Privacy Policy
In the following, we inform you about the processing of your personal data when using our website in addition to our general privacy notes.
As of May 2025
In the following, we inform you about the processing of your personal data when using our website in addition to our general privacy notes.
As of May 2025
Table of contents
The data controller responsible in accordance with the purposes of the General Data Protection Regulation (GDPR) and other data protection regulations is:
DataCo GmbH
Sandstraße 33
80335 Munich, Germany
You can reach our data protection officer as follows:
DataCo GmbH
Sandstraße 33
80335 Munich, Germany
E-Mail:
If your request is specifically directed to DataCo GmbH as the data controller, please write to us at the following e-mail address: dpo@dataguard.de
If your request is directed to one of our customers for whom we are appointed as external data protection officer, please write to us at the following e-mail address: datenschutz@dataguard.de and kindly mention the company name of our customer in this e-mail.
If you would like to report an incident, whether it is a security incident or anything else, please describe the incident in an email to incident@dataguard.com.
1. Scope of processing personal data
In general, we only process the personal data of our users to the extent necessary in order to provide a functioning website with our content and services. The processing of personal data regularly only takes place with the consent of the user. Exceptions include cases where prior consent technically cannot be obtained and where the processing of the data is permitted by law.Scope of processing personal data In general, we only process the personal data of our users to the extent necessary in order to provide a functioning website with our content and services. The processing of personal data regularly only takes place with the consent of the user. Exceptions include cases where prior consent technically cannot be obtained and where the processing of the data is permitted by law.
2. Legal basis for data processing
Art. 6 (1) (a) GDPR serves as the legal basis to obtain the consent of the data subject for the processing of their data.
As for the processing of personal data required for the performance of a contract of which the data subject is party, Art. 6 (1) (b) GDPR serves as the legal basis. This also applies to processing operations required to carry out pre-contractual activities.
When it is necessary to process personal data in order to fulfil a legal obligation to which our company is subject, Art. 6 (1) (c) GDPR serves as the legal basis.
If vital interests of the data subject or another natural person require the processing of personal data, Art. 6 (1) (d) GDPR serves as the legal basis.
If the processing of data is necessary to safeguard the legitimate interests of our company or that of a third party, and the fundamental rights and freedoms of the data subject do not outweigh the interest of the former, Art. 6 (1) (f) GDPR will serve as the legal basis for the processing of data.
3. Data removal and storage duration
The personal data of the data subject will be erased or restricted as soon as the purpose of its storage has been accomplished. Additional storage may occur if it was provided for by the European or national legislator within the EU regulations, law, or other relevant regulations to which the data controller is subject. Restriction or erasure of the data also takes place when the storage period stipulated by the aforementioned standards expires, unless there is a need to prolong the storage of the data for the purpose of concluding or fulfilling the respective contract.
The General Data Protection Regulation (GDPR) grants individuals in the EU (and EEA) a set of rights over their personal data. These rights are intended to give people transparency, control, and recourse in how their data is collected, used, and shared by organizations.
Below is a high-level summary of the key rights:
(Art. 15 GDPR)
You may request from the data controller to confirm whether your personal data is processed by them.
If such processing is the case, you can request the following information from the data controller:
You have the right to request information on whether your personal data will be transmitted to a third country or an international organisation. In this context, you can then request for the appropriate guarantees in accordance with Art. 46 GDPR in connection with the transfer.
The data controller will provide you with a copy of the personal data that is the subject of the processing. Freedoms and rights of other persons shall not be affected. For any additional copies you request, the data controller may charge a reasonable fee based on administrative costs. If you make the request electronically, the information must be provided in a common electronic format unless you specify otherwise.
(Art. 16 GDPR)
You have the right to obtain from the controller the rectification without delay of inaccurate personal data concerning you and the right to obtain the completion of incomplete personal data.
(Art. 17 GDPR)
a) Obligation to erase
If you request from the data controller to delete your personal data with immediate effect, they are required to do so immediately given that one of the following applies:
b) Information to third parties
If the data controller has made your personal data public and has to delete the data pursuant to Art. 17 (1) GDPR, they shall take appropriate measures, including technical means, to inform data processors who process the personal data, that a request has been made to delete all links to such personal data or copies or replications of the personal data, taking into account available technology and implementation costs to execute the process.
c) Exceptions
The right to deletion does not exist if the processing is necessary
(Art. 18 GDPR)
You may request the restriction of the processing of your personal data under the following conditions:
If the processing of personal data concerning you has been restricted, this data may with the exception of data storage only be used with your consent or for the purpose of asserting, exercising or defending legal claims or protecting the rights of another natural or legal person or for reasons of important public interest, interest to the Union, or a Member State.
If the processing has been restricted according to the beforementioned conditions, you will be informed by the data controller before the restriction is lifted.
(Art. 19 GDPR)
If you have the right of rectification, erasure or restriction of processing over the data controller, they are obliged to notify all recipients to whom your personal data have been disclosed of the correction or erasure of the data or restriction of processing, unless this proves to be impossible or involves a disproportionate effort.
You reserve the right to be informed about the recipients of your data by the data controller.
(Art. 20 GDPR)
You have the right to receive your personal data given to the data controller in a structured, standard and machine-readable format. In addition, you have the right to transfer this data to another person without hindrance by the data controller who was initially given the data, given that the processing is based on a consent in accordance with Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract in accordance with Art. 6 (1) (b) GDPR and the processing is done by automated means.
In exercising this right, you also have the right to maintain that your personal data relating to you are transmitted directly from one person to another, insofar as this is technically feasible. Freedoms and rights of other persons shall not be affected.
The right to data portability does not apply to the processing of personal data necessary for the performance of a task in the public interest or in the exercise of official authority delegated to the data controller.
(Art. 21 GDPR)
Subjective to your situation, you have, at any time, the right to object against the processing of your personal data pursuant to Art. 6 (1) (e) or (f) GDPR; this also applies to profiling based on these provisions.
The data controller will no longer process the personal data concerning you unless he can demonstrate compelling legitimate grounds for processing that outweigh your interests, rights and freedoms, or the processing is for the purpose of enforcing, exercising or defending legal claims.
If the personal data relating to you are processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data in regard to such advertising; this also applies to profiling insofar as it is associated with direct mail.
If you object to processing for direct marketing purposes, your personal data will no longer be processed for these purpose.
You have the possibility, in connection with the use of information society services, notwithstanding Directive 2002/58/EC, to exercise your right to object by means of automated procedures using technical specifications.
You also have the right to object, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out for scientific or historical research purposes or for statistical purposes pursuant to Art. 89(1) GDPR, unless the processing is necessary for the performance of a task carried out in the public interest.
(Art. 7 (3) GDPR)
You have the right to withdraw your consent at any time. The revocation of consent does not affect the legality of the processing carried out on the basis of the consent until the revocation.
(Art. 22 GDPR)
You have the right not to subject to a decision based solely on automated processing including profiling that will have legal effect or affect you in a similar manner. This does not apply if the decision
However, these decisions must not be based on special categories of personal data under Art. 9 (1) GDPR, unless Art. 9 (2) (a) or (g) GDPR applies and reasonable measures have been taken to protect the rights and freedoms as well as your legitimate interests.
With regard to the cases referred to in (1) and (3), the data controller shall take appropriate measures to uphold your rights and freedoms as well as your legitimate interests, including the right to obtain assistance from the data controller or their representative, to express your opinion on the matter, and to contest the decision.
Without prejudice to any other administrative or judicial remedy, you shall have the right to complain to a supervisory authority, if you believe that the processing of the personal data concerning you violates the GDPR.
The supervisory authority to which the complaint has been submitted shall inform the complainant of the status and results of the complaint, including the possibility of a judicial remedy pursuant to Art. 78 GDPR.
In case of transfer of your personal data to a recipient in a third country or to an international organization, you have the possibility to obtain a copy of the appropriate safeguards pursuant to Article 46 or Article 47 or Article 49 (1) (2) GDPR from us by sending an informal email to dpo@dataguard.de.
To deliver our services efficiently and securely, we may share personal data with carefully selected third-party service providers.
We only engage third parties that process personal data on our behalf under written contracts that require them to:
Where any third party is located outside the EU or European Economic Area (EEA), we ensure that appropriate safeguards are in place subject to the Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR are concluded with the recipients.
You can find more information about our key third-party processors and their roles in the list below:
Link:
https://legal.hubspot.com/privacy-policy
Description of Services:
An integrated CMS software solution that covers various aspects of our online marketing.
Chatbot add on allows us to process user enquiries
Data Processed including Personal data:
Location of Processing:
EU, UK, US
Lawful basis of processing:
Legitimate Interest Art. 6 (1) (f) GDPR
Link:
https://www.jentis.com/en/privacy-policy/
Description of Services:
Proxy server that prevents third country transfer to Google Servers in the USA by anonymizing data before transmission to Google
Data Processed including Personal data:
Location of Processing:
EU, UK
Lawful basis of processing:
Legitimate Interest Art. 6 (1) (f) GDPR
Link:
https://www.salesforce.com/eu/company/privacy/
Description of Services:
Allows us to make the DataGuard Consent & Preference Management available for purchasing.
There is an add on integration with HubSpot.
Data Processed including Personal data:
Location of Processing:
EU, UK, US
Lawful basis of processing:
Consent and Legal Obligation
Art. 6 (1) (a) GDPR
Art. (6) (1) (b) GDPR
Link:
https://cookiechimp.com/privacy
Description of Services:
Consent management platform that enables us to obtain and manage user consent for data processing.
Data Processed including Personal data:
Location of Processing:
EU, UK
Lawful basis of processing:
Legal Obligation
Art. 6 (1) (c) GDPR, Art. 7 (1) GDPR
Link:
https://privacy.microsoft.com/de-de/privacystatement
Description of Services:
Microsoft 365 (Outlook, Microsoft Office) Communication and records
Microsoft Teams – Video Conferencing and Meetings (Calls may be recorded for note-taking for training purposes)
Data Processed including Personal data:
Location of Processing:
EU, UK
Lawful basis of processing:
Legitimate Interest Art. 6 (1) (f) GDPR
Link:
https://legal.hubspot.com/de/privacy-policy
Description of Services:
We use the HubSpot plug-in to optimize our website, marketing activities, and, in particular, the integration of a contact form.
Data Processed including Personal data:
Location of Processing:
EU, UK, US
Lawful basis of processing:
Legitimate Interest Art. 6 (1) (f) GDPR
Description of Services:
Web analysis service to evaluate the use of our online presence.
Google Analytics Remarketing is also an add on in relation to targeted advertising.
Data Processed including Personal data:
Location of Processing:
EU, UK
Lawful basis of processing:
Consent Art. 6 (1) (a) GDPR
Description of Services:
Evaluating user activity on our website
Data Processed including Personal data:
Location of Processing:
EU, UK
Lawful basis of processing:
Consent Art. 6 (1) (a) GDPR
Link:
https://www.hotjar.com/legal/policies/privacy
Description of Services:
Web analytics service to evaluate user experience on our website
Data Processed including Personal data:
Location of Processing:
EU, UK
Lawful basis of processing:
Consent Art. 6 (1) (a) GDPR
Link:
https://www.linkedin.com/legal/cookie-policy
Description of Services:
Provides us information about visitors to our website.
Data Processed including Personal data:
Location of Processing:
EU, UK, US
Lawful basis of processing:
Consent Art. 6 (1) (a) GDPR
Link:
https://www.google.com/intl/de/tagmanager/faq.html
Description of Services:
Used to capture and measure number of visitors and impact of advertising.
Data Processed including Personal data:
Location of Processing:
EU, UK
Lawful basis of processing:
Consent Art. 6 (1) (a) GDPR
Link:
https://policies.google.com/privacy?hl=en-GB
Description of Services:
The purpose is to verify data entry, analysing and authenticating use behaviour on the website.
Data Processed including Personal data:
Location of Processing:
EU, UK, US
Lawful basis of processing:
Consent Art. 6 (1) (a) GDPR
Link:
https://drive.google.com/file/d/1gsF_mvGNDiKForPjwi4chkb1Jr7XFkfj/view
Description of Services:
Engagement Analytics
Data Processed including Personal data:
Location of Processing:
EU, UK
Lawful basis of processing:
Consent Art. 6 (1) (a) GDPR
Link:
https://www.madkudu.com/privacy-center/privacy
Description of Services:
Qualifying prospects based on the available data
Data Processed including Personal data:
Location of Processing:
EU, UK, US
Lawful basis of processing:
Consent Art. 6 (1) (a) GDPR
Link:
https://www.linkedin.com/legal/privacy-policy
Description of Services:
Marketing Communication
Data Processed including Personal data:
Location of Processing:
EU, UK
Lawful basis of processing:
Consent Art. 6 (1) (a) GDPR
Link:
https://x.com/en/privacy
Description of Services:
Marketing Communication
Data Processed including Personal data:
Location of Processing:
EU, UK, US
Lawful basis of processing:
Consent Art. 6 (1) (a) GDPR
Link:
https://www.airmeet.com/hub/privacy-policy
Description of Services:
For planning and conducting webinars.
Data Processed including Personal data:
Location of Processing:
EU, UK, US
Lawful basis of processing:
Consent Art. 6 (1) (a) GDPR
Link:
https://www.chilipiper.com/privacy-policy
Description of Services:
To qualify and schedule meetings with Leads
Data Processed including Personal data:
Location of Processing:
EU, UK, US
Lawful basis of processing:
Consent Art. 6 (1) (a) GDPR
Link:
https://www.pandadoc.com/legal/privacy-notice/
Description of Services:
Contract Management
Data Processed including Personal data:
Location of Processing:
EU, UK, US
Lawful basis of processing:
Performance of a Contract Art. 6 (1) (b) GDPR
Link:
https://www.salesforce.com/uk/company/privacy/
Description of Services:
Deal Management and CRM
Data Processed including Personal data:
Location of Processing:
EU, UK
Lawful basis of processing:
Performance of a Contract Art. 6 (1) (b) GDPR
Link:
https://www.gong.io/trust-center/privacy/
Description of Services:
Sales Management
Data Processed including Personal data:
Location of Processing:
EU, UK, US
Lawful basis of processing:
Consent Art. 6 (1) (a) GDPR
Link:
https://www.ashbyhq.com/resources/privacy
Description of Services:
Recruitment Management
Data Processed including Personal data:
Location of Processing:
EU, UK, US
Lawful basis of processing:
Consent Art. 6 (1) (a) GDPR
TISAX® is a registered trademark of the ENX Association. DataGuard is not affiliated with the ENX Association. We provide Software-as-a-Service and support for the assessment on TISAX® only. The ENX Association does not take any responsibility for any content shown on DataGuard's website.
All data provided is for information only, based on internal estimates. This information is not indicative of KPIs, and is not given with any warranties or guarantees, expressly stated or implied in relation to accuracy and reliability.