Logicc GmbH ("Logicc," "we," or "us") processes your personal data in various situations. The legal basis for this is derived in particular from the General Data Protection Regulation (GDPR), the Telecommunications Digital Services Data Protection Act (TDDDG), and the Federal Data Protection Act (BDSG).
This privacy policy informs you in accordance with Art. 12 to 14 GDPR about how we process your personal data insofar as we act as the controller in accordance with Art. 4 (7) GDPR. In particular, it explains what data we collect, for what purposes we use it, and on what legal basis the processing takes place—in particular for the following data processing processes:
- Visiting our website www.logicc.com (see sections 2.1 and 2.2),
- Contacting us via the website contact form, help center, and support chat (see section 2.3),
- Marketing and advertising, including postal advertising (see section 2.4),
- Company presence on social networks (see section 2.5),
- Ordering, concluding contracts, and providing our services, as well as handling business relationships (see section 2.6),
- Use of our platform and AI applications (see section 2.7),
- Handling requests concerning data subject rights, particularly access requests (see section 2.8).
This privacy policy also contains information about the categories of recipients of personal data (see section 3), data transfers to third countries (see section 4), the duration of data processing (see section 5), your rights as a data subject (see sections 6 and 7), the obligation to provide personal data (see section 8), and automated decision-making (see section 9).
1. Controller
According to the GDPR, the controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data (Art. 4 No. 7 GDPR). The controller for the data processing operations covered by this privacy policy is:
Logicc GmbH
Kattrepelsbrücke 1
20095 Hamburg
Email: info@logicc.com
If you have any questions about our privacy policy, you can contact our external data protection officer at any time. The contact details are provided below:
KaMUX GmbH & Co. KG
Herzogstraße 26
D-66953 Pirmasens
Email: info@kamux.eu
2. Purposes and legal basis for data processing
2.1 Visiting our website
When you visit our website, various personal data is processed depending on the type and scope of use. Personal data is information that relates to an identified or identifiable natural person; a natural person is considered identifiable if they can be identified directly or indirectly (e.g., by assigning an online identifier).
For the purpose of the technical provision of the website, it is necessary for us to process certain information automatically transmitted by your browser so that our website can be displayed in your browser and you can use the website. This information (the "access data") is automatically collected each time you visit our website and automatically stored in so-called server log files. Access data may include, among other things:
- Browser type and browser version
- Device ID and operating system used
- IP address of the requesting device
- Website from which access is made (origin or referrer URL)
- Date, time, and duration of access
The processing of access data is technically necessary to provide a functional website and for system security. Beyond the purposes mentioned above, we use server log files exclusively for the needs-based design and optimization of our website, purely for statistical purposes and without any conclusions being drawn about your person. This data is not merged with other data sources, nor is it evaluated for marketing purposes, unless you otherwise consent to its use (see also section 2.2).
If you visit our website to find out about our range of products and services or to use them on a contractual basis, the basis for the temporary storage of access data is Art. 6 (1) (b) GDPR, which permits the processing of data for the performance of a contract or for the implementation of pre-contractual measures.
In addition, Art. 6 (1) (f) GDPR serves as the legal basis for the temporary processing of access data in this case. Our legitimate interests here are to provide you with a technically functional and user-friendly website and to ensure the security of our systems. You have the right to object to processing for the protection of legitimate interests (see section 7).
The storage period and deletion of your access data are governed by section 5 of this privacy policy. Your IP address is stored for a maximum of 7 days for IT security purposes.
Website hosting
Our website is hosted by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. Vercel processes the access data described above on our behalf as a processor pursuant to Art. 28 GDPR. Access from the USA cannot be technically ruled out. Vercel is certified under the EU-U.S. Data Privacy Framework; the European Commission has determined an adequate level of data protection for certified companies (Art. 45 GDPR). Standard contractual clauses also apply. Further information: vercel.com/legal/privacy-notice.
We manage the content and images of the website in a content management system (Sanity). They are transferred to the website on publication and delivered by Vercel; no data is transmitted to Sanity when you visit the website.
2.2 Use of cookies and similar tracking technologies
We use cookies and similar tracking technologies, such as tracking pixels or fingerprinting technologies (collectively referred to as "tracking"), on our website. Depending on the purpose, tracking serves to make our offers more user-friendly, effective, and secure, as well as to personalize content and advertising. Tracking enables us to analyze how and, if applicable, which visitors use our websites. This allows us to tailor the website content to individual needs, for example by measuring the effectiveness of a particular ad and placing it in line with individual thematic interests.
a) Functional tracking:
The legal basis for accessing your device, collecting information, and further processing any personal data in these cases is Section 25 (2) No. 2 TDDDG and Art. 6 (1) (f) or (b) GDPR. The absolutely necessary tracking helps us to make a website technically usable and secure by enabling basic functions such as page navigation, login data, watch lists, or access to protected areas of the website. This also includes storing your selection in consent management, in particular whether and to what extent you want consent-based tracking. Without this type of tracking, the website cannot function properly. It is therefore necessary in order to implement the functions you have selected or to protect our legitimate interests in the functionality, security, and efficiency of our website.
b) Tracking for marketing, personalization, or analytics purposes:
Your voluntary consent is required for all other purposes mentioned; the legal basis for this is Section 25 (1) TDDDG and Art. 6 (1) (a) GDPR. You can give your consent for all purposes collectively by selecting "Accept all." In consent management, you can also individually specify the purposes for which tracking may be carried out by selecting the individual category via "Save selection". You can consent to tracking in order to display interest-based advertising and evaluate your user behavior for this purpose (marketing), to automatically take your browser preferences into account on future visits (personalization), and/or to understand your interests in order to optimize our website and services with specific content (analytics).
Once you have given your consent, you can revoke it at any time with future effect. To do so, click on "Cookie settings" at the bottom of the website and either select "Necessary only" or deactivate individual categories. You can also reject tracking from the outset by making the same selection, so that only functional tracking takes place.
Detailed information on the individual providers of tracking technologies, including storage duration and deletion, can be found below.
c) List of individual tracking technologies
| Service / provider | Purpose | Browser storage |
|---|---|---|
| Consent management – Logicc | Storage of the cookie selection | Local Storage* |
| Access protection – Cloudflare | Protection against automated access and excessive traffic | _cfuvid: session; __cf_bm: 30 minutes of inactivity |
| Sign-in – Clerk | Sign-in, session management and provision of sign-in configuration | Cookies: session and observed lifetimes of approximately 365 or 400 days; sign-in configuration in Local Storage* |
| App functions – Logicc | Language preference, restoring the scroll position and storing chat drafts | Language: 365 days; scroll position: Session Storage; drafts: Local Storage* |
| Advertising attribution – Logicc | Attributing first and last visits to sources and advertising campaigns | Cookies: 180 days; campaign parameters in Session Storage |
| Advertising measurement – Google Ads / DoubleClick | Measuring advertising performance, delivering advertisements and testing cookie support | Cookies: 15 minutes, 90 days or 13 months in the EEA; local attribution data: 5 minutes to 90 days per component entry |
| Usage analytics – Google Analytics | Recognising browsers and analysing website use | Cookies: up to 2 years; maximum 400 days in Chrome |
| Advertising measurement – Meta | Attributing visits to advertisements and recording visit sources | Cookie: 90 days; source information in Local Storage* |
| Advertising measurement, browser recognition, consent management and technical provision of the embedded service | Cookies: routing 1 day, consent status 180 days, browser identifier 365 days | |
| Advertising attribution – Outbrain | Attributing visits to advertising contacts | Cookie: up to 7 days |
| Appointment booking – Cal.eu | Secure provision of appointment booking and synchronisation of session status | Cookies: session; Local Storage* |
| Forms – Typeform | Provision and analysis of embedded forms and storage of cookie choices | Cookies: server distribution 7 days, cookie choices 183 days, visitor attribution 365 days; visitor identifiers in Local Storage* |
| Video playback – Google / YouTube | Video playback, privacy settings, functional testing and usage analytics | Cookies: session or 180 days; local player settings and caches* |
| Video player – Logicc / Plyr | Playback settings and caching of controls | Local Storage* |
(*) Local Storage has no automatic expiry set by the browser. The respective application may delete entries earlier.
2.3 Contact via website contact form, help center, and support chat
Our website provides electronic contact options to enable you to contact us quickly and easily by electronic means. If you send us inquiries through these channels, your inquiries, including the contact details you provide there, will be stored and processed by us for the purpose of processing and responding to your inquiry and in the event of follow-up questions. This also applies to your IP address and the date and time you sent your message to us. We do not pass this data on to third parties unless this is necessary in the context of processing and responding to your contact request or you have given us your consent (Art. 6 (1) (a) GDPR).
Enquiries submitted via the contact form on our website are sent to us by email. To send this email, we use the Brevo service of Sendinblue SAS, 17 rue de Salneuve, 75017 Paris, France, as a processor pursuant to Art. 28 GDPR. Processing takes place within the EU. The form data is not stored on the website itself.
The same applies if you use our help center, contact us via a support chat, or submit requests there. To support processing, requests submitted through these channels may also be pre-sorted or answered using AI-supported functions; where necessary, Logicc employees will then further review or process the request.
If you contact us within the framework of an existing contractual relationship, submit support requests, or contact us in advance for information about our product and service offerings, the data and information you provide will be processed for the purpose of processing and responding to your contact request on the basis of Art. 6 (1) (b) GDPR.
Otherwise, we will process the data to protect our legitimate interests pursuant to Art. 6 (1) (f) GDPR in providing electronic contact and support channels as a B2B company and for appropriate responses to customer/contact requests.
You are not obliged to contact us via the contact form, help center, or support chat, or to provide personal data. If you do not provide your personal data, we may not be able to process your request. Otherwise, there will be no consequences for you.
The storage period and deletion of your corresponding data are governed by Section 5 of this privacy policy.
2.4 Marketing and advertising
a) Newsletter subscription
If you have given your consent, we use your email address to send you our newsletter regularly. Only your email address is required to receive the newsletter; further information is voluntary. We use the double opt-in procedure: after registering, you receive an email asking you to confirm receipt of the newsletter. Without this confirmation, your registration is not completed. If you wish to receive our newsletter at a later date, you must register again and confirm your registration.
To document your registration and investigate possible misuse, we record your registration data, the consent declaration used at the time of registration, your IP address, the times of registration and confirmation, and the respective registration status. The legal basis in this case is Art. 6 (1) (a) GDPR.
b) Electronic advertising to existing customers (direct marketing)
If you purchase a product or service through our website and provide your email address, we may use that address to send you direct marketing, even without separate consent, unless you have objected. When you make the purchase, we clearly inform you of your right to object free of charge ("We occasionally send you tips, news and relevant offers by email. You can unsubscribe at any time free of charge with one click."; see section 2.4c) for further details).
For this purpose, we use your status as an existing customer, your name, your email address and, where applicable, information about your company or professional role and the products and services you have purchased. Direct marketing to existing customers contains only information and offers relating to our own products or services that are similar to those you have already purchased or sufficiently closely related to them. In this context, we may also send you information, news and tips about the products and services you have purchased or similar products and services.
The legal basis for sending direct marketing in this case is section 7 (3) of the German Act against Unfair Competition (UWG) in conjunction with Art. 6 (1) (f) GDPR. We have a legitimate interest in informing you, as an existing customer, about similar and comparable products and services by electronic direct marketing.
c) Unsubscribing from newsletters and electronic advertising to existing customers: withdrawal of consent or objection to direct marketing
You can unsubscribe from the newsletter or electronic advertising to existing customers at any time free of charge, regardless of whether you receive this direct marketing on the basis of consent or legitimate interests. Use the unsubscribe link at the end of such an email or send your request to the contact details in section 1. You do not have to give reasons. No costs arise other than transmission costs at your communications provider's basic rates. Further information about objecting to direct marketing is provided in section 7.2.
d) Postal advertising
We process your name, business address and, where applicable, information about your company or professional role to send you postal advertising about our products and services. We obtain the data either directly from you or from publicly accessible sources, directories and registers, particularly company and industry directories (for example, those of bar associations or other professional bodies, if you belong to the relevant profession), and other publicly accessible websites (for example, company websites).
The legal basis for processing is Art. 6 (1) (f) GDPR. Our legitimate interest is to inform potentially interested business customers about our products and services in a manner consistent with fair competition.
You can object at any time, with effect for the future, to the processing of your personal data for postal direct marketing. Further information is provided in section 7.2.
e) Telephone advertising
If we contact you by telephone for direct marketing, we address you exclusively in your professional capacity, particularly as a business owner, managing director, decision-maker or other company contact.
We make telephone contact only where specific circumstances indicate that the company concerned has an objective interest in our products or services and presumed consent to telephone contact can therefore be assumed. Relevant indications may include the company's industry and business activities, its publicly apparent demand for comparable products or services, existing business connections, previous contact or inquiries, or other specific circumstances establishing a sufficiently close connection between the company's activities and our offering. We do not make advertising calls merely because a telephone number is publicly available. Before making contact, we assess whether the apparent circumstances establish a specific business connection to our services.
Personal data relating to such telephone contact is processed on the basis of section 7 (2), no. 1, second alternative, UWG in conjunction with Art. 6 (1) (f) GDPR. Our legitimate interest is to address potential business customers specifically where our products or services may be of interest because of their business activities.
We do not contact consumers by telephone for direct marketing. Our products and services are intended exclusively for businesses and other commercial or professional customers.
You can object at any time, with effect for the future, to the processing of your personal data for telephone direct marketing. Further information is provided in section 7.2.
f) Other advertising and marketing methods
We may also process personal data for other advertising and marketing activities not already described above. These may include identifying potentially interested business customers, assessing possible business interest and approaching them for advertising purposes through suitable communication channels and digital platforms. In particular, we may process your name, business contact details and information about your company, professional role and any relevant connection to our products and services.
Where processing is based on a balancing of interests, it takes place on the basis of Art. 6 (1) (f) GDPR. Our legitimate interest is to identify potentially interested business customers, establish business contacts and draw attention to our products and services. Where a particular processing activity requires consent, processing takes place on the basis of Art. 6 (1) (a) GDPR.
You can object at any time, with effect for the future, to the processing of your personal data for direct marketing; further information is provided in section 7.2. Where processing is based on your consent, you can withdraw it at any time with effect for the future; further information is provided in section 6.6.
g) Compliance with marketing objections and withdrawals of consent (suppression records)
If you object to the processing of your personal data for direct marketing or withdraw consent given for that purpose, we continue to process the information necessary to comply with and document your objection or withdrawal. Where necessary, we enter a corresponding suppression record in our systems or a marketing suppression list. Depending on the previous contact channel, this may include your name, email address, postal address, telephone number or other contact identifier, and the date and scope of your objection or withdrawal.
We do not use this information to continue sending you advertising. It serves to implement your objection or withdrawal reliably, prevent your unwanted inclusion in our marketing activities again and, where necessary, demonstrate that consent was given or withdrawn or that consent or an objection was respected.
Where storage serves to comply with a marketing objection, processing is based in particular on Art. 6 (1) (f) GDPR in conjunction with Art. 21 (3) and Art. 17 (3) (b) GDPR. Our legitimate interest is to respect marketing objections consistently and reliably and prevent unwanted advertising contact. Where data is retained to meet statutory evidence and accountability obligations or establish, exercise or defend legal claims, processing is based on the respective applicable legal grounds (see section 2.9).
We retain this information only for as long as and to the extent necessary for these purposes. In particular, a suppression record may remain necessary for as long as there would otherwise be a risk of your contact details being reintroduced into the data used for our marketing activities. Otherwise, section 5 applies.
2.5 Company presence on social networks
We are present on various social networks, such as LinkedIn. We link directly to these networks on our website and operate a company page there. We use social networks to explain and promote our products and services and to improve your experience. You can also contact us directly via the respective network and find out about our offers.
a) Purposes and legal basis of processing by us in connection with the company's presence on social networks
We process the data from the use of our company's presence on social networks for the following purposes:
- Communication: If you interact with us via social networks (e.g., through comments, messages, or by following our page), we process your personal data in order to respond to your inquiries and provide information.
- Statistical evaluations (e.g., so-called page insights): We use the statistics provided by the social network to improve our content and to address our target groups within and outside the network in a more targeted manner.
The processing of your personal data is based on our legitimate interests pursuant to Art. 6 (1) (f) GDPR, namely to communicate with interested parties and customers, to analyze and optimize our online presence and our services, and in connection with inquiries about our products and services pursuant to Art. 6 (1) (b) GDPR.
We use the following social networks:
b) LinkedIn:
When you visit our company page on LinkedIn, personal data is processed by both LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, and by us. We are joint controllers in accordance with Art. 4 No. 7, 26 GDPR, including in the context of tracking (so-called "Page Insights").
When you visit our company page, LinkedIn collects, among other things, your IP address, information from your LinkedIn profile (e.g., job title, company), and other information about your activities on LinkedIn (e.g., likes). Based on this data, LinkedIn provides us with statistical information about the interaction with our company page and our LinkedIn posts.
For more information on how LinkedIn processes your personal data, including the legal basis on which LinkedIn relies, the purposes, and the options for exercising your rights as a data subject vis-à-vis LinkedIn, please refer to their privacy policy at: https://de.linkedin.com/legal/privacy-policy.
In order to determine the respective responsibilities for fulfilling the obligations under the GDPR with regard to joint processing, we have entered into an agreement with LinkedIn which you can access here https://www.linkedin.com/legal/l/page-joint-controller-addendum
You can assert your rights (see also sections 6 and 7) both against us and against LinkedIn. We will then forward requests pursuant to Art. 15 to 20 GDPR internally to LinkedIn, because LinkedIn is responsible for processing them in accordance with the above agreement. Alternatively, you can contact LinkedIn directly at the following link: https://www.linkedin.com/help/linkedin/ask/PPQ?lang=de
We have also agreed with LinkedIn that the Irish Data Protection Commission is the lead supervisory authority for joint processing. You always have the right to lodge a complaint with the Irish Data Protection Commission (see www.dataprotection.ie) or with any other supervisory authority.
2.6 Ordering, concluding contracts, providing our services, and handling business relationships
Within the scope of our existing or future business relationships, we process personal data that is either collected directly from you or provided to us by your employer as our B2B customer. This applies in particular to employees of business partners or persons involved in the performance of the contract. Our business relationships include suppliers, service providers, consultants, cooperation partners, and other companies with whom we work. In particular, this mainly concerns customers who purchase our products and services.
The provision of certain personal data may be required by law or contract, or may be necessary for the conclusion of a contract. If there is an obligation to provide such data, we will inform you separately. In this case, failure to provide such data may result in the requested service not being provided.
We primarily process personal data that you provide to us yourself within the scope of our business relationship or that we receive from business partners (e.g., from colleagues with whom we are already in contact, for example in connection with an inquiry or an order). In addition, we process information from publicly available sources (e.g., commercial registers, press, Internet) or data provided to us by third parties (e.g., other business partners). The scope of the data processed depends on your function within the respective company.
In the context of contract processing and business relationships, we process the following personal data in particular:
- Company name
- First and last name and position in the company
- Address (delivery and billing address)
- Sales tax ID
- Phone numbers
- Bank details or payment methods
The processing of personal data serves the preparation, execution, and processing of contracts, in particular purchase and delivery contracts, service and work contracts, and other contractual relationships (e.g., processing and reviewing relevant offers and inquiries; authenticating contractual partners; preparing and signing contract documents; processing services; sending information letters, etc.). In addition, we use the data to optimize our business processes and for the general support of our business partners.
Your personal data is processed to safeguard legitimate interests on the basis of Art. 6 (1) (f) GDPR. This includes, in particular: processing non-contractual inquiries and requests, ensuring legally compliant conduct (e.g., prevention of and protection against legal violations, assertion of and defense against legal claims, internal and external compliance measures), ensuring the availability, operation, and security of technical systems, and technical data management.
In addition, data processing may be based on Art. 6 (1) (b) GDPR if we have a direct business relationship with you or your employer and the processing is necessary for the performance and fulfillment of your obligations arising from the employment relationship.
The storage period and deletion of your contractual data are governed by section 5 of this Privacy Policy.
2.7 Use of our platform and AI applications
If you use third-party AI applications via our platform as an authorized user because our customer—your employer or another company—has provided you with access, this customer is the controller within the meaning of Art. 4 no. 7 GDPR for the processing of your personal data in the context of use. In this context, we act exclusively on the instructions of the customer and have therefore concluded a data processing agreement with them (Art. 28 (3) GDPR).
For information on the processing of your personal data when using the platform and third-party AI applications, as well as on exercising your rights as a data subject (see sections 6 and 7), please contact the customer who granted you access directly. Alternatively, you can also assert these rights against us—we will then forward your request to the responsible customer for processing in accordance with our contractual obligations.
You can also obtain further information on the processing of your personal data in the context of the respective AI application directly from the relevant third-party provider:
| AI models | Cloud providers | Legal basis and data protection information |
|---|---|---|
| OpenAI models Mistral models Meta LLAMA models | Microsoft Azure | Logicc has entered into a customer agreement with Microsoft for Azure Services. Use is based on this agreement and the product terms for Azure. These include comprehensive data protection and information security obligations. In addition, a data processing agreement has been concluded, which obliges Microsoft to take the following measures: – No disclosure or access to the data – No transfer of prompts, outputs, embeddings, and training data to other users – No transfer to OpenAI or other model developers – No use for training the models – No use for improving Microsoft services. Microsoft makes the following binding assurance in its privacy and security provisions: “If the customer configures a particular service to be delivered from a data center within a major region (each referred to as a ‘geo’), Microsoft will store the customer's data at rest within that particular geo.” |
| Anthropic models Amazon models OpenSource models | Amazon Bedrock | Logicc has entered into an AWS customer agreement with AWS. The use of AWS Bedrock services is based on the AWS Service Terms. In accordance with the Service Terms, the DPA, and the User Guide, the following binding assurance applies: “Amazon Bedrock does not store or log your prompts and completions. Amazon Bedrock does not use your prompts and completions to train any AWS models and does not distribute them to third parties.” The data processing agreement concluded with AWS obliges the provider to: – Treat the data confidentially – Not disclose it to third parties – Process the data exclusively in the European Union – Not use the data for training models – Not use it to improve other AWS services. |
| Anthropic models Google models | Google Cloud Platform | Logicc has entered into a customer agreement with Google. The use of Google Cloud Platform services is based on the Service Specific Terms. Google has made the following assurance in a guide to generative AI products and in a statement on data protection obligations for cloud-based AI products: “Customers can use Google Cloud's foundation models with confidence that their prompts, responses, and all training data for adapter models will not be used to train foundation models.” The data processing agreement concluded with Google Cloud stipulates the following binding provisions: – No use of customer data for training without prior approval – No improvement of AI/ML models with customer data – Storage of data exclusively in the selected region or multi-region. |
| OpenAI models | OpenAI | Logicc has entered into a Data Processing Addendum, and a Modified Data Retention Amendment with OpenAI. The OpenAI services are used exclusively with EU-only processing and activated Zero Data Retention. Under the DPA, OpenAI processes customer data only to provide the services and as a processor acting on Logicc's instructions. With Zero Data Retention activated, Customer Content, in particular prompts and outputs, is not logged and is not used to train or improve OpenAI models. The data processing agreement concluded with OpenAI obliges the provider to: – Process data only to provide the services – Process data exclusively in the European Union – Not use the data for model training – Not use the data to improve other OpenAI services – Apply Zero Data Retention to customer data |
| Mistral models | Mistral AI | Logicc uses Mistral models exclusively with EU-only processing and activated Zero Data Retention. Mistral processes customer data only to provide the relevant services and on Logicc's instructions. With Zero Data Retention activated, prompts, outputs, and other customer data are not permanently stored, are not logged for abuse monitoring, and are not used to train or improve Mistral models. The use is subject to the following data protection requirements: – Processing exclusively in the European Union – No use of the data for model training – No use to improve other Mistral services – Zero Data Retention for customer data |
2.8 Handling requests concerning data subject rights, particularly access requests
If you exercise any of your rights under the GDPR (see sections 6 and 7), particularly if you submit an access request under Art. 15 GDPR, we process the personal data you provide in connection with your request and, where necessary, further information to verify your identity and handle your request.
Processing serves to assess and handle your request, particularly to provide the information you requested, fulfil other data subject rights you exercise and document proper handling. The legal basis is Art. 6 (1) (c) GDPR in conjunction with Art. 12 and Art. 15 et seq. GDPR and, for documenting compliance with our data protection obligations, Art. 5 (2) GDPR. Where further information is required to verify your identity, this takes place particularly in accordance with Art. 12 (6) GDPR.
Once your request has been fully handled, we generally retain the documents necessary to demonstrate proper handling for the ordinary limitation period. Otherwise, retention and deletion are governed by section 5.
2.9 Compliance with legal requirements
In connection with all of the above processes, we also process your personal data to comply with legal obligations that may apply to our business activities. These include, in particular, information obligations under commercial, trade or tax law, as well as retention, documentation, disclosure and other statutory obligations.
We process your personal data in accordance with Art. 6 (1) (c) GDPR to fulfil the respective legal obligation to which we are subject.
2.10 Law enforcement
In connection with all of the above processes, we also process your personal data in order to assert our rights and enforce our legal claims or defend ourselves against legal claims. Finally, we process your personal data to the extent necessary to prevent or prosecute criminal offenses.
In this context, we process your personal data to protect our legitimate interests in accordance with Art. 6 (1) (f) GDPR, insofar as we assert legal claims or defend ourselves in legal disputes, or we need to prevent or investigate violations of our property or similar legal positions.
3. Categories of recipients
3.1 In order to provide our services and organize business processes efficiently, we work with external service providers who may have varying degrees of access to personal data. There are two categories:
- Processors pursuant to Art. 28 GDPR, who act exclusively on our behalf and in accordance with our instructions.
- Companies acting on their own responsibility, which decide for themselves on the processing and use of the data.
3.2 Some service providers are contractually bound to our instructions and process personal data exclusively for the agreed purposes on our behalf. For this purpose, we have concluded a data processing agreement with these recipients (Art. 28 (3) GDPR). In particular, the following categories of recipients are included:
- Hosting, cloud, and IT security services: Provision of technical infrastructure and protection of IT systems.
- Web and platform hosting: Provision and operation of our website and platform services.
- Authentication services: Verification and management of user logins.
- Payment processing: Processing payments via various payment methods, including credit cards and SEPA direct debit, insofar as the respective provider acts as a pure payment service provider.
- Customer management and communication: Management of customer relationships, sending of emails and newsletters, and operation of the website live chat.
- Automation and integration services: linking applications and automating workflows.
3.3 In certain cases, we work with companies that decide for themselves how to process personal data. In some cases, the recipients act independently under their own data protection responsibility and are also obliged to comply with the requirements of the GDPR and other data protection regulations. This includes the following categories of recipients in particular:
- Payment service providers: Independent processing of transactions and fulfillment of regulatory requirements.
- Web analysis and tracking services: Collection and evaluation of user data to optimize online offerings; see also section 2.2c).
- CRM and customer management systems: Management and analysis of customer interactions.
- Social networks: Processing of personal data for advertising analysis and campaign optimization.
- Shipping and logistics service providers: Processing of deliveries and shipping of goods.
- Authorities and public bodies, insofar as there is a legal obligation to transfer data or the transfer is necessary for law enforcement.
3.4 Finally, in individual cases, we transfer personal data to our advisors in legal or tax matters, whereby these recipients are generally already are already bound to special confidentiality and secrecy due to their professional status.
4. Data transfer to third countries
4.1 If necessary for our purposes, we may also transfer your data to recipients outside the European Economic Area ("third countries"). This is particularly the case in the context of contract processing or due to legal requirements.
4.2 We only transfer your data to recipients in third countries in accordance with the provisions of Chapter V of the GDPR, i.e. if it is ensured that the EU Commission has determined an adequate level of data protection within the meaning of Art. 45 (1) GDPR or that appropriate safeguards within the meaning of Art. 46 (2) and (3) GDPR have been implemented, or if there is an exception under Art. 49 GDPR and there are no overriding interests worthy of protection that speak against the transfer of personal data.
4.3 To ensure an adequate level of protection at the recipient of the data, we use, in particular, the EU Commission's standard contractual clauses for the transfer of personal data to third countries (SCC). You can access the SCC via the link provided or request a copy from us.
5. Duration of data processing and deletion
5.1 We initially process your personal data for the duration required for the respective processing purpose – see above.
5.2 Insofar as the processing is carried out for the purpose of executing a contract, the processing period also includes the periods of initiating a contract (pre-contractual legal relationship) and executing a contract (including any subsequent claims).
5.3 If the processing is carried out to safeguard our legitimate interests, the processing period covers the period until the pursued processing purposes have been achieved.
5.4 If the processing is based on your consent, it will take place for the period between the granting and revocation of consent or until the processing covered by the consent has been completed.
5.5 In this respect, we would like to point out that even in the event of revocation, further processing may be possible on the basis of other legal grounds (Art. 17 (1) (b) GDPR).
5.6 Even when the primary processing purposes have been achieved, further processing of your personal data may take place, in particular if this is necessary to fulfill legal obligations and/or to protect our rights. This includes, in particular, the following purposes:
- Compliance with statutory retention obligations, e.g., those arising from the German Commercial Code (Sections 238, 257 (4) HGB) and the German Fiscal Code (Section 147 (3), (4) AO). The retention and documentation periods specified therein are up to ten years.
- Preservation of evidence in accordance with the statute of limitations. According to Sections 194 et seq. of the German Civil Code (BGB), these limitation periods can be up to 30 years, with the regular limitation period being three years.
6. Rights of data subjects
You can exercise the following rights at any time using the contact details provided in section 1 (see section 2.8 for the processing of your information in connection with such a request):
6.1 Right to information: You have the right to request confirmation from us as to whether personal data concerning you is being processed; if this is the case, you have the right to information about this personal data concerning you and about information in accordance with Art. 15 (1) (a) – (h) GDPR. If personal data concerning you is transferred to a third country or to an international organization, you have the right to be informed of the appropriate safeguards pursuant to Art. 46 GDPR in connection with the transfer. Under the conditions set out in Art. 15 GDPR, you also have the right to obtain a copy of the personal data concerning you that is being processed.
6.2 Right to rectification: You have the right to request that we rectify personal data concerning you without undue delay if it is inaccurate. Taking into account the purposes of the processing, you have the right to request the completion of incomplete personal data concerning you, including by means of a supplementary statement.
6.3 Right to erasure: You have the right to request that we erase personal data concerning you without undue delay if one of the reasons specified in Art. 17 GDPR applies, e.g. if the data is being processed unlawfully.
6.4 Right to restriction of processing: Under the conditions specified in Art. 18 GDPR, you have the right to request that we restrict processing.
6.5 Right to data portability: Under the conditions specified in Art. 20 GDPR, you have the right to receive the personal data concerning you that you have provided to us on the basis of consent or for the performance of a contract in a structured, commonly used, and machine-readable format and to transmit this data to another controller without hindrance from us. When exercising this right, you have the right to have the personal data concerning you transferred directly from us to another controller, where technically feasible.
6.6 Right to withdraw consent: If data processing is based on consent pursuant to Art. 6 (1) (a), Art. 9 (2) (a) or Art. 49 (1) (a) GDPR, you may withdraw your consent at any time with effect for the future. The lawfulness of the processing of your personal data until revocation remains unaffected. When revoking your consent, you can also choose the same contact method you used when giving your consent.
6.7 Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
7. Right to object
7.1 Under the conditions specified in Art. 21 (1) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6 (1) (e) or (f) GDPR; this also applies to profiling based on this provision.
7.2 If personal data concerning you is processed for direct marketing purposes, you also have the right, pursuant to Art. 21 (2) GDPR, to object at any time to the processing of data concerning you for such marketing purposes; this also applies to profiling insofar as it is related to such direct marketing. After you object, the personal data concerned will no longer be processed for direct marketing purposes. Where necessary, we store the information required to comply with your objection in our suppression list under section 2.4g).
8. Obligation to provide data
8.1 In principle, you are not obliged to provide us with your personal data. However, if you do not do so, we will not be able to make our website available to you without restrictions or respond to your inquiries.
8.2 Personal data that we do not necessarily require for the above-mentioned processing purposes is marked accordingly as voluntary information.
9. Automated decision-making
We do not use automated decision-making within the meaning of Art. 22 (1), (4) GDPR.
This privacy policy is current as of September 28, 2026. Due to the further development of our website, products, and services, or due to changes in legal or regulatory requirements, it may become necessary to amend this privacy policy. In this case, we will update this privacy policy accordingly on our website.
