Zealience logo

Privacy Policy

For our customers and their contact persons

Preamble

With this privacy policy we inform you about the types of personal data (hereinafter referred to as "data") we process, for what purposes and to what extent, in the context of our business relationship with you.

This policy applies to our customers and to the individual contact persons acting on their behalf — for example the people who negotiate, sign or administer a contract with us, or who contact us for support. A separate privacy notice applies to visitors to our website and prospective customers.

The terms used are not gender-specific.

Status: 8 September 2026

Content overview

  • Preamble
  • Controller
  • Our software: we have no access to your data
  • Overview of processing
  • Legal bases
  • Recipients and processors
  • Transfers to third countries
  • Conclusion of the contract
  • Delivery of the software and licence management
  • Customer support
  • Invoicing, accounting and tax
  • Termination of the contract
  • Deletion of data
  • Your rights as a data subject
  • Data protection officer
  • No automated decision-making
  • Changes and updates to this privacy policy

Controller (referred to as the "controller" in the GDPR)

The data processing controller is:

Zealience GmbH

Neue Mainzer Straße 84, 60311 Frankfurt am Main, Germany

zealience.com

Our software: we have no access to your data

Z-CMS is deployed entirely within your own infrastructure. We have no connection to your instance, we receive no telemetry from it, and we have no access to the database, the authentication system or the user accounts within it.

This means that the personal data you and your users enter into Z-CMS is processed exclusively by you, under your own responsibility. We are not a processor in respect of that data, and no data processing agreement pursuant to Art. 28 GDPR is required between us for the operation of the software.

This privacy policy therefore covers only the data that arises from our business relationship with you — the contract, its administration, and the support we provide.

Support files: If you send us log files, screenshots or other materials for troubleshooting, those materials come into our possession. Z-CMS is designed so that its log files do not contain data identifying individuals: log entries are intended to reference internal user identifiers rather than user names, and not to include email addresses, IP addresses, MAC addresses or location data. Internal user identifiers can be resolved only by you, not by us. Our development guidelines require that no data identifying individuals is written to the log.

We cannot, however, entirely rule this out in an individual case. For that reason, and as set out in our service level agreement, it remains your responsibility to review log files before disclosing them to us. We ask you to apply the same care to screenshots and other materials, and to redact any data identifying individuals before sending it. Where such data nevertheless reaches us, we process it only for the purpose of resolving your request and delete it on request as far as we are technically able.

Overview of processing

Types of processed data

  • Contact data (e.g. name, job title, business email address, telephone number)
  • Content data (e.g. the content of your enquiries, support requests and meeting minutes)
  • Technical and communication data (e.g. the dates and times of emails, calls and meetings; the connection data generated when you join an online meeting; the audit trail recorded when a contract is signed electronically, including the signatory's IP address; and the record of when a download link was opened)

Categories of data subjects

  • Contact persons acting on behalf of our customers

Purposes of processing

  • Conclusion, performance and administration of contracts
  • Delivery of our software and licence management
  • Customer support and technical assistance
  • Invoicing, accounting and compliance with tax obligations
  • Establishment, exercise and defence of legal claims

Legal bases

Legitimate interests (Art. 6(1)(f) GDPR): Our contracts are concluded with organisations, not with individuals. The individual contact persons acting on a customer's behalf are therefore not themselves parties to the contract, and we process their data on the basis of our legitimate interest in performing and administering the contract with their organisation, in communicating with the right people and in maintaining the business relationship. We also rely on this basis for the establishment, exercise and defence of legal claims. This is the principal legal basis for the processing described in this policy.

Legal obligation (Art. 6(1)(c) GDPR): Processing is necessary in order to comply with legal obligations to which we are subject, in particular commercial and tax law retention and accounting obligations.

Consent (Art. 6(1)(a) GDPR): Where we ask for your consent — for example before recording a support call at your request — processing is based on that consent, which you may withdraw at any time with effect for the future.

National data protection rules in Germany: In addition to the GDPR, national rules on data protection apply in Germany, in particular the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG).

Recipients and processors

We use carefully selected service providers who process data on our behalf. Contracts pursuant to Art. 28 GDPR are in place with all of them.

  • Communication and productivity services provider — email, appointment scheduling, online meetings, document creation and document storage. Data is stored in Germany.
  • Customer relationship management provider — recording and tracking of the business relationship. Data is stored in Germany.
  • Invoicing and accounting software provider — preparation of quotations and invoices. Data is stored in Germany.
  • Electronic signature service — signature of contracts. Data is stored within the European Union.
  • Secure file sharing service — delivery of our software, documentation and licence keys. Data is stored within the European Union.
  • Telephone answering service — answers calls to our published number on our behalf. Data is processed in Germany.
  • Issue tracking service — recording of defect reports and feature requests relating to our software. Data is stored in the United States.

In addition, we transmit invoicing and accounting data to our tax advisers, who process it under their own responsibility in accordance with their professional obligations. They are not our processors.

Beyond this, we do not disclose your data to third parties unless we are legally obliged to do so or unless disclosure is necessary for the establishment, exercise or defence of legal claims.

Transfers to third countries

The service providers we use to administer our business relationship with you store data within the European Union, and Germany in particular.

An exception is our issue tracking service, which stores data in the United States. Where we record a request from you as an issue in that system, the data described under "Customer support" below is transferred there. This transfer takes place on the basis of Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.

Where our other providers transfer data to a third country in exceptional cases — for example where support personnel outside the EU are involved — such transfers take place on the basis of an adequacy decision by the European Commission or of Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.

Conclusion of the contract

In order to prepare a quotation, we process the name and contact details of the person handling the matter on your side. Quotations are prepared using our invoicing software and sent to you by email.

Where you issue us with a purchase order, we store it in our customer relationship management system and in our document storage.

Contracts are sent to you for electronic signature. In the course of the signature process, the signature service provider records the information necessary to evidence the signature, in particular the name and email address of the signatory, the time of signature and the signatory's IP address. This audit trail forms part of the signed document.

  • Legal basis: legitimate interests (Art. 6(1)(f) GDPR) in the conclusion and administration of the contract with your organisation
  • Retention: contracts and the associated signature records are retained for the duration of the contractual relationship and thereafter in accordance with the statutory retention periods and for as long as necessary for the establishment, exercise or defence of legal claims

Delivery of the software and licence management

We deliver our software and related materials through a secure file sharing platform, by means of a one-time link that we send to you by email. You do not need to create an account with that service, and we do not enter your data into it. The link is bound to the device on which it is first opened, and it expires automatically after a period we set for each delivery. There is no option to create a link that does not expire. The service provider operates a zero-knowledge architecture and cannot read the content shared.

  • Legal basis: legitimate interests (Art. 6(1)(f) GDPR) in the performance of the contract with your organisation
  • Retention: the shared link and its access record expire automatically at the end of the period set for the delivery concerned. Licence records are retained for the duration of the contractual relationship and thereafter for as long as necessary for the establishment, exercise or defence of legal claims

Customer support

You can reach us for support by email or telephone, or by booking an online meeting through the scheduling link we provide.

Calls to our published telephone number are answered on our behalf by an external telephone answering service, whose role is limited to establishing who is calling and why, so that the call can be directed to the right person. Further details of that processing, including how the call note is produced, are set out in our privacy policy for website visitors and prospective customers.

Meetings: Support meetings take place via an online meeting service. We record the connection data, the name displayed by each participant and any content shared in the meeting chat. We do not record support calls, unless you expressly ask us to. Where a recording is made at your request, we obtain the agreement of every participant before starting, and the recording is made and used for your purposes; we delete our own copy once it has been provided to you. Recordings are made on the basis of consent under Art. 6(1)(a) GDPR, which may be withdrawn at any time with effect for the future.

Documentation of enquiries: We log support enquiries and calls in our customer relationship management system so that we can trace the history of your requests and provide continuity of support. Minutes of meetings are written manually by us; we do not use AI tools to produce them.

Feature requests and defect reports: Where your enquiry concerns a change to or a defect in our software, we create an entry in our issue tracking system. So that we can attribute the request and inform you once it has been implemented, that entry contains the first name of the person making the request, the name of your organisation and the technical content of the request. We do not transfer signature blocks or other contact details to that system. Our issue tracking system is operated in the United States; see "Transfers to third countries" above.

  • Legal basis: legitimate interests (Art. 6(1)(f) GDPR) in providing effective support and in the further development of our software. Recordings: consent (Art. 6(1)(a) GDPR)
  • Retention: support correspondence and records are retained for the duration of the contractual relationship and thereafter for as long as necessary for the establishment, exercise or defence of legal claims and to comply with statutory retention obligations. Issue tracking entries are retained for as long as they are relevant to the development and maintenance of the software

Invoicing, accounting and tax

We issue invoices using our invoicing system and transmit the resulting accounting data to our tax advisers, who carry out the bookkeeping. In this context we process the details of your organisation together with the name and contact details of the person handling the matter.

  • Legal basis: legal obligation (Art. 6(1)(c) GDPR) in respect of our commercial and tax law obligations, together with our legitimate interests (Art. 6(1)(f) GDPR) in the proper administration of the business relationship
  • Retention: accounting records, invoices and the associated documents are retained for the statutory retention periods, in particular the ten-year periods under § 147 AO and § 257 HGB

Termination of the contract

When a contract ends, we ask you to delete the software and the associated documentation and to confirm to us that you have done so. We record that confirmation.

We do not delete concluded contracts, the associated correspondence or the record of enquiries handled at the end of the contractual relationship. We retain them so that, in the event of a subsequent dispute, we are able to establish what was agreed and what took place.

Deletion of data

Data processed by us is deleted in accordance with legal requirements as soon as the purpose of the processing no longer applies, the consent permitting it is withdrawn, or other permissions cease to apply.

Where data is not deleted because it is required for other, legally permissible purposes, its processing is restricted to those purposes. This applies in particular to data that must be retained for commercial or tax law reasons, and to data whose storage is necessary for the establishment, exercise or defence of legal claims.

The criteria we apply in determining how long data relating to a contractual relationship is retained are the duration of the relationship itself, the statutory retention periods that follow it — in particular the ten-year periods under § 147 AO and § 257 HGB — and the periods within which legal claims arising from the relationship may still be brought. The retention periods and criteria stated in the individual sections of this policy apply in the first instance.

Your rights as a data subject

You have the following rights under Art. 15 to 21 GDPR:

Right to object (Art. 21 GDPR): You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to such processing.

Right of access (Art. 15 GDPR): You have the right to request confirmation as to whether data concerning you is being processed, and to obtain information about that data as well as further information and a copy of the data.

Right to rectification (Art. 16 GDPR): You have the right to request the correction of inaccurate data concerning you or the completion of incomplete data.

Right to erasure and to restriction of processing (Art. 17, 18 GDPR): You have the right to request that data concerning you be erased without undue delay, or alternatively to request a restriction of its processing.

Right to data portability (Art. 20 GDPR): You have the right to receive data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request its transmission to another controller.

Right to withdraw consent (Art. 7(3) GDPR): Where processing is based on your consent, you have the right to withdraw that consent at any time with effect for the future.

To exercise these rights, please contact us at .

Right to lodge a complaint: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR.

The supervisory authority responsible for us is:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit

Gustav-Stresemann-Ring 1

65189 Wiesbaden, Germany

Data protection officer

We are not required to appoint a data protection officer. For all questions concerning the processing of your personal data, please contact us at .

No automated decision-making

We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

Change and update of the privacy policy

We ask you to inform yourself regularly about the content of our privacy policy. We adapt it as soon as changes to our data processing make this necessary. We will inform you as soon as those changes require action on your part, such as giving consent, or where individual notification is otherwise required.

Where we provide addresses and contact details of companies and organisations in this privacy policy, please note that addresses may change over time and we ask you to verify the information before using them.