Privacy policy
Last updated: 15 September 2026
Last updated: 24 July 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection provisions is:
Provimedia GmbH
Weidenweg 12
74321 Bietigheim-Bissingen
represented by the managing director Alexander Weipprecht
Email: info@provimedia.de
Phone: +49 (0)7142-9170511
2. Data Protection Officer
We have appointed a data protection officer for our company. For all questions regarding data protection and the exercise of your rights as a data subject, you can reach him directly at:
Patrick Rempfer
Email: rempfer@provimedia-team.de
3. Your Rights as a Data Subject
Subject to the statutory requirements, you have the following rights, which you may assert against us or our data protection officer at any time:
- the right to information about the data stored about you (Art. 15 GDPR),
- the right to rectification of inaccurate personal data (Art. 16 GDPR),
- the right to erasure of data stored by us (Art. 17 GDPR),
- the right to restriction of processing, insofar as we may not yet delete your data due to statutory obligations (Art. 18 GDPR),
- the right to object to the processing of your data by us (Art. 21 GDPR) and
- the right to data portability, provided you have consented to the data processing or concluded a contract with us (Art. 20 GDPR).
If you have given us consent, you may withdraw it at any time with effect for the future (Art. 7(3) GDPR), without affecting the lawfulness of the processing carried out until the withdrawal.
You also have the right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data. The competent supervisory authority is:
State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg)
Lautenschlagerstraße 20
70173 Stuttgart
www.baden-wuerttemberg.datenschutz.de
4. General Information on Data Processing
We process personal data of our users only insofar as this is necessary to provide a functioning website and our content and services. Processing takes place on the basis of your consent (Art. 6(1)(a) GDPR), for the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR), for compliance with a legal obligation (Art. 6(1)(c) GDPR), or on the basis of legitimate interests (Art. 6(1)(f) GDPR). The legal basis applicable in each individual case is stated in the relevant sections of this declaration. Your data will only be transferred to third parties for the purposes stated in this declaration.
5. SSL/TLS Encryption
For security reasons and to protect the transmission of personal data and other confidential content, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the prefix "https://" and the padlock symbol in your browser's address bar.
6. Server Log Files When You Visit Our Website
When you access our website, our hosting provider automatically collects information in what are known as server log files, which your browser automatically transmits to us. These are in particular:
- the IP address of the accessing device,
- the date and time of access,
- the name and URL of the file retrieved,
- the website from which access occurs (referrer URL),
- the browser used and, where applicable, the operating system and access provider of your device.
Processing takes place for the purpose of ensuring the technically error-free operation of our website as well as the security and stability of our systems. The legal basis is our legitimate interest pursuant to Art. 6(1)(f) GDPR. For security reasons (for example, to investigate cases of misuse), the log files are stored for 14 days and then automatically deleted; the logs of our application itself are likewise deleted after 14 days.
7. Cookies and Consent Management
Our website uses cookies and comparable technologies (including local storage) that may contain information about your use of the website. On your first visit to our website, you will be asked via a cookie consent banner for your consent to the use of cookies that are not technically necessary. We distinguish between the following categories:
- Necessary: technically required to provide the website and its core functions; no consent required (§ 25(2) no. 2 of the Telecommunications Digital Services Data Protection Act (TDDDG)).
- Analytics: web analytics with Matomo (see section 8.2), only with consent.
- Marketing (Google Ads): Google Ads conversion tracking (see section 8.3), only with consent.
- Marketing (TikTok): TikTok pixel (see section 8.8), only with consent. Deliberately maintained as a separate category so that you can decide on TikTok independently.
- Chat Assistant: the "Website AI Agent" chat module (see section 8.1), only with consent.
We only use cookies that are not technically necessary and comparable access to your device after you have given your express consent pursuant to § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. Your consent is voluntary and can be withdrawn or adjusted at any time with effect for the future via the "Cookie Settings" link. There is one exception that we set without prior consent: the cookie for the origin of your visit. What it contains, what it is for and how long it stays is set out in section 7.1.
If a new service is added, any consent given earlier is superseded: you could not have been aware of it at the time of your decision. In this case, the consent banner will appear again, and the new service will only be loaded after your new decision. Consent already given is therefore never silently extended to additional services.
We store your decision exclusively in your browser (local storage, no cookie and no transmission to us). It remains there until you change it via "Cookie Settings", delete the website data in your browser, or a new service is added.
7.1 Origin of Your Visit
In addition to the categories above, we set a cookie of our own named pm_attribution. It is created the first time you open a page of our website and is not renewed again for as long as it exists. It contains only:
- the page on which you entered our website,
- the address of the page you came to us from (referrer URL), where your browser transmits it,
- the campaign details from the address you called up (utm_source, utm_medium, utm_campaign, utm_term, utm_content) and the Google click identifier gclid, where present,
- the time of this first visit.
The cookie remains on your device for 90 days. It contains neither your name nor your address nor any visitor identifier assigned by us, and we do not transmit it to anyone. If you book a course in our Academy (AI certificate or GDPR training), we transfer the details into your participant data; we can then see which route led to the booking. This does not happen with our other offerings, and without a booking the cookie on your device is all there is.
The purpose is measuring the success of our own advertisements and referrals: we want to know which route leads to a purchase. The legal basis for the processing is our legitimate interest in this measurement pursuant to Art. 6(1)(f) GDPR. You may object to the processing pursuant to Art. 21 GDPR; the ways to do so are set out in section 3.
You can delete the cookie in your browser at any time. It is then created anew on your next visit, and the details stored until then are gone.
8. Services Used in Detail
8.1 AI Chatbot "Website AI Agent"
On our website, we offer the chat assistant "Website AI Agent", a service operated by Provimedia GmbH itself (website-ai-agent.com). The chat module is only loaded after you have consented to the "Chat Assistant" category via our cookie banner; without this consent, no connection to the chat server is established. After your consent, when the module loads, the accessed page URL, the page title, and your IP address are transmitted to the chat server so that the assistant can respond in context. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. You can withdraw your consent at any time with effect for the future via the "Cookie Settings" link.
If you subsequently use the chat actively, a first-party cookie (_wai_sid) and a local storage entry (wai_session) containing the chat history are created on your device to maintain the conversation; this is covered by your consent given above. Depending on the subject of your request, we base the substantive processing of your chat messages on Art. 6(1)(b) or (a) GDPR.
To generate the chat responses, the content you submit in the chat is processed by AI language model providers on our behalf. Insofar as data is transferred to a third country outside the EU or the European Economic Area (EEA) (in particular the United States), this is done on the basis of appropriate safeguards within the meaning of Art. 44 et seq. GDPR (EU standard contractual clauses or the EU-US Data Privacy Framework).
Pursuant to Art. 50 of the EU AI Act (Regulation (EU) 2024/1689), we inform you that you are communicating with an AI system in the chat.
8.2 Web Analytics with Matomo
After your consent (category "Analytics"), we use the self-hosted web analytics tool Matomo. Matomo uses cookies that enable analysis of your use of our website. The data collected in this way is processed exclusively on our own servers; no transfer to third parties takes place. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. You can withdraw your consent at any time via "Cookie Settings". Matomo automatically deletes the raw visit data after 12 months; only aggregated statistics without any personal reference remain thereafter.
8.3 Google Ads Conversion Tracking
After your consent (category "Marketing"), we use the conversion tracking of Google Ads, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. In this process, a cookie is set that enables us to determine whether a user has carried out an action relevant to us after clicking on a Google advertisement. This does not enable us to identify you personally. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. Insofar as data is transferred to the United States in this process, Google states that it bases this, among other things, on the EU-US Data Privacy Framework. You can withdraw your consent at any time via "Cookie Settings". The storage period of the cookies set by Google and of the data processed by Google is determined by Google; details can be found in Google's privacy policy. We ourselves do not store any data from this service.
8.4 Payment Processing with Stripe
For the purchase of our paid offerings (including the AI certificate and Company Audit), we use the payment service provider Stripe Payments Europe, Ltd., Ireland. In this process, the data required for payment processing (including name and payment data) is transmitted to Stripe. The legal basis is the performance of the contract concluded with you (Art. 6(1)(b) GDPR). A transfer to companies affiliated with Stripe outside the EU or the EEA may take place on the basis of appropriate safeguards (including EU standard contractual clauses). Further information can be found in Stripe's privacy policy.
For Code Guardian, payment can alternatively be made by SEPA direct debit. In this case, Stripe is not involved; how we handle your bank details in this process is described in section 14.
8.5 WhatsApp Contact
We offer you the option of contacting us via WhatsApp using a wa.me link. Data is only transmitted to WhatsApp or Meta Platforms Ireland Limited once you actively click the link and start a conversation via WhatsApp. The legal basis is your consent through active use (Art. 6(1)(a) GDPR) or our legitimate interest in offering a low-threshold means of contact (Art. 6(1)(f) GDPR). WhatsApp/Meta's privacy terms apply to further processing.
8.6 Fonts (Webfonts)
For the consistent and appealing display of content, we use fonts (webfonts). These are delivered exclusively locally from our own servers. No connection is made to third-party servers, in particular not to Google Fonts; accordingly, no personal data is transmitted to third parties.
8.7 Embedded YouTube Videos
On some pages, we embed videos from the YouTube platform, a service of Google Ireland Limited. The embedding takes place using the privacy-friendly two-click method: initially, only a preview image is displayed; a connection to YouTube via the privacy-friendly domain youtube-nocookie.com is only established once you actively click the preview image, thereby consenting to the loading of the video. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. After clicking, your IP address is transmitted to Google; if you are logged into your Google account at that time, Google can associate your usage behaviour with your account. Further information can be found in Google's privacy policy.
8.8 TikTok Pixel
Use and purpose. Only after your express consent (cookie category "Marketing (TikTok)") do we integrate the TikTok pixel, an analytics and advertising tool provided by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin 2, D02 T380, Ireland. The pixel measures the reach and success of our advertisements on TikTok, detects whether visitors carry out an action relevant to us after clicking on an advertisement, and enables TikTok to serve and optimise advertising. If you do not give this consent, the pixel will not be loaded; no data whatsoever is then transmitted to TikTok. Consent is voluntary; you can use our website without restriction without it.
Data processed. The data processed includes in particular: your IP address (shortened or pseudonymised by TikTok according to its own statements), information on browser, operating system, device, and screen resolution, the pages of our website you have accessed and the time of access, the referrer URL, and a pseudonymous identifier stored in the _ttp cookie. According to the provider, the storage period of this cookie is up to 13 months. If you are also logged into TikTok at the same time, TikTok can associate this information with your user account there. We ourselves receive only aggregated, non-personal evaluations from TikTok.
Legal basis. The legal basis for storing information on your device and accessing it is § 25(1) TDDDG, and for the subsequent processing of your personal data, your consent pursuant to Art. 6(1)(a) GDPR. We do not use any other legal basis for this tool; in particular, we do not rely on legitimate interest for it.
Joint controllership. For the collection of your data on our website and its transmission to TikTok, we and TikTok are joint controllers within the meaning of Art. 26 GDPR. TikTok provides the agreement required for this in Part B of its "Jurisdiction Specific Terms", which stipulates that TikTok assumes the information duties under Art. 13 and 14 GDPR for its own processing and handles data subject requests. TikTok is solely responsible for the further processing that takes place exclusively at TikTok. You can assert your rights under the GDPR against either of us, the internal allocation of tasks does not change this.
Transfer to third countries and the associated risks. We expressly point out that, in connection with the TikTok pixel, data is transferred to countries outside the EU and the EEA, namely to the United States, and that remote access to data from the EU by group companies in the People's Republic of China cannot be ruled out. TikTok states that it bases such transfers on standard contractual clauses pursuant to Art. 46(2)(c) GDPR as well as supplementary safeguards. There is no adequacy decision of the European Commission for the People's Republic of China. In April 2025, the Irish data protection authority (Data Protection Commission) imposed a fine of EUR 530 million on TikTok for unlawful transfers to China and prohibited the transfers; the Irish High Court suspended enforcement of this order on 13 November 2025 pending a final judicial clarification, so that the transfers continue in the meantime. It cannot therefore be ruled out that authorities in these countries access your data, that a level of protection equivalent to European law does not exist, and that effective legal remedies against this are not available to you. By consenting to the "Marketing (TikTok)" category, you also expressly consent, in full knowledge of these risks, to the transfer to these third countries (Art. 49(1)(a) GDPR).
Withdrawal. You can withdraw your consent at any time with effect for the future via the "Cookie Settings" link; the pixel will then no longer be loaded. The lawfulness of the processing carried out until the withdrawal remains unaffected. We cannot delete data already transmitted to TikTok ourselves; please contact TikTok for this purpose. Further information on processing by TikTok, on the standard contractual clauses, and on your rights can be found in TikTok's privacy policy at tiktok.com/legal/privacy-policy-eea.
8.9 Invoicing with Lexware Office
For the creation and sending of invoices and credit notes, we use Lexware Office (Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg im Breisgau) as a processor. This concerns the invoices for the AI certificate of the Provimedia Academy and for the Company Audit, as well as the credit notes to the partners of our partner programme.
The data transmitted includes your name or company name, your billing address, your email address, your VAT ID where applicable, and the invoice line items and amounts. The legal basis is the performance of the contract concluded with you (Art. 6(1)(b) GDPR) and the fulfilment of our tax and commercial law obligations (Art. 6(1)(c) GDPR in conjunction with § 147 of the German Fiscal Code (Abgabenordnung, AO) and § 257 of the German Commercial Code (Handelsgesetzbuch, HGB)).
If you choose SEPA direct debit for Code Guardian, section 14 applies to the additional data processed in that case.
9. Contact Form
If you send us inquiries via the contact form, we store the information you provide in the inquiry form, including the contact details you enter there, for the purpose of processing the inquiry and in case of follow-up questions. To protect against automated misuse (spam), we use a so-called honeypot field, which is not visible to human users and serves exclusively to detect automated form submissions. The legal basis for the processing is Art. 6(1)(b) GDPR where a contract is being initiated, and otherwise your consent (Art. 6(1)(a) GDPR) as well as our legitimate interest in responding to your inquiry (Art. 6(1)(f) GDPR). We do not pass on this data without your consent. The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected; this is generally the case once the respective conversation with you has concluded and the circumstances indicate that the matter concerned has been conclusively resolved. We automatically delete it no later than twelve months after the last message relating to your inquiry. If your inquiry leads to a contract, the statutory retention periods (section 13) apply to the resulting documents.
10. AI certificate / Academy: Participant Accounts
If you participate in our online courses (for example, the "AI certificate"), we set up a participant account for the performance of the contract. In doing so, we process in particular your name, your email address, and data on your course progress and any certificates issued. Login takes place via a magic link sent to you by email. The legal basis is the performance of the contract concluded with you (Art. 6(1)(b) GDPR). Your data is stored for the duration of the contractual relationship and beyond, insofar as statutory retention obligations (for example, commercial and tax law provisions) require this.
11. AI Community: Membership Accounts, Forum and AI Evaluation
For membership in our AI Community, we create a membership account. We process your name, your email address, a display name of your choice, and, where you provide them, profile picture, signature and billing address. The legal basis is the performance of the membership contract (Art. 6(1)(b) GDPR). Payment processing takes place via Stripe (see section 8.4).
In the forum, we process the posts, replies and direct messages you write, as well as any file attachments you upload and voice messages you record, on an optional basis. We count views of a topic exclusively in aggregated form; in doing so, we do not store your IP address in plain text but only a cryptographic hash value that serves solely to prevent duplicate counting and is deleted after 24 hours.
11.1 Use of AI to Evaluate Your Posts
Provider: OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland (registered in Ireland under number 737350). For customers in the EEA, OpenAI Ireland Limited is the contracting party and processes the data on our behalf.
Processing on behalf: We have a data processing agreement (DPA) with the provider pursuant to Art. 28 GDPR. Insofar as data is transferred in this context to a country outside the EEA, this takes place on the basis of the guarantees agreed in the DPA, in particular the standard contractual clauses (SCCs) of the European Commission (Art. 46(2)(c) GDPR).
No use for training: Under the provider's terms, the application programming interface (API) we use does not use transmitted content to train its models. For abuse control purposes, the provider stores requests for a limited period of up to 30 days and then deletes them, unless a statutory obligation requires longer retention.
Two functions, two legal bases. We use AI in the Community for two clearly separate purposes. They differ in whether you trigger them yourself, and therefore also in their legal basis.
(a) Transcription of voice messages. When you record and send a voice message, the recording is automatically converted into text so that your post becomes readable and searchable. This processing is an inseparable part of the function you have actively chosen; the legal basis is the performance of the membership contract (Art. 6(1)(b) GDPR). If you do not record a voice message, it does not take place.
(b) Summary of longer posts. For forum posts above a certain length, we automatically generate a short summary, a list of the questions raised in it, and keywords that improve the search function in the forum. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR). This interest lies in keeping a forum readable and searchable: in longer posts, individual questions get lost and remain unanswered, and without keywords, the search only finds a post if someone happens to use the same words as its author. We process only text that you have already published visibly to the other members; no profile is created, no assessment of you as a person, and no automated decision within the meaning of Art. 22 GDPR.
Your right to object under (b). You can object to this processing at any time, without giving reasons, without any disadvantage, and without affecting your membership: in your account under Member Area → Account & Subscription → AI Summary of Your Posts, one click. Alternatively, you can reach us using the contact details given in section 1. After you object, your posts will no longer be evaluated, and we will also delete the summaries already created for your posts; we would not be obliged to do so, but we do it anyway. You can continue to use the Community fully and without restriction; the only consequence is that no automatic summaries of your posts will be created.
Until 22 August 2026, the processing under (b) was based on your consent. If you gave consent at that time, you do not need to do anything further; if you did not give consent, you can object from now on. The lawfulness of the processing carried out up to this change remains unaffected.
Data transmitted: Only the content of the respective post or the audio recording is transmitted to the provider. Your name, your email address and your other account details are not transmitted in this process.
Third country transfer: Processing may take place in the United States.
Storage period: We store the generated summaries, question lists and keywords for as long as the associated post exists. If you delete a post, they are deleted together with it.
11.2 Deletion of Your Own Posts
You can delete your own posts at any time. This removes the post text, the associated file attachments, any voice recording together with its transcription, the AI evaluation, and the association with your account. An empty placeholder remains in the post's place so that other members' replies retain their context. We cannot retrieve notification emails already sent that contain an excerpt of your post; likewise, quotations in other members' replies may remain.
12. Partner Programme
We operate a Partner Programme. Partners recommend our products and receive a commission when this results in a purchase. So that we know who a recommendation is attributable to, we process data. What happens in this process is described here in full, including what takes place without your consent.
You encounter the programme in two ways: you click a partner link (it contains the addition ?ref= and a code), or you enter a partner's personal discount code when making a purchase. There is no third way; in particular, we do not record anything on a customer account.
Who is involved. We are the controller (section 1). The partner whose code you used is also a recipient. This person never sees your name, your email address, your address or your order number. In their overview, they only see figures: how many clicks their link received, how many purchases resulted from them, and what commission follows from this.
12.1 What Happens with Every Click on a Partner Link
When you click a partner link, we create a line on our server. It contains a random click identifier, the partner's code, the page you accessed, the internet address you came from (only the hostname, without the path), a numerical value each calculated from your IP address and your browser identifier, and the date and time.
Purpose: We attribute a later purchase to the correct partner and detect attempted fraud, such as machine-generated clicks or purchases made by a partner under their own link.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is to remunerate our partners correctly and to detect commission fraud. The balancing test we carried out for this is documented in writing and we will provide it to you on request; it names every item of data processed, the less intrusive alternatives we examined, and the points at which our assessment is uncertain.
Storage period: 120 days from the click. After that, we delete the line, unless the click has resulted in a purchase. In that case, it remains as evidence for the accounting, but after the same 120 days it loses any value that could be used to recognise a device. The exact difference is set out in section 12.5.
About the numerical values, to be honest: We do not store your IP address and your browser identifier in plain text; instead, we convert them into numerical values using a secret key that is kept separately. This is pseudonymisation, not anonymisation: the values remain personal data, and all your rights under section 3 apply to them.
12.2 Your Right to Object to Sections 12.1 and 12.3
You may object at any time to the processing under section 12.1 and section 12.3 for reasons arising from your particular situation. A message to the contact details given in section 1 is sufficient; we do not require a form or reasons.
We cannot identify you from this data, and we are required to tell you this. The lines under section 12.1 contain no name, no address and no identifier, only values calculated using a secret key. If we receive a message from you, we are therefore unable to find the line that belongs to you. Art. 11(2) in conjunction with Art. 12(2) GDPR requires precisely in this situation that we disclose this rather than promise you an effect that we cannot deliver. We prefer to state this here rather than leave you believing that a message had any effect.
For the future, your objection takes effect immediately, with one click: Object to the Partner Programme. After that, no more lines under section 12.1 and no more values under section 12.3 will be created in this browser. The same page also allows you to withdraw the objection.
Three points on this, honestly and without small print: the switch stores a marker in your browser; it is the only thing that the Partner Programme stores on your device at all, and what it stores there is precisely what ends the storing. It contains nothing but a yes, no identifier, and is valid for five years (§ 25(2) no. 2 TDDDG: it exclusively provides the service you expressly requested). It is tied to this browser; on another device or after deleting your browser data, you must set it again, which likewise follows from the fact that we do not know who you are. And lines already stored automatically expire after 120 days (section 12.5).
This paragraph is deliberately placed separately and ahead of everything else, because Art. 21(4) GDPR requires exactly that.
Nothing in the Partner Programme is based on consent; there is therefore nothing to withdraw here. The way out is this objection.
12.3 Recognition: Usable for Seven Days, Stored for 120 Days
Regardless of your decision in the consent banner, we calculate a further numerical value from information that your browser sends anyway with every page request. It allows us to recognise you when you return. In doing so, nothing is stored on or read from your device that is not already part of your request to our server. The legal basis is Art. 6(1)(f) GDPR, with the same legitimate interest as in section 12.1. You can object to this under section 12.2 above.
Two periods, and they are different. We state both because only the second is the storage period within the meaning of Art. 13(2)(a) GDPR. Used: the value applies for a maximum of seven days; a purchase on the eighth day is no longer attributed through it. Stored: it remains for as long as the click line under section 12.1 exists, that is 120 days; it is contained in the same line. After that, see section 12.5.
We do not gloss over this procedure: it is a recognition procedure. We do not call it "technically necessary", nor do we call it "no tracking".
12.4 The Way Without Any Recognition
The personal discount code. If you enter a partner's code when making a purchase, this serves as the attribution for us, and at the same time as your discount. We process the code as part of your order data. The legal basis is Art. 6(1)(b) GDPR: the code is part of the contract because it determines your price.
This method works without a cookie, without storage and without reading anything on your device. It is also the only method that works without a time limit and still functions even if you change devices.
12.5 When a Purchase Is Made
If the attribution results in a purchase, we permanently store which order is attributable to which partner, what net amount it is based on, and what commission follows from it. This is the basis for the accounting.
Storage period: eight years, beginning at the end of the year in which the accounting statement was issued (§ 14b(1) sentence 1 of the German VAT Act (Umsatzsteuergesetz, UStG), § 147(3) sentence 1 AO). Legal basis: Art. 6(1)(c) GDPR.
What happens to the click line after 120 days, and this is where two cases diverge: if the click led to no purchase, we delete the line completely. If it led to a purchase, the line remains as evidence for the accounting, but we delete from it all values that could be used to recognise a device: the numerical value from your IP address, the one from your browser identifier, and the one from section 12.3. What remains is the click identifier, the partner code, the destination page and the time.
We state this so precisely because the difference is the essential one for you: after 120 days, this line can no longer recognise you, including the one that remains.
12.6 Everything at a Glance
| Process | Data | Purpose | Legal Basis | Duration | Your Choice |
|---|---|---|---|---|---|
| Click line (12.1) | Click identifier, partner code, destination page, referring hostname, two numerical values | Attribution, fraud detection | Art. 6 I f | 120 days, then deleted or without recognition values | Objection |
| Recognition (12.3) | Numerical value from browser data | Attribution | Art. 6 I f | stored for 120 days, used for a maximum of 7 | Objection |
| Discount code (12.4) | the code entered | Attribution, discount | Art. 6 I b | with the order | Entry voluntary |
| Accounting (12.5) | Order, partner code, amount, commission | Accounting, tax | Art. 6 I c | 8 years | None |
| Objection marker (12.2) | a yes, without identifier | ending the collection | § 25 II no. 2 TDDDG | 5 years | You set it yourself |
The objection marker is the only access to your device that this programme makes, and it serves exclusively to switch it off. That is why it appears in the last row and not hidden away: it should not look as though we had set a cookie after all and simply given it a nice name.
What is deliberately NOT in this table: no cookie for attribution, no entry in your browser's local storage, no device fingerprint, no attribution to your customer account. The Partner Programme does not use any of these. Should this change, this text and the consent banner will change first, not the programme.
12.7 If You Become a Partner Yourself
If you register for the Partner Programme, we additionally process your master data: name, address, date of birth, email address, tax status and, where applicable, tax number or VAT ID, as well as your bank details for payout. The legal basis is the performance of the partner contract (Art. 6(1)(b) GDPR) and, insofar as it concerns the details required for tax purposes on the credit note, a legal obligation (Art. 6(1)(c) GDPR, § 14(4) UStG). We retain the statements for eight years. If you change your bank details, we send a confirmation to your registered email address as a security measure.
13. Storage Period and Deletion
We adhere to the principles of data avoidance and data minimisation. We therefore only store your personal data for as long as necessary to achieve the purposes named in this policy or as required by statutory retention periods. Once the respective purpose no longer applies or these periods expire, the corresponding data is routinely blocked or deleted.
In detail: we retain invoices, credit notes and other accounting records for eight years (§ 147(1) no. 4, (3) AO; § 257(4) HGB), books and annual financial statements for ten years (§ 147(1) no. 1, (3) AO), and received and sent business letters for six years (§ 147(3) AO, § 257(4) HGB). We delete server and application logs after 14 days (section 6), contact enquiries twelve months after the last message (section 9), and raw web analytics visit data after twelve months (section 8.2). Customer accounts exist for as long as the contract runs; the periods for each product are set out in sections 10 to 12.
The separate period in section 14 applies to account data from a SEPA direct debit mandate.
14. Payment by SEPA Direct Debit and Invoicing
14.1 What Data We Process
If you choose SEPA direct debit when purchasing Code Guardian, we process the following in addition to the order data:
Bank Details
- the name of the account holder,
- your IBAN,
- your BIC, but only if your account is held outside the EEA; within the EEA, we do not collect or store a BIC.
Proof of the Mandate
- the mandate reference and an indication of whether it is a mandate for a one-off payment or for recurring payments,
- the time the mandate was granted, the IP address used at that time, and the browser identifier (user agent),
- the complete wording of the mandate text in exactly the version you confirmed, including the version number and checksum,
- our creditor identifier and our name in the version that applied at the time the mandate was granted.
Payment History
- the announced due dates, the amounts, the time of submission, and any direct debit return together with its reason.
14.2 Why We Process the Data
We process the bank details and the mandate to collect the agreed amount, to send you the pre-notification and the invoice, and to handle queries and direct debit returns. We store the time, IP address, browser identifier and the wording of the mandate in order to be able to prove that, and with what content, you granted the mandate. We must be able to provide this proof if a collection is disputed as unauthorised; the law provides for a period of 13 months from the debit for this purpose.
14.3 On What Legal Basis
The processing of the bank details and the mandate is necessary for the performance of the contract concluded with you (Art. 6(1)(b) GDPR). Insofar as we create and retain invoices and accounting records, we process your data to fulfil our tax and commercial law obligations (Art. 6(1)(c) GDPR in conjunction with § 147 AO and § 257 HGB).
14.4 Who Receives the Data
Our bank receives the details necessary for the collection: account holder, IBAN, amount, due date, mandate reference, our creditor identifier, and the designation as a first or recurring collection. This transmission is part of the SEPA direct debit procedure; without it, no collection can take place.
For invoicing, we use Lexware Office (Haufe-Lexware GmbH & Co. KG, Freiburg im Breisgau) as a processor. We transmit to them your name, your billing address, your email address, your VAT ID where applicable, and the invoice line items and amounts. The remarks field of the invoice also contains the pre-notification with the earliest collection date, the mandate reference, our creditor identifier, and your IBAN shortened to the last four digits. Your complete IBAN and the name of the account holder are not transmitted to Lexware Office.
No disclosure to other recipients takes place. In particular, your bank details do not appear in the internal notifications with which we trigger a due collection; these state only the name, mandate reference, amount and due date.
14.5 How Long We Store the Data
We delete the account holder and IBAN 14 months after the last collection, provided that no valid mandate still exists at that time. The period follows the statutory refund period of 13 months for unauthorised payments plus a safety margin. If the mandate continues to exist, we store the account data for as long as the mandate is valid.
The proof of the mandate (mandate reference, time, IP address, browser identifier, wording, version and checksum), as well as the details of the payment history, remain stored beyond this because they are part of our accounting records. We retain invoices and the associated accounting records in accordance with the statutory periods (§ 147 AO, § 257 HGB).
14.6 How the Data Is Protected
We store the account holder and IBAN in encrypted form (encryption at rest). The key is located on the same server as the application; this is not end-to-end encryption. Within our company, the bank details can only be viewed via access protected by two-factor authentication, and every instance of access is logged together with the person and the time.
14.7 Whether Providing This Information Is Mandatory
Providing the account holder and IBAN is voluntary. Without this information, we cannot offer the SEPA direct debit payment method; the purchase is then possible using the other payment methods offered.
Changes to This Privacy Policy
We adapt this privacy policy whenever changes to the services we actually use or to the underlying legal situation make this necessary. For your subsequent visits to our website, the version published on this page that is current at the time will then apply. Please therefore inform yourself regularly about the content of this policy.