HAUFFEHAUFFE
ProductsHow It WorksKnowledgeReferencesAbout HAUFFE
Sign inGet startedEnglishDeutsch
ProductsHow It WorksKnowledgeReferencesAbout HAUFFESign inExecutive Discovery

HAUFFE Legal

Privacy Policy for hauffe.io and app.hauffe.io

Privacy Policy for hauffe.io and app.hauffe.io, including website, app, Customer Value Calculation, Deal Win Engine, HubSpot integration, Stripe and HAUFFE Admin grants.

Last updated: 15 August 2026.

1. Controller

The controller responsible for processing personal data is:

Hauffe OS

Torben Hauffe

Am Karlsberg 18

26676 Barßel

Germany

Email: [email protected]

VAT ID: DE145207754

2. Data Protection Officer

No data protection officer is currently appointed.

3. General Information on Data Processing

We process personal data only to the extent necessary to provide our website, our application, perform contracts, handle billing, communicate, maintain security or comply with legal obligations.

Processing is carried out in particular on the basis of Art. 6(1)(b) GDPR, Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR.

4. Visiting hauffe.io

When visiting our website, technically necessary data may be processed, in particular IP address, date and time of access, browser type and version, operating system, referrer URL, pages accessed and technical log data.

Processing serves technical delivery, security, error analysis and stability of the website. The legal basis is Art. 6(1)(f) GDPR.

5. Use of app.hauffe.io

When using the application app.hauffe.io, we process in particular name, email address, company, user role, workspace affiliation, login and session data, invited departments and users, entries relating to customer value criteria, weightings, department answers, evaluations, segment logic, score logic, export data and technical protocol and security data.

Processing is carried out to provide the application, perform the contract, create evaluations and exports and secure and improve the application. The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.

6. HubSpot Integration / HAUFFE OS Deal Win Engine

Where HAUFFE OS Deal Win Engine is connected to HubSpot, the integration may process in particular HubSpot portal or account context, installation status, OAuth and connection metadata, necessary technical identifiers, authorized permissions, technical status and error data as well as CRM data.

CRM data processed for the provided functions may include in particular deal data, deal name, deal stage or pipeline context, amounts and relevant deal properties, linked contacts, linked companies and other CRM properties relevant for the booked function.

In addition, Deal Win Engine may process customer value context, budget status, decision authority, influence, decision process, buying role, stakeholder evidence, communication profiles or DISC-related information, further Deal Win signals maintained by the user, assessment score, closing probability, risk level, recommendations, next actions and, where used, improvement or simulation results. Where technically provided, stored assessment history as well as writeback and connection metadata may also be processed.

Data may flow both from HubSpot to HAUFFE OS and from HAUFFE OS to HubSpot. HAUFFE OS reads deals, contacts, companies and relevant properties to provide Deal Win Engine. User-maintained inputs as well as approved or designated result fields may, depending on the function, be written back to HubSpot.

Authorization is performed through HubSpot OAuth. HAUFFE does not process HubSpot passwords. Access is limited to the granted permissions. OAuth tokens are stored with technical safeguards and may be refreshed where necessary to maintain the connection. If authorization is revoked or the app is uninstalled, the connection is deactivated and further access through that connection ends.

Processing serves in particular the provision of the HubSpot integration, the execution of deal assessments, the display of deal risks, the provision of recommendations, stakeholder, customer value and communication context, the storage or synchronization of user inputs, troubleshooting, security, support, abuse prevention and technical administration.

Depending on the contractual and factual processing setup, HAUFFE may act either as controller or as processor for the relevant business customer in relation to the customer's CRM data. Where required, data processing agreements can be concluded.

Depending on the specific processing, relevant legal bases may include in particular Art. 6(1)(b) GDPR for contract-related services, Art. 6(1)(f) GDPR for security, operations, support and abuse prevention, and Art. 28 GDPR for processing on behalf of the business customer.

HubSpot is an independent provider and processes data within its own services under the agreements in place with the respective HubSpot customer. HAUFFE is not responsible for all processing performed independently by HubSpot outside the HAUFFE integration.

7. Customer Value Calculation and Business Data

HAUFFE OS processes data that customers or their users enter into the application. This may include business assessments, department evaluations, criteria, weightings, segmentations and evaluations.

The customer is responsible for ensuring that the data introduced by the customer may be processed lawfully and that no inadmissible or unnecessary personal data is entered.

HAUFFE OS should generally not be used for special categories of personal data within the meaning of Art. 9 GDPR.

8. Payment Processing through Stripe

We use Stripe for payment processing, invoice creation, subscription management, payment method management and, where applicable, for the Stripe Customer Portal.

In connection with payment, in particular name, email address, billing address, company data, VAT ID or tax data, payment data, invoice data, product and package information, transaction data and technical data for fraud prevention and security may be processed.

Processing is carried out for contract performance and payment processing on the basis of Art. 6(1)(b) GDPR, to comply with legal obligations on the basis of Art. 6(1)(c) GDPR and for security and fraud prevention measures on the basis of Art. 6(1)(f) GDPR.

9. Stripe Customer Portal

Through the Stripe Customer Portal, customers can in particular view and download invoices, update payment details, manage or cancel subscriptions and update billing information.

Access to the Stripe Customer Portal is provided through server-side portal sessions. Data entered there is processed by Stripe.

10. HAUFFE Admin Grants

In certain cases, a HAUFFE Admin may manually grant access, for example for manual invoices, special agreements, demo access, goodwill, migration or support.

In this context, in particular workspace ID, the admin user's user ID, time of grant, reason for grant, term, package, number of departments and internal notes may be processed.

Processing serves contract performance, traceability, access control and prevention of misuse. The legal basis is Art. 6(1)(b) and Art. 6(1)(f) GDPR.

11. Email Communication

If you contact us by email, we process your information to handle the request. This includes in particular email address, name, company, message content and communication times.

The legal basis is Art. 6(1)(b) GDPR where the communication relates to a contract, and Art. 6(1)(f) GDPR for general communication.

12. Technically Necessary Cookies and Local Storage

Cookies or comparable technologies may be used for login, security, session management and technical functionality.

These are required to provide the application and securely authenticate users. The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.

13. Hosting and Technical Infrastructure

Technical service providers are used to provide the website and application. Server, log, security and connection data may be processed in this context.

Processing is carried out to provide, secure and stabilize the services. The legal basis is Art. 6(1)(f) GDPR.

14. Security and Log Data

For application security, we process technical log data, in particular to detect errors, misuse, unauthorized access or security incidents.

Processing is carried out on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR.

15. Processors and Recipients

Personal data may be transferred to technical service providers where this is necessary for operation, security, payment, support or contract processing.

This may include in particular hosting and infrastructure providers, HubSpot, payment service provider Stripe, email and communication services, security and monitoring services and technical development and support providers.

Where required, data processing agreements are concluded with processors.

16. Third-Country Transfers

When using international service providers, in particular HubSpot, Stripe or technical infrastructure providers, processing may take place outside the European Union or the European Economic Area.

Where data is transferred to third countries, this is done on the basis of appropriate safeguards, in particular standard contractual clauses, adequacy decisions or other mechanisms permitted under the GDPR.

17. Retention Period

We store personal data only for as long as necessary for the respective purposes.

Connection and OAuth data are not stored longer than necessary to provide and secure the integration. After revocation or uninstallation, no further access takes place through the disconnected HubSpot connection. Uninstallation does not automatically delete all data already stored in HAUFFE systems.

For HAUFFE OS, the general rule otherwise is storage during the active contract term, additionally during a reactivation window of 12 months after expiry and thereafter deletion or anonymization, unless statutory retention obligations prevent this.

Billing and invoice data may be stored for longer due to statutory retention obligations.

18. Rights of Data Subjects

Data subjects have, in accordance with the GDPR, in particular the right of access, rectification, deletion, restriction of processing, data portability, objection, withdrawal of consent and complaint to a data protection supervisory authority.

Requests can be sent to [email protected].

19. Right to Lodge a Complaint

Data subjects have the right to lodge a complaint with a data protection supervisory authority if they believe that the processing of their personal data violates data protection law.

20. Changes to this Privacy Policy

We may update this Privacy Policy if technical, legal or organizational changes occur.

The current version is available on hauffe.io or app.hauffe.io.

HAUFFEHAUFFE
HomeExecutive DiscoveryProductsPricingKnowledgeFrameworksInsightsReferencesCustomer Value ManagementExecutive inquiries[email protected]Legal NoticePrivacyTerms and ConditionsCookies
© 2026 HAUFFEBuilding Better Decisions.

HAUFFE

Cookie settings

We use necessary technologies to operate this website. Analytics and marketing are only used if you consent. Privacy Policy

HAUFFE

Cookie settings

Necessary

Required for language preference, security and core website functions.

Analytics

Helps us understand how the website is used and which content is relevant.

Marketing

Enables future campaign measurement and relevant communication.

Privacy Policy