Legal
Privacy policy
What we record when you visit this website, what we process on behalf of customers inside the application, on which legal basis, for how long, and how you exercise your rights under the GDPR.
- Application data is hosted in the European Union
- No third-party advertising, analytics or tracking services on this website
- No external font, script or icon CDNs — assets are served from our own infrastructure
- A data processing agreement under Art. 28 GDPR is offered to every customer
This text is a draft. It must be reviewed and approved by qualified German data protection counsel, and checked against the site as it is actually deployed — every script, font, embed and form on the live build — before it is published as the operative policy. Any value still shown as an unfilled placeholder must be resolved first.
1. Two sets of data, two different roles
This policy covers two things that are often confused, and it keeps them apart on purpose. The first is data about you as a visitor to this website — the pages you request, a message you send through the contact form, a signup you complete. For that data we are the controller within the meaning of Art. 4 (7) GDPR. We decide why and how it is processed, and this policy is our information notice under Art. 13 GDPR.
The second is the data our customers put into the application: their properties, their tenants and clients, their contracts, their meter readings, their invoices. We do not decide what goes in there and we do not use it for our own purposes. The customer is the controller; we act as a processor under Art. 28 GDPR, on documented instructions, under a data processing agreement (Auftragsverarbeitungsvertrag).
If you are a tenant, an owner or a service partner whose data sits inside a landlord's workspace, we are not your point of contact. The landlord or managing agent who operates that workspace is the controller and answers your access, rectification and erasure requests. We will tell you who that is if you ask and we can identify the workspace, but we cannot disclose or alter their records on your instruction.
Sections 2 to 6 and 8 to 9 of this policy describe the website. Section 7 describes the application.
2. Who is responsible and how to reach us
The controller for the processing of website visitor data described in this policy is:
Webservices Engineering GmbHBergstraße 17
82380 Peißenberg
Germany
Telephone +49 176 69014969
Email devops@webservices-engineering.de
- Represented by
- Andreas Philippi and Klaus Copony, managing partners (Geschäftsführende Gesellschafter). The register entry and the remaining corporate details are set out in the legal notice, and the two pages must agree.
- VAT identification number
- DE305060668, issued under Section 27a of the German Value Added Tax Act (UStG).
- Contact for data protection matters
- Write to devops@webservices-engineering.de or to the postal address above, marked for the attention of data protection. We answer requests under Art. 15 to 21 GDPR at that address without charge.
- Data protection officer
- Where no officer is required under Art. 37 GDPR and Section 38 BDSG, data protection responsibility rests with the management and enquiries are handled at the address above. Whether an appointment is required here is one of the points confirmed in the review noted at the top of this page.
- Supervisory authority
- The competent authority for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach, Germany. You may lodge a complaint there or with the authority of your habitual residence or place of work.
The controller identity in this section must match the legal notice exactly. Any divergence between the two pages is a defect.
3. What we process when you use this website
This website is a marketing and information site. It has no visitor accounts, no personalised content and no profiling. Four categories of data arise.
- Server log data
- Each request is logged with the requesting IP address, date and time, the resource requested, HTTP status and volume transferred, referrer and user agent. Logs secure and stabilise the service and are not merged with other data sources.
- Contact form and email
- The name, email address, optional company and telephone number, and the content of your message. We process it to answer you and to keep a record of what was asked and answered.
- Signup form
- The data needed to set up a workspace: company name, contact name, email address, chosen plan and modules, billing details. It is processed to prepare and perform the contract you asked for.
- Cookie consent record
- Your consent decision, its timestamp, the consent version and a pseudonymous identifier. We store it to prove the decision under Art. 7 (1) GDPR and to avoid asking you again on each visit.
Providing contact and signup data is voluntary, but without it we cannot answer an enquiry or create a workspace. Server log data arises automatically from the technical delivery of the page and cannot be switched off while the site is being used.
4. Legal basis for each purpose, and the legitimate interests we rely on
Where we rely on Art. 6 (1) (f) GDPR, the balancing test requires us to name the interest rather than assert one. Those interests are stated in full below.
| Processing | Purpose | Legal basis | Stated legitimate interest (where applicable) |
|---|---|---|---|
| Delivery of the requested page | Technically providing the website to the browser that asked for it | Art. 6 (1) (f) GDPR | Making our own website available and technically functional |
| Server log data | Operational security, error diagnosis, abuse and attack detection, capacity planning | Art. 6 (1) (f) GDPR | Protecting our infrastructure and our customers' service against misuse, and being able to reconstruct incidents |
| Contact form and email correspondence | Answering an enquiry and documenting the exchange | Art. 6 (1) (b) GDPR where the enquiry concerns a contract or its initiation; otherwise Art. 6 (1) (f) GDPR | Responding to business enquiries addressed to us and retaining evidence of what was communicated |
| Signup form | Preparing and performing the subscription contract | Art. 6 (1) (b) GDPR | Not applicable |
| Cookie consent record | Obtaining, documenting and honouring your consent decision | Art. 6 (1) (c) GDPR for the documentation obligation; the consented processing itself rests on Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG | Not applicable |
| Strictly necessary cookies and session storage | Session handling, load balancing and protection against cross-site request forgery | Section 25 (2) TDDDG, and Art. 6 (1) (f) GDPR | Delivering a secure and stable website that the visitor has actively requested |
| Retention of commercial correspondence | Meeting statutory retention duties | Art. 6 (1) (c) GDPR in conjunction with Section 257 HGB and Section 147 AO | Not applicable |
Where processing rests on consent under Art. 6 (1) (a) GDPR, you may withdraw it at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before it. The TDDDG citations above are current: the TDDDG replaced the TTDSG referred to in older German policies.
5. How long each category is kept
We delete or anonymise data once the purpose it was collected for has ended and no statutory retention duty stands in the way.
| Category | Retention period | What ends it |
|---|---|---|
| Server log data | 30 days | Automatic rotation and deletion; longer only for a log segment attached to a documented security incident |
| Contact form and email correspondence | Two years after the exchange is closed | Closure of the matter, unless the correspondence qualifies as a commercial letter |
| Commercial letters and accounting-relevant correspondence | Six years for commercial letters, ten years for accounting records | Expiry of the statutory period under Section 257 HGB and Section 147 AO |
| Signup data where no contract follows | Six months | Abandonment of the signup, after which the record is deleted |
| Signup and customer administration data where a contract follows | Duration of the contract plus the statutory retention period | Termination of the contract and expiry of the retention and limitation periods |
| Cookie consent record | Six months | Expiry of the storage period, withdrawal, or a new consent version superseding it |
| Backups containing any of the above | 30 days | Rotation of the backup generation; deletion requests are executed in the live systems immediately and take effect in backups as the generation rotates out |
Each period above is a statement about how the systems are configured, not an aspiration. The log rotation, the backup generation and the storage period of the consent record must be confirmed against the running configuration, and the consent record period must match the cookie policy.
6. Who receives data, where it is stored, and what we deliberately do not use
We disclose personal data only where a processor needs it to provide a service to us, where you have consented, or where we are legally obliged to. Every processor is bound by an agreement under Art. 28 GDPR.
The website and the application run on infrastructure operated by the hosting provider named below, in data centres located within the European Union. Server log data arises there.
Hosting and infrastructure providerHetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany
Data centres within the European Union
- Document and object storage
- Documents and attachments uploaded to the application are held in S3-compatible object storage in an EU region, encrypted in transit and at rest. The provider is named in our processor list, which we send on request.
- Email delivery
- Transactional email — notifications, reminders and account messages — is sent by the platform, and any delivery processor engaged for it is named in the processor list. Customers may instead configure per-account SMTP, in which case their outgoing mail leaves through their own server and never reaches ours.
- No advertising, analytics or tracking
- This website loads no advertising networks, no analytics or statistics services, no tag managers, no social media plugins, no session recorders and no cross-site tracking pixels. There is no profiling and no automated decision-making under Art. 22 GDPR.
- No external CDNs
- Fonts, stylesheets, scripts, icons and images are served from our own infrastructure. Your browser makes no request to a third-party font, script or icon provider while rendering this site, so no such provider receives your IP address.
- Third countries
- We do not transfer personal data to a country outside the EU or EEA without a valid transfer mechanism under Chapter V GDPR. Any processor operating outside the EEA is named in our processor list together with the adequacy decision or standard contractual clauses relied on.
The "no tracking, no external CDNs" statement must be re-verified against the live build whenever a script, font, embed or third-party widget is added to the site. It is a factual claim about the shipped code, and the shipped code is what governs.
7. Customer data processed inside the application
Everything a customer records in a workspace — properties, cadastral details, housing units, clients and tenants, rental contracts and bailment agreements, meter readings, rebilling entries, invoices, uploaded documents — is processed by us solely on that customer's behalf. We are a processor under Art. 28 GDPR. We do not use that data for our own purposes, we do not sell it, and we do not use it to train anything.
Before processing begins we conclude a data processing agreement (Auftragsverarbeitungsvertrag) with the customer. It sets out the subject matter and duration, the categories of data subjects and data, our obligation to act only on documented instructions, confidentiality of our personnel, the technical and organisational measures, the rules for engaging sub-processors, our assistance with data subject requests and with Art. 32 to 36 obligations, and what happens to the data at the end. The current template and our processor list are sent on request through the contact page.
Access on our side is limited to what operating and supporting the system requires. Every record belongs to exactly one account and is scoped to it. Support staff who need to reproduce a problem inside a customer's workspace do so through supervised user switching, which is recorded in an audit trail, so it is always reconstructable who looked at what and when.
When the contract ends, the customer can export their data during the agreed window, after which we delete or return it as instructed and remove it from backups as the backup generation rotates out. The commercial detail of that process is set out in the terms and conditions.
8. Your rights, and how to exercise them
These rights are exercised against the controller. For website data that is us. For data inside a customer's workspace it is that customer, and we will forward your request if you cannot identify them.
- Access (Art. 15)
- You may ask whether we process personal data about you and, if so, obtain a copy together with the purposes, categories, recipients, envisaged storage period and the origin of the data.
- Rectification (Art. 16)
- You may require inaccurate personal data to be corrected without undue delay, and incomplete data to be completed, including by means of a supplementary statement.
- Erasure (Art. 17)
- You may require deletion where the data is no longer needed, consent is withdrawn, you object successfully, or the processing was unlawful — unless a statutory retention duty or legal claim requires us to keep it.
- Restriction (Art. 18)
- You may require processing to be restricted while accuracy is contested, in place of erasure where you need the data for legal claims, or while an objection under Art. 21 is being assessed.
- Portability (Art. 20)
- Where processing rests on consent or on a contract and is carried out by automated means, you may receive your data in a structured, commonly used, machine-readable format or have it transmitted to another controller.
- Objection (Art. 21)
- You may object at any time, on grounds relating to your particular situation, to processing based on Art. 6 (1) (f). We then stop unless we demonstrate compelling legitimate grounds that override your interests, or the processing serves legal claims.
- Withdrawal of consent (Art. 7 (3))
- Consent can be withdrawn at any time with effect for the future, as easily as it was given. Cookie consent is withdrawn through the settings described on the cookie policy page.
- Complaint (Art. 77)
- You may lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement, without prejudice to other remedies.
We answer requests within one month under Art. 12 (3) GDPR and may extend by two further months for complex requests, telling you why. Where we cannot identify you from the data we hold, we may ask for information that allows identification, and may decline to act if you cannot provide it (Art. 11, Art. 12 (6)).
9. How the data is protected, and how this policy changes
We apply technical and organisational measures appropriate to the risk under Art. 32 GDPR. Traffic to this website and to the application is encrypted in transit with current TLS. Stored documents are encrypted at rest. Passwords are never stored in recoverable form. Access to production systems is restricted to named personnel, authenticated individually, and logged.
Inside the application, isolation is structural rather than advisory. Signing in requires a Workspace ID alongside the email address and password, and credentials are only ever valid inside their own workspace. Every record belongs to an account and queries are scoped to it. Roles limit what a signed-in user may do — admin, supervisor, read-only, and a support role — and read-only exists precisely so that an accountant or auditor can see the figures without being able to change them.
Backups are taken regularly and restore procedures are exercised. On a Private Cloud deployment, backups are additionally mirrored to the customer's own site, and the environment runs on dedicated resources with redundancy and monitoring. No security measure is absolute: transmission over the internet can never be guaranteed free of interception, and we do not claim otherwise.
We update this policy when the processing described in it changes, when infrastructure or processors change, or when case law or supervisory guidance requires it. The version in force is the one published here, dated 3 August 2026 (version 1.0). Material changes affecting customers are additionally notified in the manner set out in the terms and conditions. Re-reading this page before a renewal is worth the two minutes.
Questions
Asked by data protection officers and by visitors
Does this website use cookies, analytics or tracking?
It uses only strictly necessary cookies and session storage for session handling, load balancing and protection against cross-site request forgery. There is no advertising network, no analytics or statistics service, no tag manager, no social media plugin and no cross-site tracking. Fonts and scripts are served from our own infrastructure, so no external CDN receives your IP address.
Where is my data stored, and does it leave the EU?
Application data is hosted in data centres inside the European Union. Documents and attachments are held in EU-region object storage, encrypted in transit and at rest. We do not transfer personal data outside the EU or EEA without a valid transfer mechanism under Chapter V GDPR. Any processor operating outside the EEA is named in our sub-processor list with the safeguard relied on.
Do you offer a data processing agreement under Art. 28 GDPR?
Yes. A data processing agreement, in German an Auftragsverarbeitungsvertrag, is offered to and concluded with every customer before processing begins. It covers instructions, confidentiality, technical and organisational measures, sub-processors, assistance with data subject requests, and return or deletion at the end of the contract. Ask for the current template through the contact page.
I am a tenant. Who do I contact about my data?
Your landlord or managing agent, not us. They operate the workspace, decide what is recorded in it and are the controller for it. We process that data only on their documented instructions as a processor. If you cannot identify the controller, write to us with what you know and we will forward your request rather than answer it ourselves.
How long is server log data kept?
Server log data is retained for the period stated in the retention table on this page and then deleted automatically by rotation. A log segment is kept longer only where it forms part of a documented security incident, and only for as long as that incident is being investigated or defended. Logs are not merged with other data sources or used to profile visitors.
What happens to our data when we stop using the service?
You can export your data during the agreed export window after termination. Once that window closes, we delete or return the data as instructed under the data processing agreement, and it disappears from backups as the backup generation rotates out. The commercial detail, including the length of the window, is set out in the terms and conditions.
Due diligence
Questions a policy page cannot answer
If your data protection officer needs the processor list, the technical and organisational measures or the current DPA template before a decision, ask and we will send them.