Privacy Policy
Last updated: [DATE]
We take the protection of your personal data seriously. This policy explains what data we process when you visit our website and when you use Zoomaa AI, on what legal basis, and what rights you have under the EU General Data Protection Regulation (GDPR / DSGVO).
1. Controller
The controller responsible for data processing on this website is:
- Company
- [LEGAL COMPANY NAME]
- Address
- [STREET, POSTCODE, CITY, COUNTRY]
- [EMAIL ADDRESS]
- Phone
- [PHONE NUMBER]
2. Data protection officer
[If you are required to appoint a Data Protection Officer (DPO), name and contact details go here. A DPO is generally required under Section 38 BDSG if at least 20 people are permanently engaged in the automated processing of personal data, or where large-scale or particularly sensitive processing takes place. If no DPO is required, state that no DPO has been appointed and remove this block.]
3. Your rights as a data subject
You have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR): to obtain confirmation of whether we process your data and to receive a copy.
- Right to rectification (Art. 16 GDPR): to have inaccurate data corrected.
- Right to erasure (Art. 17 GDPR): to have your data deleted, provided no retention obligations apply.
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 20 GDPR): to receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21 GDPR): to object to processing based on legitimate interests, including profiling and direct marketing.
- Right to withdraw consent (Art. 7(3) GDPR): with effect for the future, at any time.
- Right to lodge a complaint (Art. 77 GDPR): with a supervisory authority, in particular in the member state of your residence, place of work or the place of the alleged infringement.
To exercise any of these rights, contact us at [EMAIL ADDRESS].
4. Hosting and server log files
Our website is hosted by [HOSTING PROVIDER, ADDRESS]. When you visit this site, the provider's servers automatically collect and store information in server log files that your browser transmits, namely:
- Browser type and version
- Operating system used
- Referrer URL
- Host name of the accessing device
- Date and time of the server request
- IP address (as a rule shortened / anonymised)
This data is not merged with other data sources. It is processed on the basis of Art. 6(1)(f) GDPR, our legitimate interest in the technically error-free presentation and security of our website. Log data is deleted after [e.g. 7 / 30 days].
Where required, we have concluded a data processing agreement (Auftragsverarbeitungsvertrag, Art. 28 GDPR) with our hosting provider.
5. Cookies and consent
Our website uses cookies and comparable technologies. Technically necessary cookies, which are required to operate the site, are used on the basis of Art. 6(1)(f) GDPR and Section 25(2) TDDDG (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz); these do not require consent.
All non-essential cookies, in particular for analytics and marketing, are only set once you have given your explicit consent via our cookie banner, pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future via [LINK / COOKIE SETTINGS].
6. Contact requests and demo bookings
If you contact us by email, contact form or by booking a demo, we process the data you provide (such as name, email address, company and the content of your message) in order to handle your request.
The legal basis is Art. 6(1)(b) GDPR where your request relates to the performance of a contract or pre-contractual measures, and otherwise Art. 6(1)(f) GDPR, our legitimate interest in responding to enquiries. We retain this data until your request has been dealt with, unless statutory retention periods (see section 10) apply.
7. Using the Zoomaa AI service
When you create an account and use Zoomaa AI, we process the following data in order to provide the service:
- Account data: name, email address, password (stored hashed), company, billing details.
- Content data: the posts, comments, messages and automation rules you create or schedule.
- LinkedIn data: where you connect a LinkedIn account, the access tokens and the data required to publish posts, read comments on your posts, and send messages on your behalf.
- Usage data: log data on how the service is used, for security and troubleshooting.
The legal basis for this processing is Art. 6(1)(b) GDPR (performance of the contract with you).
Data of third parties (your leads)
Zoomaa AI processes personal data of people who interact with your LinkedIn content, for example the name, profile information and comment or message content of a person who comments on your post.
8. Payment processing
For paid plans we use the payment service provider [e.g. Stripe Payments Europe Ltd., Dublin, Ireland]. Your payment details are transmitted directly to the provider; we do not store full payment card data ourselves. The legal basis is Art. 6(1)(b) GDPR.
9. Analytics
[If you use analytics, name the tool here, e.g. Google Analytics / Plausible / Matomo, the provider and address, what it collects, whether IP addresses are anonymised, the retention period, and the opt-out. Analytics that is not strictly necessary requires prior consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG. If you do not use analytics at all, replace this section with a sentence stating that.]
10. Retention periods
We store personal data only for as long as is necessary for the purposes described, or as long as statutory retention obligations require. Under German commercial and tax law, retention periods of 6 or 10 years apply in particular to accounting-relevant documents (Section 257 HGB, Section 147 AO). Once the purpose ceases to apply and no retention obligation exists, the data is deleted or anonymised.
11. Recipients and transfers to third countries
We only pass on personal data where this is necessary, for example to IT service providers, hosting and payment providers, all of whom are bound by data processing agreements pursuant to Art. 28 GDPR.
Where data is transferred to a country outside the EU/EEA, we ensure an adequate level of protection, in particular through an adequacy decision of the European Commission (Art. 45 GDPR) or through the EU Standard Contractual Clauses (Art. 46 GDPR) together with any additional measures required.
Current recipients: [LIST YOUR PROCESSORS, e.g. hosting, email, payment, analytics, CRM].
12. Data security
We use appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect your data against manipulation, loss and unauthorised access. This includes TLS encryption of data in transit, access controls and regular review of our measures.
13. Changes to this policy
We may update this privacy policy so that it always reflects current legal requirements or changes to our services. The current version always applies and can be accessed on this page.