Privacy Policy
For visitors to zealience.com, prospective customers and users of our profiles on external platforms
Preamble
With the following privacy policy, we would like to inform you about what types of your personal data (hereinafter referred to as "data") we process, for what purposes and to what extent.
This policy covers visitors to zealience.com, people who contact us or book a product demonstration, and users who interact with our profiles on external platforms such as LinkedIn, GitHub and Medium.
The terms used are not gender-specific.
Status: 5 September 2026
Content overview
- Preamble
- Controller
- Overview of processing
- Legal bases
- No cookies and no tracking
- Security measures
- Recipients and processors
- Transfers to third countries
- Provision of our online offering and web hosting
- Contact by email and telephone
- Booking and conducting product demonstrations
- Presence on external platforms
- Deletion of data
- Your rights as a data subject
- Data protection officer
- No automated decision-making
- Changes and updates to this privacy policy
Controller (referred to as the "controller" in the GDPR)
The data processing controller is:
Zealience GmbH
Neue Mainzer Straße 84, 60311 Frankfurt am Main, Germany
+49 1234 123 123
Overview of processing
The following overview summarizes the types of data processed and the purposes of its processing and refers to the data subjects.
Types of processed data
- Usage data (e.g. pages visited, times of access)
- Meta, communication and procedural data (e.g. IP addresses, device and browser information)
- Contact data (e.g. name, email address, telephone number)
- Content data (e.g. the content of your enquiries)
Categories of data subjects
- Visitors to our website
- Prospective customers and their contact persons
- Users who interact with our profiles on external platforms
Purposes of processing
- Provision of our online offering and its user-friendliness
- Operation of our information technology infrastructure
- Security measures
- Communication with interested parties and handling of enquiries
- Preparation and conduct of product demonstrations
Legal bases
We set out below the legal bases of the GDPR on which we process personal data. In addition to the GDPR, national data protection rules may apply in your or our country of residence.
Legitimate interests (Art. 6(1)(f) GDPR): Processing is necessary to safeguard the legitimate interests of the controller or a third party, unless the interests or fundamental rights and freedoms of the data subject, which require the protection of personal data, prevail.
Contract performance and pre-contractual measures (Art. 6(1)(b) GDPR): Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
Legal obligation (Art. 6(1)(c) GDPR): Processing is necessary for compliance with a legal obligation to which we are subject.
National data protection rules in Germany: In addition to the GDPR, national rules on data protection apply in Germany, in particular the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains specific provisions on, among other things, the right to information, the right to erasure, the right to object and automated decision-making in individual cases. The Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz – TDDDG) additionally governs the storage of, and access to, information on end users' terminal equipment.
No cookies and no tracking
Our website does not use cookies. We do not store any information on your device and we do not read any information already stored there. We do not use analytics services, tracking pixels, advertising networks or social media plug-ins, and we do not create user profiles.
The product demonstration videos on our website are hosted on our own web server. They are not embedded from third-party video platforms, so watching them does not establish any connection to a third party.
Because no information is stored on or read from your device, no consent banner is required under § 25 TDDDG.
Security measures
In accordance with legal requirements, and taking into account the state of the art, the cost of implementation and the nature, scope, circumstances and purposes of processing as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to it, as well as access, input, disclosure, availability and separation of data. We have also established procedures to ensure the exercise of data subject rights, the deletion of data and responses to threats to data. We take the protection of personal data into account when developing or selecting hardware, software and procedures, in accordance with the principles of data protection by design and by default.
TLS/SSL encryption (HTTPS): We use TLS/SSL encryption to protect data transmitted via our online services. You can recognise an encrypted connection by the "https://" prefix in your browser's address bar.
Recipients and processors
We use carefully selected service providers who process data on our behalf. Contracts pursuant to Art. 28 GDPR are in place with all of them.
- IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany — web hosting and provision of our website (DeployNow). Data is hosted in Germany.
- Microsoft Ireland Operations Limited — email (Outlook), appointment scheduling (Bookings) and online meetings (Teams). Data is stored in Germany.
- Salesforce, Inc. / Salesforce Germany GmbH — customer relationship management. Data is stored in Germany.
- ebuero AG, Hauptstraße 8, 10827 Berlin, Germany — telephone answering service. Answers calls to our published telephone number on our behalf and records the details of your enquiry.
Beyond this, we do not disclose your data to third parties unless we are legally obliged to do so.
Transfers to third countries
The service providers we use to operate our website, handle enquiries and manage prospective customer relationships store data within the European Union, and Germany in particular. Where, in exceptional cases, data is transferred to a third country — for example where a provider draws on support personnel outside the EU — such transfers take place on the basis of an adequacy decision by the European Commission or of Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR, supplemented where necessary by additional safeguards.
The external platforms described under "Presence on external platforms" below process data in the United States. Insofar as we transfer data there ourselves, for example by publishing content, this takes place on the basis of an adequacy decision by the European Commission (EU–US Data Privacy Framework) or of Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
Provision of our online offering and web hosting
We process users' data in order to provide our online services. For this purpose we process the IP address of the user, which is technically necessary in order to transmit the content of our website to the user's browser or device.
Hosting: Our website is hosted by IONOS SE on servers located in Germany.
Collection of access data and log files: Access to our website is logged in the form of server log files. These may include the address and name of the pages and files retrieved, the date and time of access, the volume of data transferred, notification of successful retrieval, browser type and version, the operating system used, the referring page and the IP address of the requesting device.
IP addresses in server log files constitute personal data. We do not use them to identify individual visitors and we do not combine them with other data sources. They are processed solely for the technical delivery of the website and for security purposes, for example to detect and prevent attacks and to ensure the stability and utilisation of the servers.
- Processed types of data: usage data; meta, communication and procedural data
- Data subjects: visitors to our website
- Purposes: provision of our online offering; information technology infrastructure; security measures
- Legal basis: legitimate interests (Art. 6(1)(f) GDPR) in the secure and stable operation of our website
- Retention: server log files are stored for 8 weeks. Data whose further retention is required for evidentiary purposes is excluded from deletion until the incident concerned has been finally resolved.
Contact by email and telephone
If you contact us by email or telephone, your enquiry and all personal data arising from it (for example your name, your company, your contact details including your telephone number, and the content of your message) will be stored and processed by us for the purpose of handling your enquiry.
Email: We use Microsoft 365 (Outlook) for our email correspondence. Data is stored in Germany.
Telephone: Calls to our published telephone number are answered on our behalf by an external telephone answering service, ebuero AG, Hauptstraße 8, 10827 Berlin. Its staff answer in our name and pass your call on to us.
Their role is limited to establishing who is calling and why, so that the call can be directed to the right person. They record only your name, the company you are calling from, your telephone number and the subject of your enquiry. They do not provide customer support, technical assistance or sales advice on our behalf, and they do not have access to our systems. Your telephone number is also transmitted to the service as part of the connection itself, unless you have suppressed it.
Calls are not recorded. To produce the call note, the service processes the audio of your call in volatile memory only, using transcription software operated in its own data centre within the European Union, and deletes the audio immediately afterwards. The resulting text is summarised by an AI service (Microsoft Azure) within the European Union, in the Azure region "Sweden Central", and is not used to train AI models. The note is then checked by the member of staff who took your call. No decision is taken about you on a solely automated basis within the meaning of Art. 22 GDPR.
ebuero AG processes this data exclusively on our behalf and on our instructions, under a data processing agreement pursuant to Art. 28 GDPR. We receive the call note by email and through the service's customer portal, and then handle your enquiry in the same way as one received by email. Further detail on this processing is set out in ebuero AG's privacy policy at https://www.ebuero.de/datenschutz.
- Processed types of data: contact data; content data; meta and communication data
- Data subjects: prospective customers and other persons contacting us
- Purposes: communication and handling of enquiries
- Legal basis: where your enquiry relates to the conclusion or performance of a contract, Art. 6(1)(b) GDPR. In all other cases, our legitimate interest in the effective handling of enquiries addressed to us and in the reliable availability of our telephone contact channel (Art. 6(1)(f) GDPR), or your consent (Art. 6(1)(a) GDPR) where it has been given; consent may be withdrawn at any time.
- Retention: we delete enquiries once they are no longer required, and review the necessity every two years. In relation to telephone enquiries, the audio is deleted immediately after the transcript has been generated and transcripts are deleted after 30 days at the latest. Call notes held by the answering service are stored and deleted in accordance with the data processing agreement concluded with it. Statutory retention obligations remain unaffected; in particular, correspondence qualifying as a commercial or business letter is retained for six years under § 257 HGB and § 147 AO.
Booking and conducting product demonstrations
If you are interested in our software, we can arrange a product demonstration with you.
Appointment booking: We send you a booking link for Microsoft Bookings. When you book an appointment, we process the details you provide there, in particular your name, your email address and your chosen appointment slot, together with any information you add yourself.
Conduct of the demonstration: The demonstration takes place via Microsoft Teams. During the meeting we process your connection data, your name as displayed and any content you share in the chat. We do not record or transcribe demonstrations.
Record in our CRM system: We create a record in Salesforce documenting your enquiry and the demonstration, so that we can look after you as a prospective customer and follow up on the discussion.
Microsoft and Salesforce process this data on our behalf on the basis of data processing agreements, on servers in Germany.
- Processed types of data: contact data; content data; meta and communication data
- Data subjects: prospective customers and their contact persons
- Purposes: preparation and conduct of product demonstrations; support of prospective customers; communication
- Legal basis: pre-contractual measures at your request (Art. 6(1)(b) GDPR) and our legitimate interest in supporting prospective customers (Art. 6(1)(f) GDPR)
- Retention: the criterion for retaining data relating to prospective customers is whether a business relationship may still come about. Where there has been no substantive contact for three years, we no longer regard the data as necessary for that purpose and delete it as part of our periodic reviews of stored data. Data is retained beyond that point only where a customer relationship has arisen in the meantime or where statutory retention obligations apply.
Presence on external platforms
We maintain profiles on external platforms in order to communicate with people interested in our work and to make our open-source contributions publicly available. Our website links to them by means of ordinary hyperlinks; no data is transmitted to a platform until you click one of these links or visit the platform yourself.
When you visit our profiles, the platform operator processes your data under its own responsibility and in accordance with its own privacy policy. We have no influence over that processing and no access to your account. As these platforms process data in the United States, the enforcement of your rights may be more difficult, and we ask you to assert them directly against the operator wherever possible.
Each platform provides us with aggregated statistics — such as views, reach, referral sources and general audience characteristics including country — which do not allow us to identify individual visitors. Separately, the platforms' standard functions show us the names and public profile information of people who follow us or interact publicly with our content, for example by reacting, commenting, applauding, starring or sharing. That information comes from the public profile you maintain yourself. Where we use it beyond merely viewing it on the platform, for example by contacting you, we do so as controller in our own right, on the basis of our legitimate interest in communicating with people interested in our work (Art. 6(1)(f) GDPR). You may object to this use at any time under Art. 21 GDPR, in which case we will cease it. We have no influence over how the platforms themselves process your data; please address any objection to that processing to the operator directly, or, in the case of LinkedIn's page statistics, see the paragraph below.
LinkedIn — LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. For the page statistics described above ("Page Insights"), we and LinkedIn are joint controllers within the meaning of Art. 26 GDPR. LinkedIn has assumed primary responsibility for that processing and for the fulfilment of data subject rights in its Page Insights Joint Controller Addendum; you may exercise your rights against either of us, and requests addressed to us will be forwarded to LinkedIn. Privacy policy: linkedin.com/legal/privacy-policy.
GitHub — GitHub, Inc., San Francisco, California, USA. Our repositories are public and accessible worldwide without registration. If you contribute to them, your username, the content of your contribution and the author details stored in your Git configuration, including the name and email address you have set there, become a permanent part of the public project history. Because Git repositories are distributed and may be copied by any number of third parties, subsequent removal is possible only to a very limited extent, so please consider carefully what you disclose. Privacy statement: docs.github.com/site-policy.
Medium — A Medium Corporation, San Francisco, California, USA. Privacy policy: policy.medium.com.
- Processed types of data: usage data; meta and communication data; public profile information of persons who follow or interact with our profiles; contact data and content data where you contribute or contact us via a platform
- Data subjects: users who visit, follow or interact with our profiles
- Purposes: public relations and communication; maintenance and development of open-source software
- Legal basis: legitimate interests (Art. 6(1)(f) GDPR) in effective public relations, in communicating with those interested in our work and in participating in the open-source community
Deletion of data
Data processed by us is deleted in accordance with legal requirements as soon as the consent permitting its processing is withdrawn or other permissions cease to apply, for example where the purpose of processing no longer applies or the data is no longer necessary for that purpose.
Where data is not deleted because it is required for other, legally permissible purposes, its processing is restricted to those purposes. This means the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons, or whose storage is necessary for the establishment, exercise or defence of legal claims.
The retention periods stated in the individual sections of this policy apply in the first instance.
Your rights as a data subject
You have the following rights under Art. 15 to 21 GDPR:
Right to object (Art. 21 GDPR): You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR. This also applies to profiling based on those provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to such processing.
Right of access (Art. 15 GDPR): You have the right to request confirmation as to whether data concerning you is being processed, and to obtain information about that data as well as further information and a copy of the data.
Right to rectification (Art. 16 GDPR): You have the right to request the correction of inaccurate data concerning you or the completion of incomplete data.
Right to erasure and to restriction of processing (Art. 17, 18 GDPR): You have the right to request that data concerning you be erased without undue delay, or alternatively to request a restriction of its processing.
Right to data portability (Art. 20 GDPR): You have the right to receive data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
Right to withdraw consent (Art. 7(3) GDPR): Where processing is based on your consent, you have the right to withdraw that consent at any time with effect for the future.
To exercise these rights, please contact us at .
Right to lodge a complaint: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR.
The supervisory authority responsible for us is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Gustav-Stresemann-Ring 1
65189 Wiesbaden, Germany
Data protection officer
We are not required to appoint a data protection officer. For all questions concerning the processing of your personal data, please contact us at .
No automated decision-making
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
Change and update of the privacy policy
We ask you to inform yourself regularly about the content of our privacy policy. We adapt it as soon as changes to our data processing make this necessary. We will inform you as soon as those changes require action on your part, such as giving consent, or where individual notification is otherwise required.
Where we provide addresses and contact details of companies and organisations in this privacy policy, please note that addresses may change over time and we ask you to verify the information before using them.