This English version is a courtesy translation. Only the German version is legally binding.
1. Controller
The controller for the processing described in section 2.1 is Legado Management UG (haftungsbeschränkt), Hauptstraße 46, 15936 Dahme/Mark, Germany, represented by managing director Christoph Seydel.
Data protection contact: info@gxpdesk.app; further details are in our legal notice.
No data protection officer has been appointed. Please send data protection enquiries to info@gxpdesk.app or by post to our address.
2. Scope and roles
This policy provides information under Art. 13 and 14 GDPR about personal data on https://gxpdesk.app and in GxP-Desk. Our offering is directed exclusively at businesses.
2.1 Where we are the controller
We determine the purposes and means of providing the website, handling contact enquiries, contract administration and billing, and managing our customer relationship. We process account, support and security data as a controller to the extent it serves these purposes of our own. Customer content does not become our own data merely because it is accessible during support or security checks. Classification depends on the particular processing purpose.
We receive data directly from you, technically from your browser or through use of the service. Where data is not collected from you, it comes in particular from the customer or its administrator (invitations, user details and permissions), the connected identity provider (SSO login details), or content and bug reports submitted by other users. The respective categories are described below. For processing as a controller, we provide information upon indirect collection under Art. 14(3) GDPR within a reasonable period, no later than one month, or at the first earlier communication or disclosure, unless a statutory exception applies.
2.2 Where we are a processor
We process customer data in the application, in particular documents, inventory, change control, training records, supplier evaluations, audit trails, signatures, AI logs, customer communications and personal content in bug reports, on behalf of the respective customer under the DPA. The customer determines purposes, legal bases and retention; if it itself acts as a processor, its principal is the controller. This policy does not establish an independent legal basis for processing customer data.
For questions and data subject requests concerning customer data, contact the customer or competent controller. We forward attributable requests received directly without undue delay and assist with handling them. Our own statutory obligations as a processor remain in force.
3. Website delivery and server log files
We operate the website and the application on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in data centres in Germany (application, databases, files and backups: Falkenstein; mail server: Nuremberg). Hetzner acts as our processor. All connections are encrypted via HTTPS (TLS). We serve fonts from our own server; no connection to Google or other font providers is established when you visit a page.
On every request, our server processes the data that your browser transmits for technical reasons in order to deliver the requested page: in particular IP address, date and time of access, requested address (URL), referrer URL, and browser type and operating system (user agent); our server generates the HTTP status code. Our web server does not keep an access log of all page requests. Application and security logs (server/container logs) may contain these data, for example for sign-in attempts, errors or blocked requests; they are rotated automatically by size.
- Purposes: delivering the website and the application, ensuring stability and security, detecting and preventing attacks and abuse, error analysis.
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in providing our online services securely and reliably.
- Recipients: Hetzner Online GmbH as processor. No transfer to third countries takes place.
- Retention: We delete server/container logs no later than after 30 days. Entries required to investigate a specific security incident are retained longer only for as long as needed for that investigation.
4. Cookies and access to your device
We use cookies and local browser storage for the requested functions listed below. Storage and access are exempt from consent under Section 25(2)(2) TDDDG only where strictly necessary for the function expressly requested; this exception does not extend across the board to audience measurement. Section 25(2)(1) TDDDG may apply to necessary technical transmission. The separate assessment of Prelumen Basic mode is set out in section 5.
| Name | Purpose | Retention |
|---|---|---|
| session | Login session (JWT, HttpOnly, SameSite=Lax) | Session cookie; login no more than 24 hours, shorter upon inactivity |
| session-mfa-pending | Intermediate step in two-factor login | 5 minutes |
| remember-device | Chosen option to remember a device for MFA | According to account policy, in days |
| NEXT_LOCALE | Selected language | 1 year |
| sso_pkce_(identifier) | Securing OIDC login | 10 minutes |
| sso_saml_(identifier) | Securing SAML login; contains email, SameSite=None | 10 minutes |
Local storage keeps the trial onboarding checklist status under onboarding-checklist:(account-ID). The entry has no expiry and remains stored until the user deletes it in the browser. Storage serves the expressly requested checklist function and relies on Section 25(2)(2) TDDDG.
Subsequent processing of personal data relies on Art. 6(1)(b) GDPR where you are personally a contracting party, otherwise Art. 6(1)(f) GDPR for securely providing the requested functions to users of our business customers. Section 2.2 applies to customer data. Technical recipients are the service providers described in sections 3 and 9; their storage rules apply alongside the browser periods listed here. You can clear or block cookies and local storage in your browser; blocking necessary login cookies may prevent login and SSO. A general cookie block does not necessarily prevent the measurement script or badge under section 5.
5. Audience measurement with Prelumen
We use Prelumen Analytics provided by onEco GmbH, Friedrichstraße 171, 10117 Berlin, in Basic mode for statistical analysis of our public website.
5.1 Measurement script in Basic mode
The script is loaded from analytics.prelumen.com on public marketing pages only for visitors who are not logged in. For each page view, it transmits only the requested URL, the referrer and a page-view ID (pageview_id). Prelumen additionally receives the IP address and the browser's user agent as a technical consequence of the HTTP request. According to Prelumen, the IP address is processed only transiently to derive country/region and is not stored. The script sets no cookies and stores nothing in local or session storage. It transmits no additional device or connection characteristics, screen resolution, Web Vitals, interaction or outbound events, or heartbeats. The script respects Do Not Track.
5.2 Prelumen badge
An image from analytics.prelumen.com is loaded as needed (lazy loading) in the footer of marketing pages for all visitors, including logged-in users. This is an ordinary image request without a measurement script. The badge image is loaded regardless of Do Not Track; Prelumen receives the IP address, user agent and referrer as a technical consequence of the request.
5.3 Legal basis, recipients and objection
- Purpose, legal basis and balancing of interests: Audience statistics serve to improve our public offering; the badge identifies the analytics service used. The legal basis for processing personal data is Art. 6(1)(f) GDPR. Our legitimate interest is analysing website use to the extent necessary and providing the badge image. The limited data scope, absence of cookies and web storage, merely transient IP processing according to the provider and the script's observance of Do Not Track weigh in favour of processing. Visitors' interests in the confidentiality of their browsing behaviour weigh against it, particularly given URL/referrer data and transmission to an external recipient. We take these interests into account when determining data scope, retention and recipients; the absence of cookies does not automatically make the data anonymous. Our interest prevails only to the extent that these limits are observed. The statutory right to object remains unrestricted.
- Assessment under Section 25 TDDDG: In Basic mode, no measurement information is stored on terminal equipment through cookies or web storage, and no additional device or connection characteristics read from the equipment are transmitted. The URL, referrer and technical HTTP details concern information the browser transmits in any event when requesting a page or image; the measurement report additionally contains a page-view ID. For this limited operation, we take the position that no separate access to terminal equipment requiring consent occurs, and operate it without a consent banner. This assessment considers the specific scope of transmission and does not rely solely on the absence of cookies. Obligations under Section 25 TDDDG remain unaffected by the legal basis under Art. 6(1)(f) GDPR.
- Recipients: onEco GmbH processes the data on our behalf as a processor under Art. 28 GDPR. Salesforce/Heroku in Ireland and Cloudflare as a CDN with US/EU edge processing are involved in hosting and delivery.
- Third country: Transfers to US recipients at Cloudflare rely on an adequacy decision under the EU-US Data Privacy Framework or on standard contractual clauses with necessary supplementary safeguards (section 15).
- Retention: We retain personal measurement data only for as long as needed for the particular analysis and necessary comparisons of usage trends; we then delete or effectively anonymise it. Service providers' retention rules apply to their technical logs to the extent that we cannot influence them. Our data protection contact can provide information on request.
- Objection and technical controls: You may exercise your Art. 21 GDPR right through info@gxpdesk.app. Do Not Track prevents script measurement. The badge image is loaded regardless of Do Not Track. Content blockers can prevent requests to analytics.prelumen.com. These technical options are voluntary; your objection does not depend on a browser setting and our statutory obligations remain in place.
6. Contacting us
6.1 Contact and demo form
Via our contact form you can request a demo, a quotation or information. We process your name, your business email address, your company, your role, the approximate number of your systems, your message and the page from which you opened the form. We need the information requested as mandatory fields in order to handle your enquiry; all other information is voluntary. Your enquiry is sent by email to our business mailbox. We do not maintain a separate lead database.
6.2 Email contact and support
If you contact us by email, for example at info@gxpdesk.app, we process your email address, your name and the information in your message. For support requests from our customers, we additionally process the account and contract details required to handle the request. If we need access to customer data to resolve an issue, we act as a processor under the DPA in that respect.
The following applies to both channels:
- Purposes: handling and answering your enquiry, preparing a quotation, providing support.
- Legal basis: Art. 6(1)(b) GDPR where you yourself are or wish to become our contractual partner. If you act on behalf of a business, we base the processing on Art. 6(1)(f) GDPR; our legitimate interest lies in communicating with prospective and existing customers and in preparing and performing contracts with your company.
- Recipients/third country: Email and hosting service providers, in particular Hetzner for our own mail server, process the data on our behalf to provide communications. The safeguards in section 15 apply to third-country transfers.
- Retention: We delete enquiries once they have been fully dealt with and no further communication is expected. Where they constitute commercial or business letters, for example because an enquiry leads to a contract, we retain them for six years under Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO) (Art. 6(1)(c) GDPR). Section 10 applies to copies in our mail system; technical retention settings do not justify storage beyond the necessary purpose. Where support enquiries contain customer data, DPA instructions and deletion obligations apply.
7. Registration for a trial account
You can register yourself for a free trial account limited to 14 days. We process your name, your business email address, a password, the name of your company and your job title. We store the password exclusively as a hash (Argon2id), never in plain text. To confirm your email address, we send you a link that is valid for 24 hours. A workspace with sample data is created for your trial. Content you enter in the application during the trial is customer data; section 2.2 applies in that respect.
- Purpose and legal basis: setting up and providing the trial account under our terms and conditions, Art. 6(1)(b) GDPR. If you act on behalf of a business and are not personally a contracting party, we rely on Art. 6(1)(f) GDPR (legitimate interest in conducting the trial requested by your company).
- Abuse prevention: To prevent automated and abusive registrations, we allow at most ten registrations per IP address per hour, limit the number of registrations per email domain within 30 days and reject addresses from known disposable email services. For this purpose we process your IP address and the domain of your email address. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in protecting our systems and the trial offering against abuse.
- Retention: Without a paid follow-on contract, we delete trial accounts and associated personal data from active systems no later than six months after the 14-day trial ends, or earlier on request. The five-working-day period does not extend that limit. Remaining backup copies of customer data follow section 16 and the DPA. Registration-limiting data is retained only for the respective hourly or 30-day assessment window and, where necessary, to investigate a specific case of abuse.
Recipients/third country: Hetzner for application and mail servers (Germany); the email service you choose receives the verification message. Sections 10 and 15 set out the relevant transfer rules.
8. Customer account and contract handling
We conclude paid contracts on the basis of an individual quotation or order form. For concluding contracts, account management and billing, we process the names, business contact details and job titles of contact persons, company and billing address, contract data (for example the plan booked, term and scope of services), invoices and payment information. Payment is made by invoice and bank transfer; we do not use an online payment service provider.
- Legal basis: Art. 6(1)(b) GDPR for performing the contract; for contact persons who are not themselves a party to the contract, Art. 6(1)(f) GDPR (legitimate interest in performing the contract with your company); for retention, Art. 6(1)(c) GDPR in conjunction with Section 147 AO and Section 257 HGB.
- Recipient categories/third country: Hetzner for hosting (Germany), banks involved in transfers and tax authorities under statutory duties; where actually engaged, tax or legal advisers subject to professional confidentiality. Further necessary email processing is governed by section 6.
- Retention: We store contract data for the term of the contract. Thereafter we retain accounting vouchers such as invoices for eight years, commercial and business letters for six years, and books and annual financial statements for ten years, in each case from the statutory starting date under Section 147(4) AO or Section 257(5) HGB, in particular the end of the calendar year of the last entry, preparation, receipt, sending or creation of the document concerned. Where necessary, we store data beyond that until the limitation periods expire in order to assert or defend legal claims (Art. 6(1)(f) GDPR).
9. Use of the application
9.1 User account and login
We process name, business email address, password hash (Argon2id), roles and permissions, account/tenant assignment and language settings to provide and administer access. We receive data from you or, for an invitation, from the customer or its administrator.
- Legal basis: For our own account administration, Art. 6(1)(b) GDPR where you are personally a contracting party, otherwise Art. 6(1)(f) GDPR; our interest is providing secure personal access for business customers. Customer-related role and content processing under section 2.2 is performed on behalf of the customer on the basis it determines.
- Recipients/third country: Hetzner (Germany), authorised customer administrators and, for SSO, the customer's identity provider. Recipients selected by the customer may process outside the EEA; section 15 applies.
- Retention: For as long as access and the respective details are needed for account or contract administration; they are deleted when no longer needed unless separate lawful retention is required. Section 9.4 governs GxP records, section 8 contract administration and section 16 return and deletion.
9.2 Multi-factor authentication and single sign-on
TOTP, WebAuthn/passkeys and SSO through OIDC or SAML 2.0 are available. Authentication and device information is processed for these functions; remembered devices also involve IP address and, in some cases, user agent. For SSO, necessary identity details come from the identity provider connected by the customer; the customer determines its selection and transmitted attributes. Our own account security and its legal bases are as described in section 9.1; section 2.2 applies where the customer specifies processing as part of its use.
Recipients and third-country cases are governed by section 9.1. Authentication data is needed only for the duration of the configured method and necessary account administration; remembered devices follow account policy. Browser periods are in section 4. Any further necessary security evidence is assessed under section 9.3, rather than retained indefinitely across the board.
9.3 Security logging and abuse prevention
Account lockout after five failed attempts within 15 minutes and rate limiting protect against unauthorised access. Failed re-authentications are logged with IP address and, where applicable, user agent.
- Purpose, legal basis and interest: Our own operational and attack security under Art. 6(1)(f) GDPR; our interest is protecting the service and user accounts. Art. 32 GDPR establishes security requirements but no blanket retention period. Records processed on behalf of the customer remain customer data.
- Recipients/third country: Hetzner for hosting in Germany; no additional external error-tracking service is envisaged. Legally required disclosures are governed by section 14.
- Retention: We delete our own server/container and security logs no later than after 30 days. Longer retention applies only for as long as necessary to investigate a specific security incident (section 3).
9.4 Audit trail and electronic signatures
The audit trail can only be appended to at database level and uses a hash chain to make tampering detectable. Audit trails, electronic signatures and training signatures include attribution to individuals and IP addresses, with user agent also recorded for electronic signatures. They support traceability and integrity of the customer's GxP records.
These records are customer data under section 2.2; the customer determines their legal bases. Security-related content does not automatically change that role. Recipients are Hetzner, users authorised by the customer and export recipients instructed by it; the DPA and section 15 apply. Audit trail entries are not deleted automatically. Retention and any rectification, erasure or restriction follow lawful customer instructions and applicable law; immutability is not an exemption from erasure. The configurable default document period is 3650 days, not a statutory minimum. Section 16 and the DPA govern return and complete deletion upon termination.
10. Transactional emails
We send transactional emails, such as confirmations, invitations, password reset links, notifications and reminders, through our self-operated mail server (Postal) in Germany. We process recipients, subject, content and delivery information. Technical sender and reply addresses do not replace the data protection contact info@gxpdesk.app.
- Purpose and legal basis: Providing requested account and contractual functions under Art. 6(1)(b) GDPR where you are personally a contracting party, otherwise Art. 6(1)(f) GDPR for reliable communication with our business customers' users and necessary delivery evidence. Customer content and notifications are processed on behalf of the customer under section 2.2; the customer determines the legal basis.
- Recipients/third country: Hetzner as the mail server hosting provider and the email service used by the recipient. The mail server is in Germany; the recipient service's processing location depends on the recipient's choice. Our Art. 44 et seq. GDPR obligations continue to apply to instructed transfers.
- Retention: We retain the content of transactional emails, including in the outgoing queue and mail server, only to the extent necessary and for no more than twelve months. Delivery metadata without content (recipient, time and delivery status) is retained as evidence of dispatch for no more than three years; this also applies to delivery events. We then delete the data. For customer data, earlier deletion instructions and the DPA deletion periods, including deletion upon termination, take precedence. Our own business records subject to statutory retention follow section 8.
11. AI features
The application offers optional AI-assisted features. They are only active if an administrator of the customer configures an AI provider with the customer's own API key ("bring your own key"): OpenAI, Anthropic, Google (Gemini) or a self-hosted AnythingLLM instance. The customer can deactivate the AI features or restrict them to locally operated models.
- Roles: The customer concludes the contract with the AI provider itself. On the customer's instructions, we transmit your inputs (prompts) and the relevant document content of the respective tenant to the selected provider. In doing so, we act as the customer's processor. The AI provider is not our sub-processor but is engaged by the customer.
- Third country: Depending on the selected provider, data may be transferred to third countries, in particular the USA. The customer is responsible for selecting and engaging the recipient and for its processing; we remain bound by our own transfer obligations under Art. 28 and Art. 44 et seq. GDPR. An instruction or API key does not replace a transfer mechanism. Whether and for how long the provider stores data or uses it for training is governed by the customer's contract with the provider.
- AI log: For traceability, we store the prompt, context and result of AI requests in an AI log. It is part of customer data; retention follows lawful customer instructions, including complete return and deletion under the DPA and section 16.
- No training by us: We do not train our own AI models with customer data.
Notice under Art. 50 of the AI Act (Regulation (EU) 2024/1689): When you use the AI features, you are interacting with an AI system; the texts and suggestions produced are AI-generated. They may be incorrect or incomplete, do not constitute decisions, and must be reviewed and approved by a competent person before use.
12. Bug reports
Logged-in users can voluntarily report errors to us via the application. We store the report and, if you attach one, a screenshot on our own server. For handling, we transfer a summary as a ticket (issue) to a private repository at GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA (Microsoft group). The summary contains the report ID, severity, the page address without parameters, route, app version, window size, user agent, time and your report text. Screenshots remain on our server. You suffer no disadvantage if you do not use this function.
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in fixing errors and improving the application. Where a report contains customer data, we process it as a processor; GitHub is engaged as a sub-processor in that respect.
- Third country: Transfers to GitHub in the USA rely on the adequacy decision for the EU-US Data Privacy Framework or on standard contractual clauses with necessary supplementary safeguards; section 15 and § 11 of the DPA apply.
- Retention: We delete reports and screenshots on our server after 180 days, or earlier under the DPA upon a valid deletion instruction or termination. We delete personal information in GitHub tickets after completing the specific error analysis and necessary follow-up checks. For customer data, instructions and complete deletion under the DPA take precedence.
- Please note: Do not enter personal data in the report text, in particular no names, health or patient data, and check screenshots for personal or confidential content before submitting them.
13. API documentation
The REST API documentation loads the Scalar library from the jsDelivr CDN (cdn.jsdelivr.net). IP address and technical details such as user agent and referrer are transmitted to jsDelivr and its CDN partners, including Cloudflare and Fastly. Processing in the USA is possible.
- Purpose and legal basis: Displaying the API documentation you requested on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in functional delivery of the requested content; processing is limited to the request data necessary for that purpose. The exception under Section 25(2)(2) TDDDG applies to terminal access only to the extent strictly necessary for the expressly requested documentation function; it does not cover additional audience measurement.
- Recipients and retention: Technical recipients are jsDelivr and the CDN service providers involved, in particular Cloudflare and Fastly. Their respective retention rules apply to their technical logs to the extent that we cannot influence them; our data protection contact provides information on request. Our server logs are governed by section 3.
- Third country: Transfers to US recipients rely on an adequacy decision under the EU-US Data Privacy Framework or on standard contractual clauses with necessary supplementary safeguards (section 15).
14. Recipients and processors
Recipients named in the individual sections receive only data necessary for the respective purpose. Overview:
| Recipient/category | Purpose | Role and processing location |
|---|---|---|
| Hetzner Online GmbH, Gunzenhausen | Hosting website, application, databases, files, mail server and backups | Processing on our behalf; Germany (Falkenstein, Nuremberg) |
| onEco GmbH, Berlin, with Salesforce/Heroku and Cloudflare | Public website audience measurement and badge requests | Processing on our behalf for the website; Ireland, possible US/EU edge processing by Cloudflare; safeguards under section 15 |
| GitHub, Inc., San Francisco | Summaries of voluntary bug reports without screenshots | Processor for our own support processing, sub-processor for customer data; USA, safeguards under section 15 |
| Email and hosting service providers for the business mailbox | Emails and form enquiries | Processing on our behalf to provide communications; safeguards under section 15 |
| jsDelivr with CDN partners, including Cloudflare/Fastly | Scalar delivery for API documentation | Technical recipients for content delivery; US processing possible, safeguards under section 15 |
| Banks and tax authorities; tax/legal advisers where engaged | Payments, statutory administration, advice | According to the particular statutory or contractual task |
| Customer administrators and authorised users | Account/permission administration and customer data processing | Within the customer's sphere of responsibility |
| Customer-selected AI/SSO providers, API clients and email recipients | Instructed integrations and communications | Selected by the customer; not sub-processors merely because of transmission, locations depend on its choice |
Processing on our behalf is subject to Art. 28 GDPR. We contractually require processors to follow instructions and protect personal data. Hetzner and GitHub are the sub-processors for customer data listed in the DPA; website recipients are distinct.
Legally required disclosures to authorities or courts rely on Art. 6(1)(c) GDPR and the particular applicable obligation. Necessary disclosures for legal proceedings may rely on Art. 6(1)(f) GDPR and our interest in establishing or defending claims. These purposes do not alone justify disclosing unnecessary data.
15. Transfers to third countries
The application, databases, files and encrypted backups are located in data centres in Germany. A US data plane is disabled. This is distinct from the external recipients described below. Third-country transfers, including access from a third country, are permissible only where Art. 44 et seq. GDPR requirements are met.
- GitHub: Bug report summaries are transferred on the basis of the adequacy decision for the EU-US Data Privacy Framework to the extent that the decision and the recipient's valid, relevant certification cover the processing, or on the basis of standard contractual clauses with necessary supplementary safeguards. Section 11 of the DPA provides details.
- Prelumen/Cloudflare, jsDelivr/CDN and business mailbox: To the extent that these services transfer personal data to recipients in the USA, transfers rely on an adequacy decision for the EU-US Data Privacy Framework with valid, relevant certification, or on standard contractual clauses with necessary supplementary safeguards. For other third countries, an applicable adequacy decision or appropriate safeguards under Art. 46 GDPR apply.
- Recipients selected by the customer: For AI, SSO, API clients and email recipients, the customer determines the connection or recipient and is responsible for engagement and processing there. The Provider remains bound by its own transfer obligations under Art. 28 and Art. 44 et seq. GDPR; an instruction or API key does not replace a transfer mechanism.
Information on the safeguards applicable to a particular transfer and a copy of the relevant standard contractual clauses is available through info@gxpdesk.app, with redaction of irrelevant confidential information where necessary. Certification can be checked in the DPF register. We transfer personal data only on a valid basis under Art. 44 et seq. GDPR; if that basis ceases to apply, we suspend the affected transfer until lawful safeguards are in place.
16. Retention periods
We retain personal data only for as long as necessary for the respective purpose or required by a statutory retention obligation. The following periods limit retention; earlier lawful deletion instructions and deletion obligations under the DPA remain applicable.
| Data | Period or determining criterion |
|---|---|
| Our own server/security logs | Deleted no later than after 30 days; longer only for as long as needed to investigate a specific security incident |
| Contact/support enquiries | Until completion and no expected further communication; statutory business-letter retention six years |
| Trial without a paid follow-on contract | Deletion on request at any time, from active systems no later than six months after trial end |
| Accounting vouchers | Eight years from the statutory starting date |
| Books/annual financial statements | Ten years from the statutory starting date |
| Transactional email content, including MailOutbox and mail server | No more than twelve months; earlier according to necessity or the DPA |
| Delivery metadata without content, including delivery events | No more than three years as evidence of dispatch; earlier according to necessity or the DPA |
| Reports/screenshots on our own server | 180 days, earlier under the DPA where applicable |
| GitHub tickets | Until necessary error analysis/follow-up completed; customer data under the DPA |
| Customer documents, audit trails, signatures, AI logs | Lawful customer instructions; configurable document default 3650 days, not a statutory minimum |
| Operational backups | Retention set to 30 days on the same production server in Falkenstein; older backups deleted at the next release-triggered backup run; no daily backups or off-site copies |
Upon termination, customer data is generally available for retrieval for 30 calendar days; for a Data Act switch, at least 30 calendar days after the agreed transitional period ends. Longer mandatory or agreed periods remain in place. Deletion from active systems and by sub-processors then occurs within five working days (Monday to Friday, excluding public holidays at the Provider's registered office); remaining backup copies no later than 90 days after active deletion, restricted from other use until then and with deletion reapplied after restoration. A lawful choice of earlier deletion and mandatory requirements remain controlling. This includes mail and GitHub customer data regardless of longer technical settings. The DPA and Terms provide details. Only the Provider's statutory retention obligations permit limited exceptions; the customer's GxP obligations do not justify us retaining data on our own initiative.
17. Your rights
Subject to the statutory requirements, you have the following rights:
- access to the personal data we process about you (Art. 15 GDPR),
- rectification of inaccurate data and completion of incomplete data (Art. 16 GDPR),
- erasure (Art. 17 GDPR), unless retention obligations or other exceptions under Art. 17(3) GDPR apply,
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR) for data you have provided to us and that we process by automated means on the basis of consent or a contract,
- objection to processing based on Art. 6(1)(e) or (f) GDPR (Art. 21 GDPR, see section 18),
- withdrawal of consent given, at any time with effect for the future (Art. 7(3) GDPR); the lawfulness of processing carried out before the withdrawal remains unaffected.
To exercise your rights, an informal message to info@gxpdesk.app is sufficient. If we have reasonable doubts about your identity, we may request additional information to confirm it. For customer data processed on behalf of a customer, please contact the competent controller (section 2.2). For our own processing, we generally respond to requests within one month under Art. 12 GDPR; any legally permissible extension is communicated in good time with reasons.
Right to lodge a complaint: You can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement. The authority competent for us is:
Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg (Brandenburg Commissioner for Data Protection and Access to Information), Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany.
18. Right to object under Art. 21 GDPR
Objection on grounds relating to your particular situation: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Objection to direct marketing: Should we process your personal data for direct marketing purposes, you have the right to object at any time to such processing; this also applies to profiling related to such direct marketing. After your objection, we will no longer use your data for direct marketing purposes.
How to object: The objection is not subject to any particular form. Send it to info@gxpdesk.app or by post to the address given in section 1. Do Not Track prevents measurement by the Prelumen script. The badge image is loaded regardless of Do Not Track. Your statutory objection does not depend on a browser setting (section 5).
19. Provision of data and automated decision-making
There is no general statutory obligation to provide us with data. Technical delivery, personal accounts and contract administration nevertheless require the necessary connection or identity details; these functions are unavailable without them. A password is required for local login, not universally for SSO. Optional information in enquiries, bug reports and AI content should be limited to what is necessary. The competent controller explains customer-related obligations to provide GxP data.
AI results are suggestions; their substantive use requires human review and approval. The described safeguards may automatically restrict access or registration. Restrictions with legal or similarly significant effects are subject to the safeguards of Art. 22 GDPR. You may request review of a restriction through info@gxpdesk.app or the customer administrator and explain your position. Solely automated decisions with such effects are permissible only under the statutory requirements and with the necessary safeguards.
20. Data security
We implement technical and organisational measures under Art. 32 GDPR that are appropriate to the risk of the processing, in particular:
- encrypted transmission throughout (HTTPS/TLS),
- storage of passwords exclusively as Argon2id hashes, available multi-factor authentication (TOTP, WebAuthn/passkeys) and single sign-on subject to customer configuration,
- role-based permissions following the principle of least privilege, tenant-bound database access and segregation of duties for approvals,
- encrypted storage of secrets such as API and AI keys (AES-256-GCM),
- electronic signatures with re-authentication and an append-only audit trail with a hash chain,
- account lockout and rate limiting,
- hardened servers (firewall, key-only SSH access, blocking of repeated failed login attempts) and an encrypted connection to the mail server,
- encrypted backups,
- automated tests and checks of the software dependencies used for known vulnerabilities before every release.
No technical system offers complete security. We accept reports of security vulnerabilities in accordance with our coordinated disclosure policy.
21. Changes to this privacy policy
We inform you of changes in processing or the legal situation by updating this Privacy Policy. Before further processing for different purposes as a controller, we provide information under Art. 13(3) or Art. 14(4) GDPR and obtain any required consent beforehand. The revision date is shown above. We inform customers about changes that affect them as controllers, in particular new sub-processors, in accordance with the DPA.