Logo Handwerkersoftware plancraft
Features
Office
Icon von einem Dokument, welches für die Funktion Auftragsdokumente steht
Project documents

Offers, order confirmations, delivery notes and invoices.

Icon von einem Laptop, welches für die Funktion Stammdaten steht
Master data

Easily manage and reuse your data.

Icon von einem Kalender, welches für die Funktion Plantafel steht
Planning board

Project and deployment planning for your company.

Icon von Ordnern, welches für die Funktion Projektmappe steht
Project folder

Central collection point for all order-related elements.

Incoming invoices

Capture and manage automatically.

Icon von einem Taschenrechner, welches für die Funktion Nachkalkulation steht
Post-calculation

Determine profitable prices for your services.

Icon für die Funktion E-Rechnung
E-Invoice

Create legally compliant e-invoices easily.

Construction site
Icon von einem Maßband, welches für die Funktion mobiles Aufmaß steht
Mobile measurement

Taking measurements on-site at the customer’s premises is child’s play.

Icon von einem Wecker, welches für die Funktion Zeiterfassung steht
Time tracking

Track times and always keep an eye on them.

Chat

Secure communication between construction site and office.

Icon von einem Baustellenhelm mit einem Dokument, welches für die Funktion Baudokumentation steht
Documentation

Documentation and reporting made easy.

Usage Options
Icon von einem Server, welches für die Funktion Schnittstellen steht
Interfaces

Import your data easily.

Icon von einem Computer mit Wolken, welches für die Funktion Cloud steht
Cloud software

Access your data from any device, anywhere.

Icon von einem Bildschirm mit Apple Symbol, welches für die die plancraft Nutzung auf Mac und iOS steht
For Mac & iOS

Easy to use from your Apple device.

Icon von einem Computer mit WIndows symbol.
For Windows

Easy to use from your Windows device.

Bild einer Mitarbeiterin von plancraft
Book a demo
In a joint product presentation, we will guide you through all the functions and answer your questions.
Select a date
AI Future
Trades
Icon eines Farbeimers und Farbrolle, welche das Gewerk Maler- und Lackierer repräsentieren
Painters & Varnishers
Icon von Werkzeugen, welche das Gewerk Dachdecker repräsentieren
Roofer
Icon eines Baums, welcher das Gewerk Garten- und Landschaftsbau repräsentiert
Landscapers & Gardeners
Stucco Worker
Interior finishing
Icon von Werkzeugen, welche das Gewerk Tischler und Schreiner repräsentieren
Joiners & Carpenters
Icon von Fliesen, welche das Gewerk Fliesenleger repräsentieren
Flooring & Tiling professionals
Icon von einem Dach mit Photovoltaik, welche das Gewerk PV repräsentieren
PV professionals
General constructor
Screed layer
Icon von einer Schubkarre, welche das Gewerk Bauunternehmer repräsentiert
Building contractors
Icon von Werkzeugen, welche das Gewerk Zimmerer repräsentieren
Carpenters
Plasterer
Metal roofer
Metal fabrication
Tips
Knowledge
Blog
Practical tips & industry news
Help
Contact & Support
Mon–Fri, 8am–5pm
Tools
plancraft Visibility Scanner
New
Check online visibility
More tools
Coming soon
More free tools
Pricing
Functions
Trades
Contact
Pricing
plancraft Visibility Scanner
New
Book a demo
Drei Sales Mitarbeiter in Kundengesprächen.
signup
Login
Start free trial

Privacy Notice

This Privacy Notice explains how personal data is processed on the website www.plancraft.com (hereinafter "Website") by Plancraft GmbH. Plancraft GmbH processes only such data as is necessary for the provision and security of the Website and its services, and adheres to the principle of data minimisation. "Personal data" means all information relating to an identified or identifiable natural person (data subject), such as name, address, telephone number, date of birth, email address or IP address. Information that cannot be attributed to a specific person — for example due to anonymisation — does not constitute personal data.

Content

H2
Cookie Name
Provider
Purpose
Category
Retention Period
IDE
Google AdSense
Used for displaying personalised advertising within programmatic advertising
Marketing/Tracking Cookies
1 year 1 month
test_cookie
Google AdSense
Checks whether the browser accepts cookies to enable ad delivery
Marketing/Tracking Cookies
14 minutes
FPAU
Google Analytics
Collects anonymous visitor data for website analysis purposes
Statistics Cookies
2 months 28 days
FPID
Google Analytics
Distinguishes individual users for statistical analysis
Statistics Cookies
1 year 1 month
FPLC
Google Analytics
Short-term user identification for statistical analyses
Statistics Cookies
20 hours

_ga
Google Analytics
Enables the distinction of individual users by Google Analytics
Statistics Cookies
1 year 1 month
_ga_[ID]
Google Analytics
Stores session status for website analysis with Google Analytics
Statistics Cookies
1 year 1 month
_gcl_au
Google Analytics
Converts clicks from Google Ads into conversions and tracks advertising effectiveness
Marketing/Tracking Cookies
2 months 28 days
_gcl_au
Google Tag Manager
Converts clicks from Google Ads into conversions and measures campaign success
Technically Necessary Cookies
2 months 28 days
TESTCOOKIESENABLED

YouTube
Checks cookie capability for video functions during video use
Technically Necessary Cookies
1 minute
VISITOR_INFO1_LIVE
YouTube
Estimates user bandwidth for optimal video playback
Preference and Comfort Cookies
5 months 29 days
VISITOR_PRIVACY_METADATA
YouTube
Stores privacy settings for embedded YouTube videos
Preference and Comfort Cookies
5 months 29 days
YSC
YouTube
Manages session data during a YouTube video visit
Technically Necessary Cookies
Session
__Secure-ROLLOUT_TOKEN
YouTube
Management of rollout changes for YouTube content
Preference and Comfort Cookies
5 months 29 days
__Secure-YNID
YouTube
Improves protection against misuse in connection with YouTube video content
Technically Necessary Cookies
5 months 29 days
_hjSession_3901576
Hotjar
Records user session behaviour to improve user-friendliness
Statistics Cookies
30 minutes
HUBLYTICS_EVENTS_53
HubSpot
Records usage events for analysis via HubSpot
Statistics Cookies
Persistent
__cf_bm
HubSpot
Distinguishes between humans and bots for security purposes with HubSpot content
Strictly Necessary Cookies
30 minutes
__hssc
HubSpot
Tracks sessions for statistical evaluation with HubSpot
Statistics Cookies
30 minutes
__hssrc
HubSpot
Determines whether the user has started a new session (HubSpot)
Statistics Cookies
Session
__hstc
HubSpot
Main cookie for tracking visitor activities via HubSpot
Statistics Cookies
5 months 29 days

_cfuvid
HubSpot
Used to distinguish users in HubSpot forms
Strictly Necessary Cookies
Session
hubspotutk
HubSpot
Identifies visitors by their HubSpot user ID for analysis
Statistics Cookies
5 months 29 days
__cmpcc
Consentmanager.net
Stores the user's consent to the use of various cookie categories
Technically Necessary Cookies
6 minutes
__cmpcccu43828
Consentmanager.net
Documents cookie settings for Consentmanager.net
Technically Necessary Cookies
11 months 30 days
__cmpcccu43828
Consentmanager.net
Documents cookie settings for Consentmanager.net
Technically Necessary Cookies
14 days
_cmpcccu43828.plancraft.com
Consentmanager.net
Permanently saves user preferences for Consentmanager.net
Strictly Necessary Cookies
Persistent
__cmpconsent43828
Consentmanager.net
Stores consent preferences for Consentmanager.net
Strictly Necessary Cookies
11 months 30 days
_cmpconsent43828.plancraft.com
Consentmanager.net
Permanently documents cookie consents via Consentmanager.net
Technically Necessary Cookies
Infinite
_fbp
Meta Pixel
Enables the placement of targeted advertising for website visitors via Facebook
Marketing/Tracking Cookies
2 months 28 days
lastExternalReferrer
Meta Pixel
Stores the last external referrer for advertising analysis
Marketing/Tracking Cookies
Infinite
lastExternalReferrerTime
Meta Pixel
Holds the timestamp of the last external referrer for advertising evaluations
Marketing/Tracking Cookies
Infinite
MUID
Microsoft Advertising
Tracks user behaviour across various Microsoft services for advertising optimisation
Marketing/Tracking Cookies
1 year 25 days
_uetsid
Microsoft Advertising
Stores session ID for tracking Microsoft Ads campaigns
Marketing/Tracking Cookies
Infinite
_uetvid
Microsoft Advertising
Stores unique visitor ID for Microsoft Ads tracking
Marketing/Tracking Cookies
Infinite
_rdt_uuid
Reddit
Anonymises users for reach measurement of Reddit advertisements
Marketing/Tracking Cookies
2 months 28 days
1547645:session-data
Taboola
Collects session data to optimise Taboola advertising
Marketing/Tracking Cookies
Infinite
eng_mt
Taboola
Enables control of Taboola marketing templates
Marketing/Tracking Cookies
Infinite
t_gid
Taboola
Stores unique user identifier for Taboola advertising
Marketing/Tracking Cookies
11 months 30 days
t_pt_gid
Taboola
Enables user recognition for Taboola promotion tracking
Marketing/Tracking Cookies
11 months 30 days
taboola_session_id
Taboola
Manages current session for Taboola content tracking
Marketing/Tracking Cookies
Session
TDCPM
TradeDesk
Distinguishes users and stores preferences for TradeDesk advertising
Marketing/Tracking Cookies
11 months 30 days
TDID
TradeDesk
Identifies users for targeted ad delivery by TradeDesk
Marketing/Tracking Cookies
11 months 30 days
_tt_enable_cookie
TikTok Pixel
Enables tracking via the TikTok Pixel for targeted advertising campaigns
Marketing/Tracking Cookies
1 year 25 days
_ttp
TikTok Pixel
Tracks user actions via the TikTok Pixel to measure advertising success
Marketing/Tracking Cookies
1 year 25 days
ttcsid
TikTok Pixel
Stores session information for the TikTok Pixel for conversion measurement
Marketing/Tracking Cookies
1 year 25 days
__cf_bm
Vimeo
Used to distinguish between legitimate users and bots on Vimeo
Strictly necessary cookies
30 minutes
vuid
Vimeo
Stores the Vimeo user ID for analysis purposes
Statistics cookies
1 year 1 month

1. Controller

The Controller responsible for the processing of personal data on the Website within the meaning of the General Data Protection Regulation (GDPR) is:

‍

Plancraft GmbH, Zirkusweg 6, 20359 Hamburg

‍

For data protection enquiries or to exercise your Data Subject Rights, please contact legal(at)plancraft.com.
‍

2. Data Protection Officer

The following has been appointed as Data Protection Officer:
‍

Kertos GmbH, Brienner Straße 41, 80333 München, Deutschland, Email: dsb(at)kertos.io

‍

3. Data Processing on Our Website

3.1. Provision of the Website

Purpose: We process your data in order to:

  • ensure reliable operation of the website
  • enable user-friendly access to our website
  • and maintain IT security

Recipients:

  • Webflow, Inc. 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA (Website hosting)
  • Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg (CDN for faster delivery of the website)
  • Volentio JSD Limited, 57, James Place Street, St Paul's Bay, SPB 3415, Malta (CDN for faster delivery of the website)
  • Fastly Inc., 475 Brannan St, Suite 300, San Francisco, CA 94107, USA (CDN for faster delivery of the website)

Processed data:

  • IP address of the requesting device
  • Method (e.g. GET, POST), date and time of the request
  • Address of the website accessed and path of the requested file
  • Where applicable, previously accessed or requesting website/file (HTTP referrer)
  • Information about the browser and operating system used
  • Version of the HTTP protocol, HTTP status code, size of the delivered file
  • Request information such as language, content type, content encoding, character encodings

Legal basis: Art. 6(1)(f) GDPR. The processing of the aforementioned data is necessary for the provision of the Website and to ensure secure and user-friendly operation.

‍

Retention period: The collected data is deleted as soon as it is no longer required for the operation of the Website. After no more than 7 days, the data is anonymised by shortening the IP address to domain level, making it no longer possible to establish a reference to an individual user. In anonymised form, the data may also be processed for statistical purposes.

‍

Further information: https://webflow.com/legal/eu-privacy-policy; https://d1.awsstatic.com/legal/privacypolicy/AWS%20Privacy%20Notice%20-%202024-01-01_DE.pdf; https://www.fastly.com/de/privacy; https://volentio.com/privacy-policy

‍

3.2. Google Fonts

Purpose: Display of website content and fonts.

‍

Recipients: Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

‍

Processed data:

  • Access data (e.g. IP address, time of error)
  • Device information (e.g. device type, operating system)
  • Browser data (e.g. browser type, version)
  • Location data (e.g. country based on IP address)

Legal basis: Legitimate interest pursuant to Art. 6(1)(f) GDPR in a technically secure, consistent and visually appealing display of content and fonts.

‍

Retention period: The data is deleted as soon as the purpose of display has been achieved.

‍

Third-country transfer: Data may be transferred to servers in the USA. Google is certified under the EU-U.S. Data Privacy Framework, so the transfer can be based on Art. 45 GDPR. In addition, standard contractual clauses (SCCs) have been concluded with Google.

‍

Further information: https://policies.google.com/privacy

‍

3.3. Newsletter

Purpose: Sending email newsletters to provide information about products, services and company activities.

‍

Recipients: HubSpot Ireland Limited, 1 Sir John Rogerson's Quay, Dublin 2, Ireland and HubSpot, Inc., 2 Canal Park, Cambridge, MA 02141, USA

‍

Processed data:

  • Contact data (e.g. email address, name)
  • Technical data (e.g. time of access, IP address)
  • Usage data (e.g. open rates, click behavior)

Legal basis: Consent pursuant to Art. 6(1)(a) GDPR

‍

Retention period: The data is stored for as long as you have subscribed to the newsletter. After you unsubscribe, your data will be deleted unless statutory retention obligations preclude this.

‍

Third-country transfer: Data processing in the USA (HubSpot) on the basis of an adequacy decision (EU-U.S. Data Privacy Framework, Art. 45 GDPR)

‍

Further information: You can unsubscribe from the newsletter at any time by clicking the unsubscribe link at the end of each newsletter. https://legal.hubspot.com/privacy-policy

‍

3.4. Book a demo

Purpose: Scheduling an appointment for a product demonstration (demo) as well as accompanying communication including reminder emails for the preparation, conduct and follow-up of the initial meeting.

‍

Recipients: RevenueHero Inc., 1901 S Bascom Ave #1180, Campbell, CA 95008, USA and HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland; HubSpot Inc., 25 First Street, Cambridge, MA 02141, USA

‍

Processed data:

  • First name, last name
  • Company name
  • Email address
  • Mobile number
  • Country
  • Industry
  • Company size
  • Currently used software solution
  • Referral source
  • Opt-in for notifications

Legal basis: Contract performance and implementation of pre-contractual measures pursuant to Art. 6(1)(b) GDPR; where consent has been given to marketing communications, pursuant to Art. 6(1)(a) GDPR

‍

Retention period: Until after completion of the demo and the contact, at the latest 12 months after the last contact, provided no further contractual relationship arises or statutory retention periods preclude deletion.

‍

Third-country transfer: Data processing in the USA on the basis of EU standard contractual clauses.

‍

Further information: https://revenuehero.io/privacy-policy; https://legal.hubspot.com/privacy-policy

‍

Demodesk

Purpose: Conducting online demos and sales meetings as well as recording and analysing sales conversations.

‍

Recipients: Demodesk GmbH, Isartorplatz 8, 80331 München, Deutschland.

‍

Processed data:

  • Contact data (e.g., name, email address of participants)
  • Meeting content data (e.g., shared screen content, chat messages, audio and video recordings)
  • Usage data (e.g., meeting duration, number of participants, features used)
  • Device data (e.g., operating system, browser type)

Legal basis: Contract performance and implementation of pre-contractual measures pursuant to Art. 6(1)(b) GDPR; consent pursuant to Art. 6(1)(a) GDPR where you have agreed to recording.

‍

Retention period: Recordings are stored by default for up to 90 days.

‍

Further information: https://demodesk.com/legal/privacy-policy

‍

3.5 Create a Trial Account

Purpose: Enabling the registration and administration of a trial account for the use and testing of the platform's features.

‍

Processed data:

  • First name
  • Last name
  • Email address
  • Password
  • Registration and usage timestamps

Legal basis: Contract performance and implementation of pre-contractual measures pursuant to Art. 6(1)(b) GDPR

‍

Retention period: Until deletion of the account or at the latest six months after expiry of the trial period, provided no further use takes place.

‍

3.6 Live Chat

Purpose: Provision of a live chat system for direct customer communication and support.

‍

Recipients: HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland; HubSpot Inc., 25 First Street, Cambridge, MA 02141, USA

‍

Processed data:

  • Contact information (e.g., name, email address)
  • Chat content (e.g., messages, enquiries)
  • Technical data (e.g., IP address, browser type)
  • Usage data (e.g., time and duration of the chat)

Legal basis: Consent pursuant to Art. 6(1)(a) GDPR for the use of live chat; legitimate interest pursuant to Art. 6(1)(f) GDPR for processing to improve our customer service and optimise our services. Please note that you can end the live chat at any time and withdraw your consent to data processing. The lawfulness of processing carried out prior to withdrawal remains unaffected.

‍

Retention period: Chat logs and associated data are stored for 90 days. Contact information may be retained in the CRM system for longer in accordance with statutory retention periods and business requirements.

‍

Third-country transfer: Data transfer to the USA on the basis of the EU-U.S. Data Privacy Framework (Art. 45 GDPR)

‍

Further information: https://legal.hubspot.com/de/privacy-policy

‍

3.7 Surveys/Feedback

Purpose: Conducting and evaluating online surveys and feedback processes; collecting and evaluating user opinions to optimise services as well as for direct interaction with users on websites and in applications.

‍

Recipients: Survicate S.A., Zamiany 8 LU2, 02-786 Warsaw, Poland; hosting and IT service providers or sub-contractors engaged as required within the framework of data processing on behalf; HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland; HubSpot Inc., 25 First Street, Cambridge, MA 02141, USA

‍

Processed data:

  • Survey/feedback responses (e.g., free-text fields, multiple-choice answers, star ratings)
  • IP address (e.g., 192.168.1.1, pseudonymised)
  • Browser and device data (e.g., Chrome on Windows 11)
  • Usage/interaction data (e.g., session information, timestamp, referrer)
  • Voluntarily provided contact information (e.g., email address in survey contact forms)

Legal basis: Legitimate interest pursuant to Art. 6(1)(f) GDPR for internal optimisation purposes and usage analysis; consent pursuant to Art. 6(1)(a) GDPR where you receive survey invitations by email or voluntarily provide personal data.

‍

Retention period: Until the purpose is fulfilled or consent is withdrawn; responses and usage data are deleted as soon as they are no longer required or upon the user's request.

‍

Further information: https://help.survicate.com/en/articles/3943207-terms-of-service-privacy-policy-gdpr-and-dpa; https://legal.hubspot.com/de/privacy-policy

‍

3.8 Referral Programme

Purpose: Implementation of referral and bonus programmes, creation of personalised referral links, allocation of bonus actions and analysis of the use and optimisation of the programme.

‍

Recipients: Cello (Powerplay GmbH, Philipp-Loewenfeld-Str. 19, 80339 München, Deutschland)

‍

Processed data:

  • Username
  • Email address
  • Referral link/referral ID
  • Name and email of new prospects via referral link
  • Referral programme usage data

Legal basis: Consent pursuant to Art. 6(1)(a) GDPR for participation in the referral programme and linking with bonus actions; legitimate interest pursuant to Art. 6(1)(f) GDPR for optimising and securing the service.

‍

Retention period: Data is stored until consent is withdrawn or the purpose is achieved (completion/payment of the bonus action), generally no longer than three years; statutory retention obligations remain unaffected.

‍

Further information: https://cello.so/privacy-policy/

‍

3.9 Job Applications

Purpose: Selection of applicants for the possible establishment of an employment relationship.

‍

Recipients: Ashby, Inc., 548 Market St, San Francisco, CA 94104, USA

‍

Processed data:

  • Name
  • Email address
  • Phone number
  • Curriculum vitae (CV)
  • Cover letter
  • Additional application documents provided by you
  • IP address
  • Browser type and version
  • Operating system
  • Date and time of access

Legal basis: Art. 6(1)(b) GDPR (implementation of pre-contractual measures) and § 26(1) BDSG; Art. 6(1)(f) GDPR to the extent that our legitimate interest lies in the efficient conduct of the application process.

‍

Retention period: We store your personal data until the conclusion of the application process. In the event of a rejection, your data will be stored for a further six months after notification of the decision. In the event of legal proceedings, longer retention until final resolution may take place. If you are hired, your application documents will be stored in your personnel file for the duration of the employment relationship. You can withdraw your application at any time or object to processing; in this case, your data will be deleted and your application will not be considered further.

‍

The transfer is made on the basis of the EU-U.S. Data Privacy Framework (Art. 45 GDPR), to which Ashby has acceded as a certified company.

Further information: https://www.ashbyhq.com/privacy

‍

3.10 Analytics and Tracking

Cookies are small text files stored by your browser on your device. Cookies do not execute programs and do not install malware. Comparable technologies include web storage (local/session storage), fingerprinting, tags and pixels. Most browsers accept these technologies by default; however, you can adjust your settings to block their use or require consent. If cookies or similar technologies are blocked, certain website functions may not be fully available.

‍

Purpose: We use tracking and analysis tools to continuously optimise our website and adapt it to your requirements. For this purpose, information is collected using appropriate technologies or device information is combined (device fingerprinting).

‍

Legal basis: Technically required tools for operating the website are used on the basis of our legitimate interests pursuant to Art. 6(1)(f) GDPR or for the performance of a contract or pre-contractual measures pursuant to Art. 6(1)(b) GDPR. The storage of or access to information on your device is mandatory in these cases and is governed by § 25(2) TDDDG. Optional tools are used exclusively with your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. The tracking and analysis tools used, their respective purposes and the data processed are set out below.

‍

Recipients:

‍

Consentmanager

Purpose: Management and documentation of consent for cookies and comparable technologies on the website in order to meet legal requirements regarding proof of consent and user preferences.

‍

Recipients: consentmanager AB, Håltegelvägen 1b, 72348 Västerås, Sweden

‍

Processed data:

  • IP address (e.g. 192.168.1.1)
  • Browser version (e.g. Chrome 120.x)
  • Device information (e.g. Windows PC, smartphone)
  • Language settings (e.g. German, English)
  • Consent or withdrawal decisions (e.g. opt-in/opt-out for statistics, marketing)
  • Time and scope of the respective selection (e.g. 12/23/2025, all cookies accepted)

Legal basis: Fulfilment of legal obligations pursuant to Art. 6(1)(c) GDPR; legitimate interest pursuant to Art. 6(1)(f) GDPR; consent pursuant to Art. 6(1)(a) GDPR for non-essential cookies

‍

Retention period: Consent data stored for up to 24 months, after which re-queried; settings in local storage/cookie until actively deleted by the user or until the storage period expires

‍

Further information: https://www.consentmanager.net/datenschutz/

‍

Google Analytics

Purpose: Web analysis

‍

Recipients: Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland and Google, LLC 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

‍

Processed data:

  • Device data (e.g. IP address, device type, screen resolution)
  • Browser data (e.g. browser used, language, installed plug-ins such as ad blockers)
  • Usage data (e.g. pages visited, time spent per page, click paths, scroll depth, entry and exit pages)
  • Event data (e.g. button/link clicks, form submissions)
  • Location data (e.g. country, city)
  • Source and traffic data (e.g. referrer URL, access source such as search engine)
  • Conversion and goal achievement data (e.g. newsletter sign-ups, goals achieved on the website)

Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG

‍

Third-country transfer: For data transfers to the USA, there is an adequacy decision by the EU Commission, the EU-U.S. Data Privacy Framework. Google is certified within this framework, which is why such transfers are based on the legal basis under Art. 45 GDPR. In addition, standard contractual clauses (SCCs) have been concluded with Google.

‍

Further information: https://policies.google.com/privacy

‍

Google Ads

Purpose: Delivery of personalised advertisements, placement and optimisation of advertising campaigns and reach measurement via Google's advertising network.

‍

Recipients: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

‍

Processed data:

  • Online identifiers (e.g. cookie ID, advertising ID)
  • IP address (shortened/anonymised)
  • Browser information (e.g. language, version)
  • Information on user behaviour (e.g. ads clicked, pages visited)
  • Usage data (e.g. time and duration of interaction)
  • Device information (e.g. device type, operating system)

Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG

‍

Retention period: Cookies are stored for up to 90 days.

‍

Third-country transfer: Transfer of data to the USA on the basis of the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and additional standard contractual clauses (SCCs)

‍

Further information: https://policies.google.com/privacy

‍

Google AdSense

Purpose: Display of personalised advertising and measurement of advertising effectiveness.

‍

Recipients: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

‍

Processed data:

  • Technical information (e.g. IP address, browser type)
  • Usage behaviour (e.g. page views, clicks on ads)
  • Device information (e.g. screen resolution, operating system)
  • Location data (e.g. city, country)
  • Interest profiles (e.g. interests derived from browsing history)

Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG

‍

Retention period: Data is stored for a maximum of 18 months.

‍

Third-country transfer: Data transfer to the USA on the basis of the EU-U.S. Data Privacy Framework (Art. 45 GDPR)

‍

Further information: https://policies.google.com/technologies/ads?hl=de

‍

Google Ads Remarketing

Purpose: Use of Google Ads Remarketing for the placement of personalised and interest-based advertisements based on user behaviour on the website, audience expansion, conversion tracking and optimisation of advertising campaigns.

‍

Recipients: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; possibly advertising partners involved in the Google Display Network

‍

Processed data:

  • IP address (pseudonymised; e.g. 192.168.1.54)
  • Cookie IDs and online marketing IDs (e.g. NID, IDE, _gads)
  • Pages visited and interaction data (e.g. products viewed, clicks, time spent)
  • Device and browser information (e.g. device type, operating system, language)
  • Audience and remarketing lists (e.g. user interests, segment memberships)

Legal basis: Consent pursuant to Art. 6(1)(a) GDPR (via consent banner); occasionally legitimate interest pursuant to Art. 6(1)(f) GDPR only for non-personalised ads and system security

‍

Retention period: Cookies and marketing IDs generally up to 540 days or until consent is withdrawn; event and usage data anonymised or deleted in accordance with Google's policies

‍

Third-country transfer: Transfer of personal data to the USA and other third countries pursuant to Art. 45 GDPR on the basis of the EU-U.S. Data Privacy Framework; additional safeguards through standard contractual clauses (Art. 46(2)(c) GDPR) for non-certified recipients; additional technical and organisational measures in accordance with Google's specifications

‍

Further information: https://policies.google.com/privacy?hl=de, Opt-Out: https://www.google.com/settings/ads/anonymous

‍

Google Tag Manager

Purpose: Management and triggering of website tags via a uniform interface.

‍

Recipients: Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland and Google, LLC 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

‍

Processed data:

  • Access data (e.g. time of page view, referrer URL)
  • Device data (e.g. IP address, device type)
  • Browser data (e.g. browser used, language settings)
  • Event data (e.g. tag triggering, interactions with embedded scripts)
  • Location data (e.g. country, city – based on IP address)

Retention period: Cookies are stored for up to 90 days.

‍

Third-country transfer: Transfer of data to the USA on the basis of the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and additional standard contractual clauses (SCCs)

‍

Further information: https://policies.google.com/privacy

‍

Meta Pixel

‍Purpose: Measurement of the effectiveness of Facebook advertisements (conversion tracking) and delivery of targeted advertising.

‍

Recipients: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

‍

Processed data:

  • Access data (e.g. pages visited, time of visit)
  • Device data (e.g. IP address, browser information)
  • Usage data (e.g. interactions with advertisements, click behaviour)

Legal basis: Consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG

‍

Retention period: Cookies are stored for up to 90 days.

‍

Further information: https://www.facebook.com/about/privacy

‍

YouTube Videos

Purpose: Embedding videos in our website and improving the user experience.

‍

Recipients: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("YouTube")

‍

Processed data:

  • IP address
  • Date and time of the request
  • Page visited on our website
  • Browser type and operating system used
  • Technical connection data (e.g. HTTP headers)
  • YouTube account information (if logged in)

Legal basis: Consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG

‍

Retention period: In accordance with YouTube's privacy policy

‍

Third-country transfer: Data may be transferred to the USA. Transfers are based on the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and standard contractual clauses (SCCs)

‍

Further information: https://www.youtube.com/howyoutubeworks/privacy/

‍

YouTube Images

Purpose: Embedding preview images (thumbnails) from YouTube videos.

‍

Recipients: Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

‍

Processed data:

  • Access data (e.g. IP address, time of errors)
  • Usage data (e.g. general usage statistics, page views at time of error)
  • Device information (e.g. device type, operating system)
  • Browser data (e.g. browser used, version)
  • Location data (e.g. country – based on IP address)

Legal basis: Consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG.

‍

Third-country transfer: Google is certified under the EU-U.S. Data Privacy Framework, which allows data transfers to the USA pursuant to Art. 45 GDPR. In addition, standard contractual clauses (SCCs) have been concluded to ensure an adequate level of data protection.

‍

Further information: https://www.youtube.com/howyoutubeworks/privacy/

‍

Optibase

Purpose: Analysis and optimisation of website performance through the implementation and evaluation of A/B and split tests, in particular to improve user experience, conversion rates and marketing measures.

‍

Recipients: WOICE, razvoj digitalnih produktov, svetovanje in prodaja, d.o.o., Ulica škofa Maksimilijana Držečnika 6, 2000 Maribor

‍

Processed data:

  • Online IDs and cookie information (e.g. user identifier, session UUID)
  • IP address (pseudonymised, e.g. 192.168.1.1)
  • Usage and interaction data (e.g. pages visited, events, clicks)
  • Technical metadata (e.g. browser type, device, referrer)
  • Marketing and tracking parameters (e.g. campaign attribution)

Legal basis: Consent pursuant to Art. 6(1)(a) GDPR (via consent banner); in exceptional cases legitimate interest pursuant to Art. 6(1)(f) GDPR (e.g. for IT security)

‍

Retention period: Until consent is withdrawn or cookies are deleted by the user, at most 24 months

‍

Further information: https://cdn.prod.website-files.com/658213b70c2c8e5b9d06ca08/6660bea787a22a337b5debe4_nlaw_Optibase%20PrivacyPolicy_5jun2024.docx.pdf

‍

Vimeo

Purpose: Embedding and playback of videos and analysis of video usage.

‍

Recipients: Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA

‍

Processed data:

  • Technical information (e.g. IP address, browser type)
  • Usage data (e.g. videos watched, playback duration)
  • Device information (e.g. screen resolution, operating system)
  • Account information, if applicable (e.g. username, email address)
  • Interaction data (e.g. likes, comments)

Legal basis: Consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG

‍

Retention period: Data is stored for the duration of the consent, but for no longer than 24 months

‍

Third-country transfer: Data transfer to the USA on the basis of the EU-U.S. Data Privacy Framework (Art. 45 GDPR)

‍

Further information: https://vimeo.com/privacy

‍

HubSpot Analytics‍

Purpose: Website monitoring and support and optimisation of digital marketing measures.

‍

Recipients: HubSpot, Inc., 25 First Street, Cambridge, MA 02141, USA.

‍

Processed data:

  • Identification data (e.g. unique user token, user identifier in the cookie "hubspotutk")
  • Access data (e.g. date and time of visit, domain of the website)
  • Session data (e.g. number of sessions, duration of individual visits)
  • Device data (e.g. device type, operating system)
  • Browser data (e.g. browser used, language settings)
  • Usage data (e.g. pages visited, returning visits)

Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG

‍

Retention period: Cookies are stored for up to 90 days.

‍

Third-country transfer: Transfer of data to the USA on the basis of the EU-U.S. Data Privacy Framework (Art. 45 GDPR)

‍

Further information: https://legal.hubspot.com/de/privacy-policy

‍

Microsoft Advertising

Purpose: Placement of targeted advertising and analysis of the effectiveness of advertising measures.

‍

Recipients: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18

‍

Processed data:

  • Device information (e.g. IP address, browser type)
  • User behaviour (e.g. clicks, page views)
  • Demographic data (e.g. age group, gender, where specified)
  • Advertising interaction data (e.g. impressions, conversions)

Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG

‍

Retention period: Data is stored for up to 18 months.

‍

Third-country transfer: Transfer of data to the USA on the basis of the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and additional standard contractual clauses (SCCs)

‍

Further information: https://privacy.microsoft.com/en-us/privacystatement

‍

Mixpanel

Purpose: Analysis of user behaviour to optimise the website and online services offered.

‍

Recipients: Mixpanel, Inc., One Front Street, 28th Floor, San Francisco, CA 94111, USA

‍

Processed data:

  • Access data (e.g. IP address, date and time of request)
  • Usage data (e.g. pages visited, interactions with the website)
  • Source and traffic data (e.g. referrer URL, entry page)
  • Device data (e.g. device type, screen resolution)
  • Browser data (e.g. browser type and version)
  • Location data (e.g. country, region – based on IP address)

Legal basis: Consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG

‍

Retention period: Data is stored for up to 12 months according to the provider, unless configured otherwise.

‍

Third-country transfer: Transfer of data to the USA on the basis of the EU-U.S. Data Privacy Framework (Art. 45 GDPR)

‍

Further information: https://mixpanel.com/legal/privacy-policy

‍

Taboola

Purpose: Implementation and optimisation of programmatic advertising through the delivery of personalised content and analysis of advertising impact.

‍

Recipients: Taboola Germany GmbH, Alt-Moabit 2, 10557 Berlin; Taboola Inc., 16 Madison Square West, 7th Floor, New York, NY 10010, USA

‍

Processed data:

  • Access data (e.g. IP address, time of access)
  • Usage data (e.g. interactions with advertising content)
  • Source and traffic data (e.g. referrer URL)
  • Device data (e.g. device type, screen resolution, mobile device ID such as IDFA/AAID)
  • Browser data (e.g. browser type and version, operating system)
  • Location data (e.g. country, region – based on IP address)
  • Cookie data for pseudonymised recognition (e.g. Taboola ID, session timestamp)

Legal basis: Consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG

‍

Retention period: Cookies and tracking data are generally stored for up to 13 months.

‍

Third-country transfer: Transfer of data to the USA on the basis of the EU-U.S. Data Privacy Framework (Art. 45 GDPR); for other third countries, application of appropriate safeguards (e.g. standard contractual clauses pursuant to Art. 46 GDPR)

‍

Further information: https://www.taboola.com/de/policies/datenschutzerklaerung

‍

The Trade Desk

Purpose: Placement and optimisation of personalised online advertising, reach measurement, interest-based delivery of advertisements, analysis and measurement of advertising campaign success.

‍

Recipients: The Trade Desk, Inc., 42 N. Chestnut Street, Ventura, CA 93001, USA; possibly affiliated companies, technical service providers, advertisers and publishers within the programmatic advertising supply chain

‍

Processed data:

  • Online identifiers and cookies (e.g. cookie ID, device ID)
  • IP address (e.g. 192.168.1.1, pseudonymised/shortened)
  • Usage and interaction data (e.g. clicks on advertising materials, content viewed)
  • Location data (e.g. approximate geo-coordinates, country)
  • Device and browser properties (e.g. device type, operating system, browser version)
  • Assignment to audiences/profiles (e.g. interests, segment membership)

Legal basis: Consent pursuant to Art. 6(1)(a) GDPR (via consent banner); partly legitimate interest pursuant to Art. 6(1)(f) GDPR for fraud prevention and system security (limited data processing, see CMP)

‍

Retention period: Cookies/IDs generally up to 12 months, interaction/usage data up to 24 months, depending on opt-in and legal requirements

‍

Third-country transfer: Transfer to the USA on the basis of the EU-U.S. Data Privacy Framework (Art. 45 GDPR) for certified recipients; additional safeguards for other recipients through standard contractual clauses (Art. 46 GDPR) and supplementary technical/organisational measures

‍

Further information: https://www.thetradedesk.com/de/privacy

‍

TikTok Pixel

Purpose: Measurement of the effectiveness of advertising campaigns, tracking of user interactions, conversion tracking, audience analysis and optimisation of advertisements on TikTok.

‍

Recipients: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland; TikTok Information Technologies UK Limited, Kaleidoscope, 4 Lindsey Street, London, United Kingdom, EC1A 9HP; possibly technical sub-processors within the European locations

‍

Processed data:

  • Online identifiers, cookies and tracking IDs (e.g. pixel ID, device identifier)
  • IP address (pseudonymised)
  • Usage data (e.g. pages visited, time spent, interactions such as clicks and conversions)
  • Possible location data (approximate geolocation, country)
  • Technical details of the device used (e.g. browser type, operating system)
  • Event data such as actions performed (e.g. purchase, registration)

Legal basis: Consent pursuant to Art. 6(1)(a) GDPR (via cookie or consent banner); legitimate interests pursuant to Art. 6(1)(f) GDPR only in exceptional cases

‍

Retention period: Cookies and tracking IDs are generally stored for up to 2 years, event data is deleted upon achievement of purpose or after withdrawal of consent; further retention may arise from legal obligations

‍

Third-country transfer: Transfer to third countries (e.g. USA, United Kingdom) on the basis of standard contractual clauses (Art. 46(2)(c) GDPR); TikTok may use certified recipients under the EU-U.S. Data Privacy Framework where applicable

‍

Further information: https://www.tiktok.com/de/privacy-policy

‍

Reddit

Purpose: Reach and conversion measurement, audience building, marketing/remarketing and display and measurement of advertising on and via Reddit.

‍

Recipients: Reddit Ireland Limited, Fitzwilliam Hall, Fitzwilliam Place, Dublin 2, D02 T292, Ireland; Reddit Inc., 520 Third Street, Suite 305, San Francisco, CA 94107, USA; possibly technical processors in the context of platform services

‍

Processed data:

  • Online IDs, cookie and tracking identifiers (e.g. _rdt_uuid)
  • IP address (pseudonymised)
  • Usage data (e.g. pages viewed, click paths, interactions, conversions)
  • Technical device information (e.g. browser, operating system, device type)
  • Location data (based on IP; e.g. country, city)
  • Timestamps and session data (e.g. visit times, time spent)

Legal basis: Consent pursuant to Art. 6(1)(a) GDPR (via consent banner); in exceptional cases legitimate interest pursuant to Art. 6(1)(f) GDPR

‍

Retention period: Storage period of cookies (e.g. _rdt_uuid) up to 2 years from setting; event-related analysis data until purpose is achieved or deleted after withdrawal of consent

‍

Third-country transfer: Transfer of personal data to the USA and other third countries on the basis of the EU-U.S. Data Privacy Framework (Art. 45 GDPR) or – where required – on the basis of standard contractual clauses (Art. 46(2)(c) GDPR) and supplementary protective measures

‍

Further information: https://www.reddit.com/policies/privacy-policy

‍

Below you will find an overview of the cookies we use:

‍

{{info-table}}

‍

3.11 Contact / Customer Communication

Purpose: Processing and responding to your enquiry.

‍

Processed data:

  • Name
  • Email address
  • Content of your message

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in communicating with you). If your enquiry is directed towards the conclusion or performance of a contract, processing is carried out on the basis of Art. 6(1)(b) GDPR.

‍

Retention period: Your data will only be stored for as long as is necessary for the final processing of your enquiry.

‍

Purpose: In-app communication, customer support and helpdesk management.

‍

Recipients: Intercom R&D Unlimited Company, 124 St. Stephen's Green, Dublin 2, Ireland.

‍

Processed data:

  • Identification data (e.g. user ID, email address)
  • Communication data (e.g. content of chat messages and support tickets)
  • Usage data (e.g. pages visited, interactions with the messenger widget)
  • Device data (e.g. browser, operating system, IP address)
  • Session data (e.g. time and duration of session)

Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR and § 25(1) TDDDG

‍

Retention period: Data is stored for the duration of the contractual relationship; cookies are stored for up to 9 months.

‍

Third-country transfer: Transfer of data to the USA on the basis of the EU-U.S. Data Privacy Framework (Art. 45 GDPR)

‍

Further information: https://www.intercom.com/legal/privacy

‍

3.12 Social Media Online Presences

Purpose: Communication with interested parties, information about products and services and analysis of the use of our online presences.

‍

Recipients:

  • LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
  • Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, D04 X2K5, Ireland ("Facebook" & "Instagram")
  • Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07 Ireland ("X")
  • TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland ("TikTok")
  • Reddit Inc., 548 Market St. #16093, San Francisco, CA 94104, USA ("Reddit")
  • Vimeo Inc., 330 West 34th Street, 10th Floor, New York, NY 10001, USA ("Vimeo")
  • Google Ireland Limited, Gordon House, 4 Barrow Street, Dublin, D04 E5W5, Ireland ("YouTube")
  • HubSpot Ireland Limited, 1 Sir John Rogerson's Quay, Dublin 2, Ireland and HubSpot, Inc., 2 Canal Park, Cambridge, MA 02141, USA (analysis and evaluation of interactions with our social media profiles and for contacting and managing communications via the social media platform)

Processed data:

  • Demographic information (e.g., age, gender)
  • Professional information (e.g., industry, professional experience)
  • Interaction data (e.g., likes, shares)
  • Usage statistics (e.g., page views, video views)
  • Content preferences (e.g., popular topics, interests)

Legal basis:

  • Art. 6(1)(b) GDPR (performance of a contract and pre-contractual measures)
  • Art. 6(1)(f) GDPR (legitimate interest in effective information and communication)

Retention period: In accordance with the privacy policies of the respective platforms

‍

Third-country transfer: Possible transfer to the USA and other third countries, depending on the platform

‍

Further information:

  • Meta & Instagram:
    • https://de-de.facebook.com/legal/terms/information_about_page_insights_data
    • https://www.facebook.com/legal/terms/page_controller_addendum
    • https://www.facebook.com/about/privacy/
    • https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect
  • LinkedIn:
    • https://legal.linkedin.com/pages-joint-controller-addendum
    • https://www.linkedin.com/legal/privacy-policy
  • X: https://twitter.com/de/privacy
  • Reddit: https://www.redditinc.com/policies/privacy-policy
  • TikTok: https://www.tiktok.com/legal/page/eea/privacy-policy/de-DE
  • YouTube: https://policies.google.com/privacy?hl=de

Note: We have no influence over the independent data processing carried out by the platform operators. When you visit our online presences, usage data may be transmitted to the operators, who use it for their own purposes. Data Subject Rights can be asserted directly against the platform operators.

‍

4. Privacy Information for Customers and Other Contractual or Business Partners and Prospective Customers

4.1 Contract initiation, performance, fulfilment and pre-contractual measures

Purpose: Initiation, performance and fulfilment of contracts and the implementation of pre-contractual measures (e.g. request for quotation, contract negotiations)

‍

Recipients: Internal responsible parties and specialist departments; affiliated companies; processors in the area of hosting, customer management and IT services; possibly external tax advisors and public authorities (e.g. tax authorities, law enforcement authorities) where legally required

‍

Processed data:

  • First and last name (e.g., John Smith)
  • Contact/address information (e.g., email, address)
  • Company-related data (e.g., company name, contact person)
  • Contractual transaction data (e.g., quote number, scope of services)
  • Other information you provide during contract initiation (e.g., special requests)

Legal basis: Contract performance and pre-contractual measures pursuant to Art. 6(1)(b) GDPR

‍

Retention period: For the duration of the business relationship and beyond in accordance with statutory retention periods (e.g. 6 years under § 257 HGB, 10 years under § 147 AO, up to 30 years under BGB for certain claims)

‍

Third-country transfer: Data transfers are generally made only within the EU/EEA; transfers to third countries (e.g. USA) only where an adequacy decision exists (Art. 45 GDPR, e.g. EU-U.S. Data Privacy Framework) or on the basis of standard data protection clauses (Art. 46(2)(c) GDPR) and additional protective measures

‍

4.2 Data processing for advertising purposes

Postal or telephone advertising measures directed at business customers

‍

Purpose: Postal and telephone contact with business customers for personalised information about products, services and offers

‍

Recipients: HubSpot Ireland Limited, 1 Sir John Rogerson's Quay, Dublin 2, Ireland, HubSpot, Inc., 2 Canal Park, Cambridge, MA 02141, USA; Aircall SAS, 11-15 rue Saint-Georges, 75009 Paris, France

‍

Processed data:

  • Salutation
  • First and last name
  • Business address
  • Business phone number

Legal basis: Legitimate interest pursuant to Art. 6(1)(f) GDPR in direct advertising for own products and services.

‍

Retention period: Until withdrawal/objection or as long as the purpose exists; subsequent deletion, unless other retention obligations apply

‍

Third-country transfer: Data processing in the USA (HubSpot) on the basis of an adequacy decision (EU-U.S. Data Privacy Framework, Art. 45 GDPR)

‍

Further information: https://legal.hubspot.com/privacy-policy and https://aircall.io/de/privacy/

‍

Email  advertising directed at business customers

Purpose: Sending direct advertising by email to existing customers for information about similar products and services following an existing contractual relationship

‍

Recipients: Internal sales and marketing departments; HubSpot Ireland Limited, 1 Sir John Rogerson's Quay, Dublin 2, Ireland; HubSpot, Inc., 2 Canal Park, Cambridge, MA 02141, USA

‍

Processed data:

  • Salutation
  • First and last name
  • Business address

Legal basis: Legitimate interest pursuant to Art. 6(1)(f) GDPR taking into account the exception under § 7(3) UWG

‍

Retention period: Until objection to processing or as long as the advertising purpose continues; deletion thereafter or where other statutory retention periods apply

‍

Third-country transfer: Transfer to the USA to HubSpot, Inc. on the basis of an adequacy decision pursuant to Art. 45 GDPR (EU-U.S. Data Privacy Framework); for transfers to other third countries, use of standard data protection clauses pursuant to Art. 46(2)(c) GDPR and supplementary protective measures

‍

Further information: https://legal.hubspot.com/privacy-policy

‍

4.3 Privacy Information for Plancraft Software and App

‍Our software and app are made available to independent users within the framework of data processing on behalf. To the extent that they use our software and app to process data relating to their customers, project partners and employees therein, we act as your service provider as a strictly instruction-bound processor. The Controller for data processing is the entrepreneur or company using our software. An agreement on data processing on behalf pursuant to Art. 28 GDPR has been concluded between us and the Controller with regard to the provision and operation of the software and app.

In order to obtain information as a data subject about the processing of your data, the contact details of the Controller and the contact details of the Controller's Data Protection Officer, please contact the responsible party for the use of our software and app.

‍

Purpose: Plancraft supports the processing of project-related commercial processes in sales, consulting, employee management, invoicing and related business areas. Data collection/processing is carried out for the exercise of these purposes.

‍

Processed data:

  • Access credentials (email, password, SMS code)
  • IP address and device information
  • Names and addresses of customers, clients, suppliers, and partners
  • Company size/industry
  • Documents (e.g., quotes, invoices, contracts)
  • In-app chat content and metadata
  • Project duration/staff deployment, working hours, and project data
  • Accounting and banking data (IBAN, BIC)
  • Wage costs, surcharges, payment reminders
  • Data in logos, letterheads, or other files

Legal bases: Compliance with the statutory legal bases is the responsibility of the Controller.

‍

Recipients: Depending on the feature and scope of use, data is transferred to the following service providers:

  • DanglIT GmbH
  • Google Ireland Ltd.
  • Mailgun Technologies Inc.
  • Neon Inc.
  • OpenAI Inc.
  • Sentry / Functional Software, Inc.
  • Stripe Payments Europe Ltd.
  • Stripe Inc.

Data processing in third countries: Data processing may take place outside the EEA, in particular in the USA. The transfer is made pursuant to Art. 45 GDPR on the basis of the EU-U.S. Data Privacy Framework, provided the providers are certified (e.g. Google LLC, Neon Inc., Stripe Inc., Sentry). If no certification exists, standard data protection clauses (Art. 46(2)(c) GDPR) and, where applicable, additional protective measures are used.

‍

Retention period: The retention period is determined by your company as the Controller, generally in line with the respective business purposes. You can object to the data processing at any time.

‍

Services integrated by Plancraft as Controller

‍

Cello

‍

Purpose: Implementation and management of a referral programme ("customers refer customers") and allocation and reward of successfully referred new customers; tracking, evaluation and optimisation of the status and success of user referrals.

‍

Recipients: Powerplay GmbH, Sumpfmeisenweg 3A, 81249 Munich, Germany

‍

Processed data:

  • Contact data (e.g., name, email address)
  • Company-related data (e.g., company name/ID)
  • Registration and contract data (e.g., registration status, selected product/subscription)
  • Technical data (e.g., IP address, browser, timestamp)
  • Marketing and tracking data (e.g., referral link usage)

Legal basis: Legitimate interest pursuant to Art. 6(1)(f) GDPR (provision of the referral programme for existing customers) and where applicable consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG (when using cookies/tracking mechanisms)

‍

Retention period: Data is stored for the duration of the programme and for as long as necessary to achieve the purpose and no statutory retention obligations preclude deletion; deletion takes place after the processing purpose ceases or consent is withdrawn.

‍

Further information: https://cello.so/privacy-policy/

‍

Stripe

‍

Purpose: Processing of payments in the online shop as well as fraud prevention, compliance with statutory audit obligations and optimisation of the payment process.

‍

Recipients: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland; Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA

‍

Processed data:

  • Payment information (e.g., credit card/account number, payment amount)
  • Billing and transaction data (e.g., order number, customer number)
  • Contact details (e.g., name, email address)
  • Technical information (e.g., IP address, device/browser data)
  • Verification number/authentication data (e.g., CVC)

Legal basis: Contract performance pursuant to Art. 6(1)(b) GDPR (payment processing); where applicable legitimate interest pursuant to Art. 6(1)(f) GDPR (security/fraud prevention); where applicable consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG (tracking/cookies)

‍

Retention period: Until purpose is achieved or statutory retention obligations expire; commercial and tax law requirements up to 10 years (e.g. § 257 HGB, § 147 AO)

‍

Third-country transfer: Transfer of personal data to the USA, in particular to Stripe, Inc., on the basis of the adequacy decision (EU-U.S. Data Privacy Framework, Art. 45 GDPR); additional safeguards through standard contractual clauses.

‍

Further information: https://stripe.com/privacy

‍

5. International Data Transfers

Personal data is primarily processed within the EU/EEA. Transfers to so-called "third countries" are made exclusively in compliance with the requirements of the GDPR and in the presence of appropriate safeguards. Before a transfer to a service provider in a third country, the level of data protection is assessed. A transfer only takes place if sufficient protective mechanisms exist. All service providers must conclude a data processing agreement. For providers outside the EEA, additional measures are required. Pursuant to Art. 44 et seq. GDPR, a transfer is permissible if at least one of the following conditions is met:

‍

  • The European Commission has determined that an adequate level of data protection exists.
  • Standard contractual clauses have been agreed upon with the recipient.
  • Other appropriate safeguards pursuant to Art. 46 GDPR are in place.
  • In certain exceptional cases pursuant to Art. 49 GDPR.
    ‍

6. Recipients

Personal data collected by us is generally only disclosed if:

  • You have provided your explicit consent in accordance with Art. 6(1)(a) GDPR,
  • the disclosure is necessary to safeguard our legitimate interests or to establish, exercise, or defend legal claims, and there is no reason to believe that your overriding interests or fundamental rights and freedoms requiring the protection of personal data prevail (Art. 6(1)(f) GDPR),
  • we are legally required to disclose the data (Art. 6(1)(c) GDPR), or
  • this is legally permissible and necessary for the performance of a contract with you or to take steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR).

Possible recipients include:

  • Processors: Group companies or external service providers (e.g. for technical infrastructure, processing, maintenance, or payment services) that are carefully selected and monitored. Processors may only handle data in accordance with our instructions.
  • Public authorities: Authorities and government institutions (e.g. tax authorities, public prosecutors, courts) to which we are required to transfer personal data, for instance to fulfill legal obligations or protect legitimate interests.
    ‍

7. Data Security and Protective Measures

We use appropriate technical and organisational measures to ensure the security and confidentiality of your personal data. These measures serve to protect against unauthorised access, manipulation, loss or misuse. Our security precautions are regularly reviewed and adapted to the state of the art and current industry standards.

‍

Please note that despite extensive protective measures, data transmission over the internet can fundamentally have security vulnerabilities. In particular, with unencrypted communication (e.g. standard email), there is a risk that data may be read by third parties. We have no influence over the behaviour of external parties. We therefore recommend using encryption or other protective measures when transmitting sensitive information electronically in order to minimise potential risks.

‍

8. Retention period and deletion/blocking of data

Personal data is deleted or blocked as soon as the purpose of storage no longer applies. Storage beyond this only takes place if this is required by Union or national law to which the Controller is subject. Data is also deleted or blocked as soon as a statutory retention period expires, provided that further storage is not required for the fulfilment of a contractual relationship.

‍

9. Data Subject Rights

You have the following rights with regard to your personal data:

‍

  1. Right of access (Art. 15 GDPR, § 34 BDSG): You may request information regarding whether and which of your personal data we process, the purpose of the processing, the recipients or categories of recipients to whom the data is disclosed, and the duration for which the data is stored.‍
  2. Right to rectification (Art. 16 GDPR): You may demand the immediate correction of inaccurate personal data or the completion of incomplete data.‍
  3. ‍Right to erasure (Art. 17 GDPR): You may request the deletion of your personal data, particularly if it is no longer necessary, if you have withdrawn your consent, or if the data has been processed unlawfully.‍
  4. Right to restriction of processing (Art. 18 GDPR): You may request the restriction of your data processing, for example, if the accuracy of the data is contested.‍
  5. Right to data portability (Art. 20 GDPR): You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, or—where technically feasible—to request its transfer to another controller.‍
  6. Right to withdraw consent (Art. 7(3) GDPR): You may withdraw your consent at any time, effective for the future. The lawfulness of processing prior to withdrawal remains unaffected.
  7. Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority if you are of the opinion that the processing of your personal data violates data protection provisions.

Right to object (Art. 21 GDPR): You can object at any time to the processing of your personal data on grounds relating to your particular situation, in particular in connection with direct marketing or associated profiling.

‍

Hamburg, June 2026

Logo Handwerkersoftware plancraft
Less Office. More Craft.
+49 40 32 89 02 43 0

Mo - Fr 9am to 6pm

Facebook LoogInstagram LogoLinkedIn LogoYoutube LogoIcon von TikTok
Learn more
PricingProduct updatesCorporate PartnersCreatorPartner BusinessesFor master studentsFor business founders
Comparison
plancraft vs. Traditional Softwareplancraft vs. Word/Excelplancraft vs. HERO softwareSwitching Bonus
Company
About usCareersEventswebinarPressNewsletters
Support & Help
Book a DemoFAQHelp CenterContact

Made with 💚 in 🇩🇪

English
German
English
German (Austria)
Dutch (Netherlands)
Italian (Italy)
Spanish (Spain)
© plancraft 2026
ImprintPrivacy PolicyTerms & Conditions