Privacy Policy
Stand: 29.06.2026 Version: v1.3-2026-06-29
1. Controller
The controller within the meaning of the DSGVO (GDPR — General Data Protection Regulation) and other national data protection laws as well as other data protection provisions is:
Digital Consulting EU LLC 2125 Biscayne Blvd, Ste 204 #10182 Miami, FL 33137 USA
Represented by: V. Schneider (Managing Member)
Email: support@kombizent.com Data protection contact: datenschutz@kombizent.com
(hereinafter: "we", "us", "Kombizent" or "Controller")
Applicability of the GDPR: Since our offering is specifically directed at persons in the European Union, the GDPR applies to all processing operations pursuant to Art. 3 (2) GDPR, even though the controller is established outside the EU.
2. Data Protection Officer
Due to the size of our company, we are not obliged to appoint a data protection officer (Art. 37 GDPR). Please direct data protection inquiries to:
Email: datenschutz@kombizent.com
3. Scope of this Policy
This privacy policy applies to:
- the marketing website kombizent.com
- the software application ("Cockpit") at app.kombizent.com
- all associated subdomains and functions
It informs you about the processing of personal data when using these offerings. Personal data is any information relating to an identified or identifiable natural person (Art. 4 No. 1 GDPR).
4. General Information on Data Processing
4.1 Scope of Processing
As a matter of principle, we process personal data of our users only insofar as this is necessary to provide a functional website and our content and services. Processing regularly takes place only with the user's consent or where another legal basis applies.
4.2 Legal Bases
We process personal data on the following legal bases:
- Art. 6 (1) lit. a GDPR — Consent (e.g. newsletter, optional cookies, AI features)
- Art. 6 (1) lit. b GDPR — Performance of a contract (e.g. provision of the SaaS application)
- Art. 6 (1) lit. c GDPR — Legal obligation (e.g. tax/accounting retention)
- Art. 6 (1) lit. f GDPR — Legitimate interest (e.g. server security, abuse prevention)
4.3 Data Erasure and Storage Period
Personal data is erased as soon as the purpose of storage ceases to apply. Storage beyond this only takes place insofar as provided for by statutory retention obligations (e.g. Section 257 HGB (German Commercial Code), Section 147 AO (German Fiscal Code): up to 10 years) or by US law.
4.4 Data Security (Art. 32 GDPR)
We use appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorized access by third parties:
- Encrypted transmission via HTTPS (TLS 1.3)
- Encrypted data storage (AES-256 for sensitive fields, e.g. SMTP credentials)
- Strict access controls (multi-factor authentication for admin access)
- Logical separation of tenant data (row-level security at the database level)
- Regular backups (with encryption at rest)
- Regular security audits (internal and external)
- Pseudonymization where possible
Important regarding data location: All customer and business data is stored exclusively in the European Union (Frankfurt, AWS eu-central-1) via Supabase. The data does not leave the EU, even though the controller is established in the USA.
5. Processing Activities in Detail
5.1 Provision of the Website (Server Log Files)
Description: Each time our website is accessed, data is automatically transmitted from the accessing device to our server and stored in server log files.
Data processed:
- IP address (truncated after 7 days)
- Date and time of the request
- URL/referrer
- HTTP status
- Amount of data transferred
- Browser type and version
- Operating system
- Language
Purpose: Provision of the website, ensuring stability and security, abuse detection
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in error-free provision)
Storage period: 7 days (followed by automatic deletion); in the event of abuse, until the matter is resolved
5.2 Contact Form & Email Contact
Description: When you contact us via the contact form or by email, the data transmitted is stored in order to process the inquiry.
Data processed:
- Name
- Email address
- Company (optional)
- Industry, team size (optional)
- Message content
- Time of the inquiry
Purpose: Processing the inquiry, making contact, potentially initiating a contractual relationship
Legal basis: Art. 6 (1) lit. b GDPR (pre-contractual measures), supplementarily Art. 6 (1) lit. f GDPR
Storage period: Until the inquiry has been dealt with, thereafter 6 months for evidentiary purposes. If a contract is concluded: in accordance with statutory retention periods.
5.3 Newsletter Distribution
Description: On our website you can subscribe to a free newsletter. Registration takes place via a double opt-in procedure.
Data processed:
- Email address
- Registration IP address (hashed)
- Time of registration
- Confirmation IP address (DOI click, hashed)
- Time of confirmation
- Consent text
- Dispatch statistics (opens, clicks — only with additional consent)
Purpose: Sending information about our products, features, and industry news
Legal basis: Art. 6 (1) lit. a GDPR in conjunction with Section 7 (2) No. 3 UWG (German Act Against Unfair Competition) (express consent)
Storage period: Until consent is withdrawn. After withdrawal, the email address + proof of consent are stored on a suppression list (accountability obligation under Art. 7 (1) GDPR).
Unsubscribing: At any time via the unsubscribe link in every newsletter email or by email to datenschutz@kombizent.com.
5.4 Registration & User Account
Description: Registration is required to use the Cockpit (app.kombizent.com).
Data processed:
- Name
- Email address
- Password (hashed with bcrypt)
- Company name
- Industry
- Phone number (optional)
- Address (for invoicing)
- VAT ID (for invoicing)
Purpose: Provision of the account, authentication, performance of the contract, invoicing
Legal basis: Art. 6 (1) lit. b GDPR (performance of a contract)
Storage period: For the duration of the contractual relationship. After the contract ends: master data for 6-10 years pursuant to Section 147 AO and Section 257 HGB, other data for 30 days for restoration in the event of an error, then deletion.
5.5 Provision of the Cockpit (Software-as-a-Service)
Description: In the Cockpit, Customers process their own data, including personal data of their own end customers (e.g. contact data, order data, invoice data).
Processing role: Here, we act as a processor within the meaning of Art. 28 GDPR. The Customer (= controller) decides which personal data it stores in the Cockpit. We process this data exclusively on its instructions. Details are governed by the data processing agreement (DPA / AVV) concluded with each Customer.
Categories of data processed (Customer end customers):
- Master data (name, address, contact data)
- Contract data (quotes, orders, invoices)
- Communication data (emails, WhatsApp, calls)
- Payment data (status only, no card/account data)
- History data (inquiries, appointments, maintenance)
Legal basis: Art. 6 (1) lit. b GDPR (performance of a contract) and Art. 28 GDPR in conjunction with the data processing agreement
Storage period: For the duration of the Customer's contract. After the contract ends: 30 days for restoration, then deletion — unless statutory retention periods of the Customer prevent this.
5.6 Payment Processing
Description: For payment of subscription fees, we use the payment service provider Mollie B.V. (Netherlands).
Data processed:
- Name
- Billing address
- Email address
- Payment data (SEPA mandate, credit card data — held directly by Mollie, not by us)
- Transaction data
Purpose: Payment processing
Legal basis: Art. 6 (1) lit. b GDPR
Recipient: Mollie B.V., Keizersgracht 313, 1016 EE Amsterdam, Netherlands. A data processing agreement is in place with Mollie.
Third-country transfer: None. Processing takes place in the EU.
Mollie privacy policy: https://www.mollie.com/de/privacy
5.7 AI Features in the Cockpit (Anthropic Claude)
Description: In the Cockpit, we provide AI-supported features (e.g. automatic inquiry classification, text suggestions, marketing generator). For this purpose, we transmit content (e.g. inquiry texts, Customer notes) to the AI API of Anthropic, PBC.
Data processed:
- Customer-specific content that the Customer actively releases for AI processing
- No pre-selected data categories — the Customer controls, per feature, which data is transmitted.
Purpose: Provision of AI-supported functions, automation of routine tasks
Legal basis: Art. 6 (1) lit. b GDPR (performance of a contract) or Art. 6 (1) lit. a GDPR (consent), depending on the feature
Recipient: Anthropic, PBC, 548 Market St., PMB 90375, San Francisco, CA 94104, USA. A data processing agreement is in place with Anthropic (as part of the Commercial Terms of Service).
Third-country transfer: Transfer to the USA. Safeguarded by Standard Contractual Clauses pursuant to Art. 46 (2) GDPR (Implementing Decision (EU) 2021/914 — Module 2).
Residual risk: US authorities can, in principle, access data in the USA under FISA 702 and Executive Order 12333. We minimize this risk through:
- Active control by the Customer (only explicitly released data is sent to Anthropic)
- Pseudonymization where possible
- Avoidance of sensitive data in AI prompts (notice in the Cockpit UI)
- Opt-out toggle per AI feature in the Cockpit settings
- Contractual obligation of Anthropic not to use transferred data for model training
Anthropic privacy policy: https://www.anthropic.com/legal/privacy
5.8 Image Generation (Google Imagen)
Description: In the Cockpit, Customers can have AI-generated icons and images created. The Google Imagen API is used for this purpose.
Data processed:
- Text prompts of the Customer
- Generated image outputs
Purpose: Provision of AI image generation
Legal basis: Art. 6 (1) lit. a GDPR (consent — the feature is opt-in)
Recipient: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Third-country transfer: Transfer to the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF); in addition, Standard Contractual Clauses are in place.
Google privacy policy: https://policies.google.com/privacy
5.9 Cookies and Similar Technologies
See the separate Cookie Policy at https://kombizent.com/cookies. Details on the cookies used, their purpose, storage period, and how to manage your consent.
Legal basis: Section 25 TDDDG (German Telecommunications Digital Services Data Protection Act) (cookies and similar technologies) and Art. 6 (1) lit. a GDPR (consent); for essential cookies, Art. 6 (1) lit. f GDPR or Section 25 (2) TDDDG.
6. Service Providers and Sub-Processors Used
We use the following technical service providers to operate the marketing website and the Cockpit. Data processing agreements pursuant to Art. 28 GDPR or Standard Contractual Clauses pursuant to Art. 46 GDPR are in place with all service providers.
6.1 Hosting & Infrastructure
Vercel Inc. 340 S Lemon Ave #4133, Walnut, CA 91789, USA Purpose: Hosting of the website and the Cockpit (CDN, edge functions) Third-country transfer USA: ✅ Vercel is DPF-certified; additionally SCC DPA: https://vercel.com/legal/dpa Privacy policy: https://vercel.com/legal/privacy-policy
Supabase Inc. 970 Toa Payoh North, Singapore 318992 (with US subsidiary Supabase Inc., USA) Purpose: Database, authentication, storage Server location: EU (Frankfurt, eu-central-1) — Customer data does not leave the EU Third-country transfer USA: Possible for administrative purposes (e.g. support). Safeguarded by SCC. DPA: https://supabase.com/legal/dpa Privacy policy: https://supabase.com/privacy
6.2 AI Services
Anthropic, PBC 548 Market St., PMB 90375, San Francisco, CA 94104, USA Purpose: AI-supported text processing (inquiry classification, marketing copy, etc.) Third-country transfer USA: Safeguarded by SCC + DPA (in Commercial Terms) Privacy policy: https://www.anthropic.com/legal/privacy Important note: In accordance with the DPA, Anthropic does not process data for training purposes.
Google LLC (Imagen API) 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA Purpose: AI image generation Third-country transfer USA: ✅ DPF-certified + SCC Privacy policy: https://policies.google.com/privacy
6.3 Payment Processing
Mollie B.V. Keizersgracht 313, 1016 EE Amsterdam, Netherlands Purpose: Payment processing Third-country transfer: None (EU) DPA: https://www.mollie.com/de/privacy
6.4 Communication
Transactional emails (registration confirmation, newsletter double opt-in, password reset, system notifications) are sent via our own mail server infrastructure. No external email delivery service provider is involved as a sub-processor.
Customers may alternatively configure their own SMTP server in the Cockpit ("Bring Your Own SMTP"), through which their own Customer communications are then routed. In this case, the respective SMTP provider is a sub-processor of the Customer, not of Kombizent.
6.5 Accounting (optional, upon activation)
sevDesk GmbH (upon Customer activation of the integration) Hauptstraße 115, 77652 Offenburg, Deutschland Privacy policy: https://sevdesk.de/datenschutz
Haufe-Lexware GmbH & Co. KG (upon Customer activation of the integration) Munzinger Str. 9, 79111 Freiburg, Deutschland Privacy policy: https://www.lexoffice.de/datenschutz
DATEV eG (upon Customer activation of the integration) Paumgartnerstraße 6-14, 90329 Nürnberg, Deutschland Privacy policy: https://www.datev.de/web/de/datev-de/datenschutz
6.6 Messaging
Meta Platforms Ireland Limited (for WhatsApp Business API, upon Customer activation) 4 Grand Canal Square, Dublin 2, Irland Privacy policy: https://www.whatsapp.com/legal/business-data-transfer-addendum
Twilio Inc. (for telephone integration, upon Customer activation) 375 Beale Street, San Francisco, CA 94105, USA Third-country transfer USA: SCC Privacy policy: https://www.twilio.com/legal/privacy
6.7 External Geocoding Services
OpenStreetMap Foundation (Nominatim) St John's Innovation Centre, Cowley Road, Cambridge, CB4 0WS, UK Purpose: Address data geocoding (postal code → coordinates) Third-country transfer UK: ✅ Adequacy decision of the EU Commission Privacy policy: https://wiki.openstreetmap.org/wiki/Privacy_Policy
7. Third-Country Transfers
Since the controller itself is established in the USA (Miami, Florida), a transfer of personal data to the controller may legally qualify as a third-country transfer. In practice, however, all customer and application data is processed and stored exclusively on EU servers (Frankfurt, AWS eu-central-1). The data does not leave the EU.
Insofar as personal data is transferred to recipients in the USA for the provision of individual functions (see above under sections 5.7 and 5.8), this takes place on the basis of one of the following grounds:
- Art. 45 GDPR — Adequacy decision (e.g. EU-U.S. Data Privacy Framework for certified US providers; UK Adequacy Decision)
- Art. 46 GDPR — Standard Contractual Clauses (SCC) pursuant to Implementing Decision (EU) 2021/914
- Art. 49 GDPR — Derogations for specific situations (only in exceptional cases)
Current assessment: The EU-U.S. Data Privacy Framework (DPF) remains valid following the decision of the General Court of the European Union of 03.09.2025 (Case T-553/23 "Latombe"). Should the DPF adequacy decision be revoked in the future, the additionally concluded Standard Contractual Clauses will apply as a fallback.
Residual risk with US transfers: US authorities can, in principle, access data in the USA under FISA 702 and Executive Order 12333. We minimize this risk through:
- Preference for EU servers (Supabase Frankfurt) for primary data storage
- Data minimization with US services
- Contractual requirements (storage media encryption, audit rights, pseudonymization)
8. Your Rights as a Data Subject
If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis us:
8.1 Right of Access (Art. 15 GDPR)
You may request information from us as to whether personal data concerning you is processed by us.
8.2 Right to Rectification (Art. 16 GDPR)
You have a right to rectification and/or completion vis-à-vis us insofar as the personal data processed is inaccurate or incomplete.
8.3 Right to Erasure (Art. 17 GDPR)
You may request that we erase your data without undue delay insofar as one of the statutory conditions applies. The right to erasure does not exist insofar as the processing is necessary, e.g. for compliance with a legal obligation (e.g. retention obligations).
8.4 Right to Restriction of Processing (Art. 18 GDPR)
You have the right to request the restriction of the processing of your personal data.
8.5 Right to Data Portability (Art. 20 GDPR)
You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format.
8.6 Right to Object (Art. 21 GDPR)
You have the right to object, on grounds relating to your particular situation, at any time to the processing of your personal data which is based on Art. 6 (1) lit. e or f GDPR.
Where personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing.
8.7 Withdrawal of Consent (Art. 7 (3) GDPR)
You have the right to withdraw your data protection consent declaration at any time. The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of the consent prior to its withdrawal.
8.8 Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR)
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
For complaints from Germany, please contact the state data protection authority responsible for your place of residence. A list is available at: https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html
For complaints from other EU Member States, please contact the respective nationally competent supervisory authority.
8.9 Exercising Your Rights
To exercise your rights, please contact us informally at: datenschutz@kombizent.com
We process requests within the statutory period of one month (extendable by two months in complex cases). To verify your identity, we may ask you for additional information.
9. Automated Decision-Making and Profiling
Fully automated decision-making within the meaning of Art. 22 GDPR with legal effect or significant impairment of your person does not take place.
AI features in the Cockpit make suggestions (e.g. classification of an inquiry) but no automatic decisions — the final decision is always made by a human (the Customer user).
10. Changes to this Privacy Policy
We reserve the right to adapt this privacy policy so that it always complies with the current legal requirements or to implement changes to our services, e.g. when introducing new services. The then-current version will apply to your next visit.
Material changes will be communicated to the Customer by email with a notice period of 6 weeks before they take effect.
11. Contact and Point of Contact
For questions about the processing of your personal data or to exercise your rights:
Controller: Digital Consulting EU LLC 2125 Biscayne Blvd, Ste 204 #10182 Miami, FL 33137, USA
Email: datenschutz@kombizent.com
This privacy policy was prepared taking into account the GDPR, the DDG (German Digital Services Act), and the TDDDG (German Telecommunications Digital Services Data Protection Act) as well as current case law (as of 06/2026).
Stand: 29.06.2026 · Version: v1.3