Privacy Policy
Last updated: April 2026
Privacy Policy for the content and functions
of the SaaS platform „Humane Plus“
(hereinafter „Services“)
Last updated: April 2026
Introduction
Privacy policies are often hard to read. We understand that. And we would like to do it differently. With our privacy policy we would like to give users an easily understandable explanation of the manner in which we process personal data. To this end we structure our privacy policy clearly for users and show users, for each subject area, whether and how we process users' personal data.
In this privacy policy we explain to users whether and how we process personal data. In doing so we set out for users all processing operations that are carried out by us, by third-party services commissioned or integrated by us, or by other third parties on our behalf in the context of the use of our software, our social media profiles and the functions available in each case, as well as in the context of the performance of our contractual relationship (hereinafter also referred to collectively as „Services“).
Table of contents
Our privacy policy is structured as follows
General information - Brief introduction to the subject matter of the privacy policy, to the controller and to the data protection officer
General information on data processing - Information on what personal data is, on what legal basis we process it or also share it with third parties
Data subject rights - Information on users' rights to, among other things, access, erasure or objection to our data processing
Information on the cookies and other technologies used - Information on the use of cookies and other technologies with or by means of which we process users' personal data
Data processing in connection with the use of our Services - Information on our data processing within our Services themselves
Communication Services - Information on services for communication and on the corresponding processing of personal data
Payment processing - Information on the processing of payments with the integration of payment service providers and the processing of personal data resulting from this
Provision of our Services - Information on hosting service providers and the services used by them
Tracking & Tools - Information on services by means of which we provide our Services to users and by means of which we analyse the use of our Services
Transactional mails - Information on the integration of mailing service providers with which we implement transactional mailings
Newsletter - Information on the integration of newsletter services by means of which we provide users with regular information about our services
Profiles on social media - Information on our presences on social media networks and on the processing of personal data resulting from this
1. General information
The protection of personal data and of privacy is extremely important to us. For this reason we would like to offer users comprehensive transparency regarding the processing of personal data (GDPR) as well as regarding the storage of information on the user's terminal equipment (TDDDG, German Telecommunications Digital Services Data Protection Act). Because only if the processing of personal data and information is comprehensible for users as data subjects are they sufficiently informed about the scope, the purposes and the benefits of the processing.
This privacy policy applies to all processing of personal data carried out by us as well as to the storage of information on terminal equipment. It therefore applies to users both in the context of the provision of services within our Services and within external online presences, such as our social media profiles.
The controller within the meaning of the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and other data protection law requirements is
Humane Plus UG (haftungsbeschränkt)
Lagerplatzstraße 4
36391 Sinntal
E-Mail: gethumaneplus@gmail.com
Telephone: +49-174-9590539
Hereinafter referred to as „controller“ or „we“.
2. General information on data processing
First of all we would like to give users introductory information on what the protection of personal data means, what personal data is, how we process it and what security measures we apply in this respect.
Humane Plus is an AI-supported customer support automation platform for e-commerce merchants in the DACH region. The platform receives merchants' incoming customer e-mails via a Postmark inbound forwarding, automatically links them with order data from the respective Shopify shop and, on the basis of OpenAI language models, generates contextually accurate reply suggestions. The merchant decides for themselves whether they approve each reply manually (human-in-the-loop mode) or activate fully automatic sending.
2.1 Processing of personal data
Personal data (hereinafter also „data“) are individual particulars concerning the personal or factual circumstances of an identified or identifiable natural person.
Individual particulars concerning personal or factual circumstances are, for example, the following data, whereby it is clarified that not all of this data must also be processed by our Services:
Personal details - name, age, marital status, date of birth
Communication data - postal address, telephone number, e-mail address
Account data - account number, credit card number
Geodata - IP address & location data
The „processing“ of personal data includes, for example, the following measures:
Collection - The collection of data via contact forms, by e-mail or through processes and services used by us
Transmission - The transmission of data to our service providers, integrated services or other third parties
Storage - The storage of data in our databases or on our servers
Alteration - The alteration of data due to changes of the name, the place of residence or of details in our Services
Erasure - The erasure of data when we no longer have any authorisation to process it
2.2 Legal bases for the processing of personal data
We process personal data only within the legally permissible limits. This is already required of us by law. In particular by the GDPR. Under it we are obliged always to be able to base data processing operations on a legal basis. These legal bases are laid down in Art. 6(1) GDPR. In the following we name all legal bases on which we base a processing of personal data.
Consent - Art. 6(1)(a) GDPR: Data is processed if users have actively consented to this processing, after having previously been sufficiently informed by us about its scope and purposes, i.e. for example by an „opt-in“. Should users withdraw their consent or not have granted it, we do not (any longer) process our users' data for purposes for which we require consent.
For the performance of a contract - Art. 6(1)(b): Data is processed if it is necessary for the performance of a contract between us or for the implementation of pre-contractual measures. Where the processing is no longer necessary for the performance of the contract, we no longer process users' personal data.
Compliance with a legal obligation . Art. 6(1)(c) GDPR: Data is processed if this processing is necessary for compliance with a legal obligation to which we as controller are subject.
Legitimate interest - Art. 6(1)(f) GDPR: Data is processed if this is necessary for safeguarding a legitimate interest on our side and if the users' interests or fundamental rights and freedoms concerning the protection of data do not override it.
Personal data is processed by us only for specified purposes (Art. 5(1)(b) GDPR). As soon as the purpose of the processing ceases to apply, users' personal data is erased or protected by technical and organisational measures (e.g. by pseudonymisation).
The same applies to the expiry of a prescribed storage period, subject to the cases in which further storage is necessary for the conclusion or performance of a contract. In addition, a statutory obligation to store data for a longer period or to pass it on to third parties (in particular to law enforcement authorities) may arise. In other cases the storage period and the type of the data collected as well as the type of the data processing depend on which functions the user uses in the individual case. We will gladly provide users with information about this in the individual case as well, pursuant to Art. 15 GDPR.
2.3 We process these categories of data
Categories of data are in particular the following data:
Master data (e.g. names, addresses, dates of birth),
Contact data (e.g. e-mail addresses, telephone numbers, messenger services),
Content data (e.g. text entries, photographs, videos, contents of documents/files),
Contract data (e.g. subject matter of the contract, terms, customer category),
Payment data (e.g. bank details, payment history, use of other payment service providers),
Usage data (e.g. history within our Services, use of certain content, access times),
Connection data (e.g. device information, IP addresses, URL referrer).
2.4 We take these security measures
In accordance with the statutory requirements and taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of the processing as well as the varying likelihood of occurrence and severity of the threat to rights and freedoms, we take appropriate technical and organisational measures in order to ensure a level of protection appropriate to the risk.
The measures include in particular ensuring that our users' data is stored and processed confidentially, with integrity and available at all times. Furthermore, controls of the access to data as well as of retrieval, input, disclosure, safeguarding availability and its separation from data of other natural persons are among the security measures we implement. In addition we have established procedures which ensure the exercise of data subject rights (see under section 3), the erasure of data and reactions in the event of a threat to our users' data. Furthermore we already take the protection of personal data into account during the development of our software as well as through procedures which correspond to the principle of data protection by design and by default.
2.5 This is how we transmit or disclose personal data to third parties
In the context of our processing measures relating to personal data it happens that this data is transmitted or disclosed to other bodies, companies, legally independent organisational units or persons. These third parties may include, for example, payment institutions in the context of payment transactions, service providers commissioned with IT tasks or providers of services and content which we have integrated into our Services. Should we transmit or disclose users' personal data to third parties, we observe the statutory requirements and in particular conclude corresponding contracts or agreements serving the protection of data with the recipients of the data.
2.6 This is how a transfer to a third country takes place
Should it be stated in this privacy policy that we transfer users' personal data to a third country, i.e. a country outside the EU or outside the EEA, the following applies. A transfer to a third country takes place only in accordance with the statutory requirements. We assure users that we have a contractual or statutory authorisation for the transfer and processing of data in the third country concerned. In addition, we have our users' data processed only by service providers in third countries which in our view have a recognised level of data protection. This means that, for example, a corresponding adequacy decision exists between the EU and the country to which we transfer users' personal data. An „adequacy decision“ is a decision adopted by the European Commission pursuant to Art. 45 GDPR by which it is determined that a third country (i.e. a country not bound by the GDPR) or an international organisation offers an adequate level of protection for personal data. Alternatively, i.e. for example if there is no adequacy decision, a transfer to a third country takes place only if, for instance, contractual obligations exist between us and the service provider in the third country by way of so-called standard contractual clauses of the EU Commission and further technical security precautions have been taken which guarantee a level of protection appropriately equivalent to that in the EU, or the service provider in the third country can demonstrate data protection certifications and our users' data is processed only in accordance with internal data protection rules (Art. 44 to 49 GDPR. Information page of the EU Commission: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de).
Within the framework of the so-called „Data Privacy Framework” („DPF“), the EU Commission has recognised the level of data protection for certain companies from the USA as secure within the framework of the adequacy decision of 10.07.2023. Users can find a list of the certified companies as well as further information on the DPF on the website of the U.S. Department of Commerce at https://www.dataprivacyframework.gov/ (in English). Within the framework of this privacy policy we inform users which of the services used by us are certified under the Data Privacy Framework.
Please note: Certification under the EU-US Data Privacy Framework (DPF) is company-specific and can change at any time. We regularly check whether the US service providers used by us are certified under the DPF at the time of the respective data processing. The list of certified companies as currently applicable can be accessed at: https://www.dataprivacyframework.gov/list.
Where a service provider used by us is not (or no longer) certified under the DPF, a transfer of personal data takes place exclusively on the basis of the standard contractual clauses of the EU Commission as well as supplementary technical and organisational measures.
2.7 Erasure of data
The data processed by us is erased in accordance with the statutory requirements as soon as the consents permitting its processing are withdrawn or other permissions cease to apply (e.g. if the purpose of processing this data has ceased to apply or it is not necessary for the purpose). Where the data is not erased because it is necessary for other and legally permissible purposes, its processing is restricted to those purposes. That is to say, the data is blocked and not processed for other purposes. This applies, for example, to data which must be retained for commercial law or tax law reasons or the storage of which is necessary for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person.
Within the framework of this privacy policy we provide information, where applicable, on the erasure as well as on the retention of data which apply specifically to the respective processing operations.
2.8 Storage of and access to data on the user's terminal equipment
Insofar as we do not obtain consent from users, the storage of or the access to information on the user's terminal equipment takes place pursuant to § 25(2) no. 2 of the Act on Data Protection and the Protection of Privacy in Telecommunications and Digital Services (TDDDG), since the storage of and the access to this information is strictly necessary in order to provide the desired functions of our Services. Insofar as we obtain consent for this, the legal basis is § 25(1) TDDDG. Our Services use cookies, tokens or other technologies which may be stored on terminal equipment and without which the provision of our Services would not be possible.
Cookies, tokens or other technologies are as a rule text files which are stored on the user's terminal equipment and which can be read out by us and third parties when our Services are accessed. Many of the aforementioned technologies contain their own ID. Such an ID is a unique identifier of the technology used in each case. It consists of a character string by which websites and servers can be assigned to the specific internet browser or the specific service or terminal equipment used in which cookies, tokens or other technologies have been stored. This makes it possible for the operators of websites and analysis services to identify users as users and to distinguish them from others.
2.9 Processing on behalf of a controller
Should we make use of external service providers for the processing of data, these are carefully selected and commissioned by us. Should the services which these service providers provide constitute processing on behalf of a controller within the meaning of Art. 28 GDPR, the service providers are bound by our instructions and are checked regularly. In this respect our data processing agreements (Auftragsverarbeitungsverträge) comply with the strict requirements of Art. 28 GDPR as well as with the requirements of the German data protection authorities.
3. Data subject rights
If our users' personal data is processed, they are data subjects within the meaning of the GDPR and users, as users, have the following rights vis-à-vis the controller:
3.1 Right of access
Users may request confirmation from the controller as to whether personal data concerning the users is being processed by us.
If such processing is taking place, users may request access from the controller to the following information:
the purposes for which the personal data is processed;
the categories of personal data which are processed;
the recipients or the categories of recipients to whom the personal data concerning the users has been or will still be disclosed;
the envisaged period for which the personal data concerning the users will be stored or, if specific information on this is not possible, criteria for determining the storage period;
the existence of a right to rectification or erasure of the personal data concerning the users, of a right to restriction of processing by the controller or of a right to object to this processing;
the existence of a right to lodge a complaint with a supervisory authority;
all available information on the origin of the data if the personal data is not collected from the data subject;
the existence of automated decision-making including profiling pursuant to Art. 22(1) and (4) GDPR and – at least in these cases – meaningful information about the logic involved as well as the significance and the envisaged consequences of such processing for the data subject.
Users have the right to request information as to whether the personal data concerning the users is transferred to a third country or to an international organisation. In this connection users may request to be informed of the appropriate safeguards pursuant to Art. 46 GDPR in connection with the transfer.
3.2 Right to rectification
Users have a right to rectification and/or completion vis-à-vis the controller if the processed personal data concerning the users is inaccurate or incomplete. The controller must carry out the rectification without undue delay.
3.3 Right to restriction of processing
Under the following conditions users may request the restriction of the processing of the personal data concerning the users:
if users contest the accuracy of the personal data concerning the users for a period enabling the controller to verify the accuracy of the personal data;
the processing is unlawful and users oppose the erasure of the personal data and instead request the restriction of the use of the personal data;
the controller no longer needs the personal data for the purposes of the processing, but users need it for the establishment, exercise or defence of legal claims, or
if users have objected to the processing pursuant to Art. 21(1) GDPR and it is not yet established whether the legitimate grounds of the controller override the users' grounds.
Where the processing of the personal data concerning the users has been restricted, such data may – apart from its storage – only be processed with a consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of an important public interest of the Union or of a Member State.
Where the restriction of processing has been restricted under the above conditions, users will be informed by the controller before the restriction is lifted.
3.4 Right to erasure
3.4.1. Users may request the controller to erase the personal data concerning the users without undue delay, and the controller is obliged to erase this data without undue delay if one of the following grounds applies:
The personal data concerning the users is no longer necessary for the purposes for which it was collected or otherwise processed.
Users withdraw a consent on which the processing was based pursuant to Art. 6(1)(a) or Art. 9(2)(a) GDPR, and there is no other legal basis for the processing.
Users object to the processing pursuant to Art. 21(1) GDPR and there are no overriding legitimate grounds for the processing, or users object to the processing pursuant to Art. 21(2) GDPR.
The personal data concerning the users has been unlawfully processed.
The erasure of the personal data concerning the users is necessary for compliance with a legal obligation under Union law or the law of the Member States to which the controller is subject.
The personal data concerning the users was collected in relation to information society services offered pursuant to Art. 8(1) GDPR.
3.4.2. If the controller has made the personal data concerning the users public and is obliged pursuant to Art. 17(1) GDPR to erase it, it shall, taking account of available technology and the cost of implementation, take reasonable steps, including of a technical nature, to inform controllers which process the personal data that users as data subjects have requested the erasure by them of any links to, or copies or replications of, that personal data.
3.4.3. The right to erasure does not exist insofar as the processing is necessary
for exercising the right of freedom of expression and information;
for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
for reasons of public interest in the area of public health pursuant to Art. 9(2)(h) and (i) as well as Art. 9(3) GDPR;
for archiving purposes in the public interest, scientific or historical research purposes or for statistical purposes pursuant to Art. 89(1) GDPR, insofar as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing, or
for the establishment, exercise or defence of legal claims.
3.5 Right to be informed
If users have asserted the right to rectification, erasure or restriction of processing vis-à-vis the controller, the latter is obliged to communicate this rectification or erasure of the data or restriction of processing to all recipients to whom the personal data concerning the users has been disclosed, unless this proves impossible or involves disproportionate effort.
Users have the right vis-à-vis the controller to be informed about these recipients.
3.6 Right to data portability
Users have the right to receive the personal data concerning the users which users have provided to the controller in a structured, commonly used and machine-readable format. In addition, users have the right to transmit this data to another controller without hindrance from the controller to which the personal data was provided, provided that the processing is based on a consent pursuant to Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR or on a contract pursuant to Art. 6(1)(b) GDPR and the processing is carried out by automated means.
In exercising this right users furthermore have the right to obtain that the personal data concerning the users is transmitted directly from one controller to another controller, insofar as this is technically feasible. Freedoms and rights of other persons must not be adversely affected thereby.
The right to data portability does not apply to processing of personal data which is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
3.7 Right to object
Users have the right to object at any time, on grounds relating to their particular situation, to the processing of the personal data concerning the users which is carried out on the basis of Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions.
The controller will no longer process the personal data concerning the users unless it can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of our users, or the processing serves the establishment, exercise or defence of legal claims.
Where the personal data concerning the users is processed for the purposes of direct marketing, users have the right to object at any time to the processing of the personal data concerning the users for the purposes of such marketing; this also applies to profiling insofar as it is connected with such direct marketing.
If users object to the processing for the purposes of direct marketing, the personal data concerning the users will no longer be processed for these purposes.
Users have the possibility, in connection with the use of information society services – notwithstanding Directive 2002/58/EC – to exercise the right to object by automated means using technical specifications.
3.8 Right to withdraw the data protection consent declaration
Users have the right to withdraw a data protection consent declaration at any time. The withdrawal of the consent does not affect the lawfulness of the processing carried out on the basis of the consent up to the withdrawal. The processing is lawful until a withdrawal – the withdrawal therefore takes effect only in relation to the processing after receipt of the withdrawal. Users may declare the withdrawal informally by post or e-mail. The processing of personal data then no longer takes place, subject to it being permitted by another legal basis. If this is not the case, our users' data must be erased without undue delay after the withdrawal pursuant to Art. 17(2) GDPR. The right to withdraw a consent subject to the above conditions is guaranteed.
The withdrawal is to be addressed to:
Humane Plus UG (haftungsbeschränkt)
Lagerplatzstraße 4
36391 Sinntal
E-Mail: gethumaneplus@gmail.com
Telephone: +49-174-9590539
3.9 Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, users have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their place of residence, their place of work or the place of the alleged infringement, if users are of the opinion that the processing of the personal data concerning the users infringes the GDPR.
The supervisory authority with which the complaint has been lodged informs the complainant of the status and the outcome of the complaint, including the possibility of a judicial remedy pursuant to Art. 78 GDPR.
3.10 Automated individual decision-making, including profiling
Automated individual decision-making within the meaning of Art. 22 GDPR does not take place. However, in individual areas we use automated procedures in order to structure or optimise content, communication or processes (e.g. statistical evaluations, AI-supported reply suggestions). These procedures do not produce legal effects vis-à-vis users and do not similarly significantly affect them.
3.11 Notification obligations of the controller
Should users' personal data have been disclosed to other recipients (third parties) on a legal basis, we notify them of every rectification, erasure or restriction of the processing of personal data (Art. 16, Art. 17(1) and Art. 18 GDPR). The notification obligation ceases to apply if it involves disproportionate effort or is impossible. We furthermore inform users about the recipients upon request.
4. Information on the cookies and other technologies used
4.1 Cookies
We use cookies or other technologies in order to provide our Services. Cookies are, for example, small text files which contain data from visited websites or domains and which are stored on a device (computer, tablet or smartphone). If users access a website, the cookie stored on a device sends information to the party which placed the cookie.
4.2 This is how we use cookies and other technologies
At present we use exclusively functional cookies. However, we would like users to be in a position to make an informed decision for or against the use of cookies and other technologies which are not strictly necessary for the technical characteristics of the Services. Should we use cookies and other technologies which require consent, we enable users, by way of a voluntary decision on their first visit to our Services and thereafter permanently in corresponding settings, to choose which cookies and other technologies users allow. In this respect it always applies that functional cookies and other technologies are mandatory for visiting our Services and are therefore already allowed via our default settings. Statistics and marketing cookies and other technologies are optional. Users can allow them by consenting accordingly in the consent banner to the setting of these cookies and other technologies. Alternatively users can reject statistics and marketing cookies and other technologies.
5. Data processing in connection with the use of our Services
The use of our Services with all their functions goes hand in hand with the processing of personal data. We explain to users here exactly how this happens.
5.1 Registration
In order to be able to use our Services, users have the possibility of registering for this purpose. In this respect we process in particular master data and contact data such as, for example, the name, the e-mail address and the password. In addition we automatically process in this respect connection data such as, for example, date, device information and IP address. For the registration we use the authentication service „Clerk“, which is provided by Clerk Inc., 101 S Reid St, Palatine, IL 60067, USA. Since the use of Clerk results in data being transferred to a third country (in particular the USA), this takes place on the basis of a data processing agreement (Auftragsverarbeitungsvertrag) concluded with Clerk and in accordance with standard contractual clauses agreed with Clerk and other security measures permitted by the GDPR which ensure the security of the processing of our users' personal data with a level of protection identical to that in the EU, as well as in particular on the basis of the EU-US Data Privacy Framework (DPF).
Some processing steps may also take place at third-party providers. The data processing by the third-party providers takes place on the terms of the respectively applicable privacy policies. In the case of a data processing with third-party providers, this may constitute processing on behalf of a controller within the meaning of Art. 28 GDPR. This is subject to strict statutory requirements which we comply with in the course of our contractual agreements with our processors.
The use during or after registration and login has taken place and the data processing operations connected with it may differ from purely informational use. The collection of this data connected with a profile takes place for the purpose of verifying the status and the related fulfilment of our contractual obligations vis-à-vis users. These are legitimate purposes pursuant to Art. 6(1)(b) GDPR. Should a consent be necessary for the processing operation, we will obtain it at the appropriate place (for example via the opt-in possibility within the framework of a consent banner on the first use of our Service). For further questions we are gladly at users' disposal within the framework of the right of access pursuant to Art. 15(1) GDPR. The use of Clerk as an authentication service in the context of registration is necessary for ensuring the security of our information technology systems. Herein at the same time lies our legitimate interest, which is why the processing is also lawful pursuant to Art. 6(1)(f) GDPR
5.2 Connection of the Shopify account
After registration has taken place, users can connect their Shopify account with our Services in order to make use of our Services and their functions. If users do this, the personal data processed by them there is transmitted to us and stored in our information technology systems. In particular, Shopify order data, end customer data (name, e-mail, shipping address) and product information are retrieved and processed temporarily on our servers in order to link incoming support enquiries with the correct order context.
The processing operations connected with the connection of the Shopify account serve the purpose of being able to assign future order transactions and end customer communications between users and end customers and of being able to access the entire offering of our Services. The processing of data therefore serves the performance of the contract, is thus purpose-bound and necessary pursuant to Art. 6(1)(b) GDPR.
The storage of the personal data entered by users and their end customers takes place until the point in time at which this data is erased within the user account or at the latest until the complete erasure of the user account with us. Contrary to this, we process certain personal data of users only insofar as we have a statutory or contractual authorisation for this. This is the case, for example, if we may retain contract or payment data even after erasure of the user account for accounting or other reasons which are necessary for the proper settlement of our contractual relationship.
5.3 Sign-on & Google OAuth
In order to be able to use some or all of our Services, users must first log in, should this be necessary for the use. We then create a user profile to which the specific information provided by users can be assigned. Various possibilities are open to users for logging in. Users can log in with an e-mail address. To handle the login process we use Google OAuth. The recipient of the data is Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland. Should Google transfer this data to a third country (for example the USA), this takes place only in the individual case, on the basis of a data processing agreement (Auftragsverarbeitungsvertrag) concluded with Google and in accordance with standard contractual clauses agreed with Google and other security measures permitted by the GDPR which ensure the security of the processing of personal data with a level of protection identical to that in the EU, in particular on the basis of the EU-US Data Privacy Framework (DPF). This data processing is necessary for the initiation of the contract as well as for the performance of the contract in accordance with the login procedure chosen by users. The legal basis for the data processing is therefore Art. 6(1)(b) GDPR.
5.4 Functions of our Services
Depending on a registration or also purely informational use of our Services, users have available to them, among other things, the functions listed below. We provide all of the functions listed below to users so that they can make full use of the scope of our Services, depending on the model booked, and so that we can achieve the best result for them in our cooperation. We pass on the data entered by users only to authorised third parties and process it for the fulfilment of the contractual relationships entered into with users, in particular for the fulfilment of the usage contract which users have concluded through the use of our Services. The legal basis for the processing of data therefore results from Art. 6(1)(b) GDPR.
Ticket management and communication hub
All incoming support enquiries from our users' end customers are stored and managed as „tickets“ in our Services. Users can view, edit and categorise tickets and approve or reject replies. Ticket histories including communication history are retained for 3 years after closure.
Automatic e-mail receipt & dispatch
Approved or automatically sent replies from users to their end customers are sent via the SMTP server configured by users or preferably via the connected Postmark DNS. In this respect master data, contract data, content data or also connection data may be processed. For the receipt as well as for the dispatch and forwarding of the e-mails we use the service „Postmark“ of Postmark (ActiveCampaign, LLC), 1 N Dearborn St, Chicago, IL 60602, USA. Users' incoming end customer e-mails are received via a Postmark inbound forwarding and are automatically created as tickets in our Services. For this purpose users set up a forwarding of their support e-mail address to an inbound address generated in our Services. Should Postmark transfer data to a third country (for example the USA), this takes place on the basis of a data processing agreement (Auftragsverarbeitungsvertrag) concluded with Postmark and in accordance with standard contractual clauses agreed with Postmark and other security measures permitted by the GDPR which ensure the security of the processing of our users' personal data with a level of protection identical to that in the EU, and, insofar as a data transfer to the USA takes place, in particular on the basis of the EU-US Data Privacy Framework (DPF).
5.5 Artificial intelligence
In our Services we use artificial intelligence services („AI services“). The AI services here offer us the possibility of providing our Services with a state of the art quality and an individual precision which is particularly valuable for our relationship with one another. With the AI services we can provide users, within the framework of the data processing for the provision of our Services, with an intelligent system which processes all interactions in our Services into which the AI services are integrated in the most efficient and, for users, most useful manner. We use integrated services among other things for the following functions:
Semantic analysis and categorisation of incoming customer e-mails,
Generation of contextually accurate reply suggestions on the basis of the merchant prompt and Shopify order data,
Internal quality scoring of every generated reply before dispatch, as well as
Support in improving the customer prompt through analysis of sample e-mails.
The categories of data processed here are master data, contact data, content data, where applicable usage data, connection data and where applicable contract data. The recipients of the data here are the providers of AI services integrated by us and named below. Should these AI services transfer data to a third country (for example the USA), this takes place on the basis of a data processing agreement (Auftragsverarbeitungsvertrag) concluded with them and in accordance with standard contractual clauses agreed with them and other security measures permitted by the GDPR which ensure the security of the processing of our users' personal data with a level of protection identical to that in the EU, and, insofar as a data transfer to the USA takes place, in particular on the basis of the EU-US Data Privacy Framework (DPF). The AI services used by us process personal data exclusively for the provision of the functions requested by users. Our legal basis for the use of AI services results from Art. 6(1)(b) GDPR (performance of a contract). Our entire service is based on AI services supporting various functionalities and thereby greatly simplifying users' work. We therefore use the AI services for the automation and quality enhancement of our users' communication with their end customers in e-commerce customer support. The aim of using AI services is to be able to answer 80–90% of our users' incoming support tickets without extensive manual processing by our users. The interests of users in controlling and withholding their data are not thereby adversely affected to such an extent that these interests override the legitimate interest on our side in using the AI services. The AI services selected by us have their seat in the EU or in a third country for which an adequacy decision of the EU applies. The AI services selected by us may not also process input data for AI training purposes. Such processing is technically prevented or has been objected to by a corresponding setting. A data processing agreement (Auftragsverarbeitungsvertrag) pursuant to Art. 28 GDPR for the protection of personal data has been concluded with the AI services selected by us.
Providers of the AI services used by us
OpenAI
OpenAI Ireland Limited
1st Floor
The Liffey Trust Centre
117-126 Sheriff Street Upper
Dublin 1
D01 YC43
Ireland
https://openai.com/de-DE/policies/eu-privacy-policy/
6. Communication Services
6.1 Contact form / contact by e-mail
We process users' personal data which users make available to us in the context of making contact for the purpose of answering an enquiry, an e-mail or a request for a call back. The categories of data processed here are master data, contact data, content data, where applicable usage data, connection data and where applicable contract data. In the individual case we pass this data on to companies affiliated with us, or third parties which may process this data as agreed for the handling of orders and bookings. The legal basis of the processing depends on the purpose of making contact. With an enquiry in the contact form or by making contact by e-mail, users declare that they wish to receive answers or information on certain topics. For this purpose users also leave their data. We answer an enquiry as requested and process our users' data for this purpose. The authorisation for the processing of data therefore is based on Art. 6(1)(b) GDPR, since we process it in order to answer an enquiry and thus for the performance of the contract regarding this.
6.2 Support enquiry
We process users' personal data which users make available to us in the context of submitting support enquiries for the implementation of the support enquiry such as, for example, for remedying malfunctions or errors. The categories of data processed here are master data, contact data, content data, where applicable usage data, connection data and where applicable contract data. In the individual case we pass this data on to companies affiliated with us, or third parties which we engage for remedying malfunctions or errors in our Services. The legal basis of the processing depends on the purpose of the support enquiry. With the support enquiry users declare that they wish, for example, for malfunctions or errors to be remedied. We record this information and process our users' data for this purpose. The authorisation for the processing of data therefore is based on Art. 6(1)(b) GDPR for the performance of the contract.
7. Payment processing
For the settlement of payment claims we offer various payment methods. For this purpose we integrate the payment service providers described below. We do this for the purpose of the proper provision of our services as required. The data processed in this connection is usage data, connection data, master data, payment data, contact data or also contract data, such as e.g. account numbers or credit card numbers, passwords, TANs and checksums as well as the contract-, sum- and recipient-related particulars. The particulars are necessary in order to carry out the transactions. The data entered is processed only by the payment service providers and stored with them. We do not receive any account- or credit card-related information, but only information about the confirmation or a negative notification of the payment. Under certain circumstances our users' data is transmitted by the payment service providers to credit agencies. The purpose of this transmission is the checking of identity and creditworthiness. In this respect we refer to the general terms and conditions and the data protection notices of the payment service providers. The legal basis for the use of the payment service providers results from Art. 6(1)(b) GDPR. We can provide the services promised to users with our Services and thus the fulfilment of our contractual obligations only if we make use of third parties, such as the payment service providers, for the handling of payment transactions. Should a payment service provider transfer data to a third country (for example the USA), this takes place only in the individual case, on the basis of a data processing agreement (Auftragsverarbeitungsvertrag) concluded with them and in accordance with standard contractual clauses agreed with them and other security measures permitted by the GDPR which ensure the security of the processing of personal data with a level of protection identical to that in the EU, in particular on the basis of the EU-US Data Privacy Framework (DPF).
Payment service providers
The payment service providers integrated by us are:
Stripe
If users decide on a payment method of the payment service provider Stripe, the payment is processed via the payment service provider Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, to whom we pass on the information communicated in the context of the order process together with the information about an order (name, address, account number, bank sort code, possibly credit card number, invoice amount, currency and transaction number) pursuant to Art. 6(1)(b) GDPR. Further information on data protection at Stripe at the URL https://stripe.com/de/privacy#translation.
Stripe reserves the right to carry out a creditworthiness check on the basis of mathematical-statistical procedures in order to safeguard the legitimate interest in establishing the user's ability to pay. Stripe transmits the personal data necessary for a creditworthiness check and received in the context of the payment processing, where applicable, to selected credit agencies, which Stripe discloses to users upon request. The credit report may contain probability values (so-called score values). Insofar as score values are incorporated into the result of the credit report, these have their basis in a scientifically recognised mathematical-statistical procedure. Among other things, but not exclusively, address data is incorporated into the calculation of the score values. Stripe uses the result of the creditworthiness check with regard to the statistical probability of payment default for the purpose of deciding on the eligibility to use the selected payment method.
Users can object to this processing of data at any time by a message to Stripe or the commissioned credit agencies.
However, Stripe may where applicable continue to be entitled to process users' personal data insofar as this is necessary for the contractual processing of payments.
8. Hosting
8.1 Provision of our Services
In order to be able to provide our Services to users, we make use of the services of the hosting providers named below. Our Services are accessed from the servers of these hosting providers. For these purposes we make use of the infrastructure and platform services, computing capacity, storage space and database services as well as security services and technical maintenance services of the hosting providers.
The data processed includes all such data which users enter in the context of the use and communication in connection with their visit to our Services or which is collected from users in this respect (for example IP address). Our legal basis for the use of the hosting providers for the provision of our Services results from Art. 6(1)(f) GDPR (legitimate interest).
8.2 Collection of access data and log files
We ourselves (or the hosting providers) collect data on every access to the server (server log files). The server log files may include the address and name of the Services and files accessed, the date and time of access, the volumes of data transferred, a message about successful access, the type of device together with version, operating system, referrer URL (the previously visited page) and as a rule IP addresses as well as the requesting provider.
The server log files can be used on the one hand for security purposes, e.g. in order to avoid an overloading of the servers (in particular in the case of abusive attacks, so-called DDoS attacks) and on the other hand in order to ensure the utilisation of the servers and their stability. Our legal basis for the use of a hosting provider for the collection of access data and log files results from Art. 6(1)(f) GDPR (legitimate interest).
The hosting providers used by us are the following:
Contabo GmbH
Aschauer Straße 32a
81549 München
Germany
netcup GmbH
Emmy-Noether-Str. 10
76131 Karlsruhe
9. Tracking & Tools
In order to ensure a smooth technical process and an optimal user-friendly use of our Services, we use the following services:
Microsoft Clarity
We use Microsoft Clarity for the purpose of the statistical evaluation of the use of our Services. In this respect Clarity records in particular mouse movements and creates a graphical representation of the part of the Services on which users scroll particularly frequently (heatmaps). Clarity can furthermore record sessions, so that we can view the page usage in the form of videos. Furthermore we receive particulars about general user behaviour within our Services. Clarity uses technologies which enable the recognition of the user for the purpose of analysing user behaviour (e.g. cookies or the use of device fingerprinting). The data processed is usage data & connection data. The recipient of the data here is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland. Should Microsoft transfer this data to a third country (for example the USA), this takes place only in the individual case, on the basis of a data processing agreement (Auftragsverarbeitungsvertrag) concluded with Microsoft and in accordance with standard contractual clauses agreed with Microsoft and other security measures permitted by the GDPR which ensure the security of the processing of personal data with a level of protection identical to that in the EU, in particular on the basis of the EU-US Data Privacy Framework (DPF). The legal basis for the use of Microsoft Clarity is a consent (for example via an opt-in in the consent banner), insofar as users have granted it to us in the context of the visit to our Services, and therefore results from Art. 6(1)(a) GDPR. On the basis of a consent, cookies or similar (text) files are stored on the user's terminal equipment and personal data is thereby read out. Should users not have granted us the consent to use Microsoft Clarity (no opt-in in the consent banner or withdrawal of a consent), we do not (any longer) use Microsoft Clarity in the context of visits to our Services. More information on the data processing at https://privacy.microsoft.com/de-de/privacystatement
10. Transactional mailings
For administrative processes, for the confirmation of actions as well as in the context of our non-promotional customer communication we send transactional notifications (hereinafter „transactional mailings“) to users. Our transactional mailings here contain important administrative information about our Services. For the administration of our transactional mailings as well as for the creation and dispatch of transactional mailings we use the transactional mail services listed below. In the context of users accessing the transactional mailings, technical information, such as information about the browser and about the system, as well as the IP address and the time of access, can be collected. This information is used for the technical tracing of the interaction with our transactional mailings on the basis of the technical data or of the target groups and their reading behaviour. The legal basis for the use of transactional mailings lies in Art. 6(1)(b) GDPR, since with the information in the transactional mailings we fulfil our contractual obligations vis-à-vis users. Should we make use of the services of third-party providers for this purpose, the legal ground for this lies in Art. 6(1)(f) GDPR. We have a legitimate interest in standardising the dispatch of transactional mailings and controlling it collectively. In this respect the interest of users in the most data-minimising processing possible of their data is not unduly adversely affected. Should providers transfer data to a third country (for example the USA), this takes place only in the individual case, on the basis of a data processing agreement (Auftragsverarbeitungsvertrag) concluded with them and in accordance with standard contractual clauses agreed with them and other security measures permitted by the GDPR which ensure the security of the processing of personal data with a level of protection identical to that in the EU, in particular on the basis of the EU-US Data Privacy Framework (DPF).
Providers of the transactional mail services used by us
Postmark
ActiveCampaign, LLC
1 N Dearborn Street, 5th Floor
Chicago, IL 60602
USA
https://www.activecampaign.com/legal/privacy-policy
11. Newsletter dispatch
With a consent (as a rule by subscribing) we send newsletters, e-mails and other electronic notifications (hereinafter „newsletter“) to users. Our newsletters as a rule contain technical, commercial and promotional information about our Services. For the administration of our newsletter subscribers as well as for the creation and dispatch of newsletters we use the newsletter services listed below. For subscribing to our newsletter it is in principle sufficient if users provide an e-mail address. The subscription to our newsletter always takes place in a so-called double opt-in procedure. After subscribing to our newsletter users therefore receive an e-mail in which they are asked to confirm the subscription by clicking a confirmation link. This confirmation is necessary in order to prevent someone else from subscribing to a newsletter with an e-mail address. We log the newsletter subscriptions for the purpose of being able to demonstrate the subscription process in accordance with the legal requirements. For this purpose we store the time of subscription and of confirmation as well as the IP address. Changes to the data stored with the dispatch service provider are likewise logged. Users can unsubscribe from our newsletter at any time. To do so users simply click on the „Unsubscribe“ button which is contained in the footer of every newsletter. Should users unsubscribe from our newsletter, an e-mail address may be stored for up to three years on the basis of our legitimate interests before we erase it, so that we can demonstrate a consent formerly given. Insofar as we commission a service provider with the dispatch of e-mails, this takes place on the basis of our legitimate interests in an efficient and secure dispatch system. Our newsletters may contain a so-called "web beacon“. A web beacon is a pixel-sized file which is retrieved from our server (or, where a dispatch service provider is used, from its server) when the newsletter is opened. In the context of this retrieval, technical information, such as information about the browser and a system, as well as the IP address and the time of retrieval, is first collected.
This information is used for the technical improvement of our newsletter on the basis of the technical data or of the target groups and their reading behaviour on the basis of their places of retrieval (which can be determined with the help of the IP address) or of the access times. This analysis likewise includes establishing whether the newsletters are opened, when they are opened and which links are clicked. For technical reasons this information can indeed be assigned to the individual newsletter recipients. However, it is neither our aim nor, where one is used, that of the dispatch service provider, to observe individual users. Rather, the evaluations serve us in recognising the reading habits of our users and adapting our content to them or sending different content in accordance with the interests of our users.
The evaluation of the newsletter and the measurement of success take place, subject to an express consent of the users, on the basis of our legitimate interests for the purposes of using a user-friendly as well as secure newsletter system which serves both our business interests and corresponds to the expectations of the users.
The legal basis for the dispatch of newsletters and thus also for the use of web beacons is a consent, insofar as users have granted it to us by subscribing to the newsletter, and therefore results from Art. 6(1)(a) GDPR. Should users not have granted us a consent to the dispatch of newsletters, we do not (any longer) send any newsletters to users. This automatically also means that the use of web beacons ceases to apply.
Should we make use of the services of third-party providers for this purpose, the legal ground for this lies in Art. 6(1)(f) GDPR. We have a legitimate interest in standardising the dispatch of newsletters and controlling it collectively. In this respect the interest of users in the most data-minimising processing possible of their data is not unduly adversely affected. Should providers transfer data to a third country (for example the USA), this takes place only in the individual case, on the basis of a data processing agreement (Auftragsverarbeitungsvertrag) concluded with them and in accordance with standard contractual clauses agreed with them and other security measures permitted by the GDPR which ensure the security of the processing of personal data with a level of protection identical to that in the EU, in particular on the basis of the EU-US Data Privacy Framework (DPF).
Providers of the newsletter services used by us
Klaviyo Inc.
125 Summer Street
Boston
MA 02110
USA
12. Profiles on social media websites
We maintain profiles on the platforms of the social networks of the internet and in this context process personal data in order to communicate with the users active there or in order to offer information about us. We point out to users that our users' data may be processed when visiting our profiles outside the area of the European Union. Responsible for this are the operators of the respective social networks. Users can find a detailed presentation of the respective forms of processing and of the possibilities of objection (for example opt-out) in the privacy policies of the operators of the respective social networks.
On visiting our social media profiles, usage behaviour may be evaluated and information obtained from this may be communicated to us („insights“). This evaluation takes place for the purposes of the economic optimisation and needs-based design of our Services. The categories of data processed here are where applicable master data, where applicable contact data, content data, usage data, connection data. The recipient of the data is the provider of the respective social media platform as joint controller pursuant to Art. 26 GDPR. The legal basis for the processing of the data in accordance with the criteria named here results from our legitimate interest and thus from Art. 6(1)(f) GDPR. Responsible for the implementation of data subject rights is the respective social media platform. We provide information about data subject rights below when naming the respective social media platform on which we maintain a profile. Users can also assert their rights vis-à-vis us; we will then forward their enquiry to the operator of the social media platform without delay.
TikTok
tiktok technology limited 10 earlsfort terrace, dublin d02 t380 Ireland. Data subject rights: https://www.tiktok.com/legal/privacy-policy?lang=de-DE.
LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. Data subject rights: https://de.linkedin.com/legal/privacy-policy.