Datenschutzerklarung

Privacy Policy

Last updated: 5 August 2026

We take the protection of your personal data seriously. This policy explains what data we process when you visit our website and when you use Zoomaa AI, on what legal basis, and what rights you have under the EU General Data Protection Regulation (GDPR / DSGVO).

1. Controller

The controller responsible for data processing on this website is:

Name
Jan Kozak-Giegerich
Address
Heinrich-Heine-Str. 11, 64319 Pfungstadt, Deutschland

2. Data protection officer

A Data Protection Officer is not required and has not been appointed.

3. Your rights as a data subject

You have the following rights regarding your personal data:

To exercise any of these rights, please contact us using the details in our Impressum.

Right to object (Art. 21 GDPR). Where we process your data on the basis of a legitimate interest, you have the right to object at any time on grounds relating to your particular situation. If you object to processing for direct marketing purposes, we will stop that processing immediately and without needing a reason.

4. Hosting and server log files

Our website is hosted by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. When you visit this site, the provider's servers automatically collect and store information in server log files that your browser transmits, namely:

This data is not merged with other data sources. It is processed on the basis of Art. 6(1)(f) GDPR, our legitimate interest in the technically error-free presentation and security of our website. Log data is retained only for as long as necessary for these purposes and is then deleted.

Where required, we have concluded a data processing agreement (Auftragsverarbeitungsvertrag, Art. 28 GDPR) with our hosting provider.

5. Cookies and consent

Our website uses cookies and comparable technologies. Technically necessary cookies, which are required to operate the site, are used on the basis of Art. 6(1)(f) GDPR and Section 25(2) TDDDG (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz); these do not require consent.

All non-essential cookies, in particular for analytics and marketing, are only set once you have given your explicit consent via our cookie banner, pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future.

6. Contact requests and demo bookings

If you contact us by email, contact form or by booking a demo, we process the data you provide (such as name, email address, company and the content of your message) in order to handle your request.

The legal basis is Art. 6(1)(b) GDPR where your request relates to the performance of a contract or pre-contractual measures, and otherwise Art. 6(1)(f) GDPR, our legitimate interest in responding to enquiries. We retain this data until your request has been dealt with, unless statutory retention periods (see section 10) apply.

7. Using the Zoomaa AI service

When you create an account and use Zoomaa AI, we process the following data in order to provide the service:

The legal basis for this processing is Art. 6(1)(b) GDPR (performance of the contract with you).

Data of third parties (your leads)

Zoomaa AI processes personal data of people who interact with your LinkedIn content, for example the name, profile information and comment or message content of a person who comments on your post.

In relation to this data, you are the controller and we act as a processor on your behalf pursuant to Art. 28 GDPR. We therefore conclude a data processing agreement (DPA) with you, and we process this data only on your documented instructions. You are responsible for having a valid legal basis for contacting these people, in particular where you send direct messages for marketing purposes.

8. Payment processing

For paid plans, payment is handled by a third-party payment service provider. Your payment details are transmitted directly to that provider; we do not store full payment card data ourselves. The legal basis is Art. 6(1)(b) GDPR.

9. Analytics

We do not currently use third-party web analytics on this website.

10. Retention periods

We store personal data only for as long as is necessary for the purposes described, or as long as statutory retention obligations require. Under German commercial and tax law, retention periods of 6 or 10 years apply in particular to accounting-relevant documents (Section 257 HGB, Section 147 AO). Once the purpose ceases to apply and no retention obligation exists, the data is deleted or anonymised.

11. Recipients and transfers to third countries

We only pass on personal data where this is necessary, for example to IT service providers, hosting and payment providers, all of whom are bound by data processing agreements pursuant to Art. 28 GDPR.

Where data is transferred to a country outside the EU/EEA, we ensure an adequate level of protection, in particular through an adequacy decision of the European Commission (Art. 45 GDPR) or through the EU Standard Contractual Clauses (Art. 46 GDPR) together with any additional measures required.

Current recipients: Cloudflare, Inc. (website hosting).

12. Data security

We use appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect your data against manipulation, loss and unauthorised access. This includes TLS encryption of data in transit, access controls and regular review of our measures.

13. Changes to this policy

We may update this privacy policy so that it always reflects current legal requirements or changes to our services. The current version always applies and can be accessed on this page.