies that are needed for the operation of our Taxkiwi.com, such as for authentication when you log in to your account. We also use analytical or performance cookies to recognize and count the number of users on the Taxkiwi.com or our website. We may use functionality-related cookies to tell us, for example, whether you have used the Services before, or to remember your language preferences or even where you left off in the Taxkiwi.com in your last session. In some cases, we may share limited activity data about you with third parties (such as whether you have registered for the Services), to optimize our marketing efforts. The legal basis for the processing is Art. 6 (1) lit. f GDPR.
G. Disabling Tracking.
In many cases, you can manage your cookie preferences and opt-out of having third-party cookies and other data collection technologies used by adjusting the settings on your browser. However, please note that if you choose to remove or reject cookies, this could affect the features and functionality of the Taxkiwi.com.
F. How We Protect Your Data
Security Measures. We maintain state-of-the-art technical measures to secure your personal data from accidental loss and from unauthorized access, use, alteration and disclosure. All transactions, regardless of their nature, are encrypted using SSL technology. The information you provide to us is generally stored in a computer center located in Europe in accordance with high security standards and is. Our data center is equipped with state-of-the-art technical security measures and is certified in accordance with ISO 27018 standards and guidelines. We carefully select and regularly monitor our service providers, who are instructed by us and required to ensure that any data processing including transfers to third countries is subject to stringent technical security measures compliant with European standards.
G. External Transfers
Transfers to Third Countries. Should any processing of your data take place outside of the EU, this will be done in compliance with Art. 44 GDPR – namely, on the basis of certain guarantees (e.g. standard contractual clauses in the respective data processing agreement with the relevant third party) or under the EU-U.S. Privacy Shield Framework.
H. Your Rights Under the GDPR
Data Subject Rights. As the data subject, you have the right of access (Art. 15 GDPR), the right to rectification (Art. 16 GDPR), the right to erasure of your personal data (Art. 17 GDPR), the right to restriction of processing of your personal data (Art. 18 GDPR) and the right to data portability (Art. 20 GDPR). Please note, that the restrictions of Sections 34 and 35 BDSG Taxkiwi.com to your right of access and erasure.
Right of Revocation. If you have given your consent to the processing of your data, you can revoke your given consent at any time pursuant to Art. 7 (3) GDPR and we will no longer continue any such processing that is based on your consent moving forward. Note that such revocation will not affect the legality of any processing carried out based on your consent up to the point of revocation.
Right to Object. You can object to the processing of your personal data insofar as we base such processing on the balance of legitimate interests under Art. 6 (1) lit. f GDPR. This is the case if the processing is not necessary for the fulfillment of a contractual obligation or for compliance with our legal obligations. In case you wish to object, we kindly ask you to provide an explanation of the reasons for the objection against the processing of your personal data, so that we may examine and assess the situation, and either discontinue or adapt the data processing, or point out to you our compelling legitimate reasons based on which we continue the processing of your data. You may, of course, object to data processing for the purposes of advertising or direct marketing at any time. In this case, please send a message to help@Taxkiwi.com.