1. Controller
The controller responsible for processing personal data is:
Hauffe OS
Torben Hauffe
Am Karlsberg 18
26676 Barßel
Germany
Email: [email protected]
VAT ID: DE145207754
HAUFFEHAUFFE Legal
Privacy Policy for hauffe.io and app.hauffe.io, including website, app, Customer Value Calculation, Stripe and HAUFFE Admin grants.
The controller responsible for processing personal data is:
Hauffe OS
Torben Hauffe
Am Karlsberg 18
26676 Barßel
Germany
Email: [email protected]
VAT ID: DE145207754
No data protection officer is currently appointed.
We process personal data only to the extent necessary to provide our website, our application, perform contracts, handle billing, communicate, maintain security or comply with legal obligations.
Processing is carried out in particular on the basis of Art. 6(1)(b) GDPR, Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR.
When visiting our website, technically necessary data may be processed, in particular IP address, date and time of access, browser type and version, operating system, referrer URL, pages accessed and technical log data.
Processing serves technical delivery, security, error analysis and stability of the website. The legal basis is Art. 6(1)(f) GDPR.
When using the application app.hauffe.io, we process in particular name, email address, company, user role, workspace affiliation, login and session data, invited departments and users, entries relating to customer value criteria, weightings, department answers, evaluations, segment logic, score logic, export data and technical protocol and security data.
Processing is carried out to provide the application, perform the contract, create evaluations and exports and secure and improve the application. The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.
Hauffe OS processes data that customers or their users enter into the application. This may include business assessments, department evaluations, criteria, weightings, segmentations and evaluations.
The customer is responsible for ensuring that the data introduced by the customer may be processed lawfully and that no inadmissible or unnecessary personal data is entered.
Hauffe OS should generally not be used for special categories of personal data within the meaning of Art. 9 GDPR.
We use Stripe for payment processing, invoice creation, subscription management, payment method management and, where applicable, for the Stripe Customer Portal.
In connection with payment, in particular name, email address, billing address, company data, VAT ID or tax data, payment data, invoice data, product and package information, transaction data and technical data for fraud prevention and security may be processed.
Processing is carried out for contract performance and payment processing on the basis of Art. 6(1)(b) GDPR, to comply with legal obligations on the basis of Art. 6(1)(c) GDPR and for security and fraud prevention measures on the basis of Art. 6(1)(f) GDPR.
Through the Stripe Customer Portal, customers can in particular view and download invoices, update payment details, manage or cancel subscriptions and update billing information.
Access to the Stripe Customer Portal is provided through server-side portal sessions. Data entered there is processed by Stripe.
In certain cases, a HAUFFE Admin may manually grant access, for example for manual invoices, special agreements, demo access, goodwill, migration or support.
In this context, in particular workspace ID, the admin user's user ID, time of grant, reason for grant, term, package, number of departments and internal notes may be processed.
Processing serves contract performance, traceability, access control and prevention of misuse. The legal basis is Art. 6(1)(b) and Art. 6(1)(f) GDPR.
If you contact us by email, we process your information to handle the request. This includes in particular email address, name, company, message content and communication times.
The legal basis is Art. 6(1)(b) GDPR where the communication relates to a contract, and Art. 6(1)(f) GDPR for general communication.
Cookies or comparable technologies may be used for login, security, session management and technical functionality.
These are required to provide the application and securely authenticate users. The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.
Technical service providers are used to provide the website and application. Server, log, security and connection data may be processed in this context.
Processing is carried out to provide, secure and stabilize the services. The legal basis is Art. 6(1)(f) GDPR.
For application security, we process technical log data, in particular to detect errors, misuse, unauthorized access or security incidents.
Processing is carried out on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR.
Personal data may be transferred to technical service providers where this is necessary for operation, security, payment, support or contract processing.
This may include in particular hosting and infrastructure providers, payment service provider Stripe, email and communication services, security and monitoring services and technical development and support providers.
Where required, data processing agreements are concluded with processors.
When using international service providers, in particular Stripe or technical infrastructure providers, processing may take place outside the European Union or the European Economic Area.
Where data is transferred to third countries, this is done on the basis of appropriate safeguards, in particular standard contractual clauses, adequacy decisions or other mechanisms permitted under the GDPR.
We store personal data only for as long as necessary for the respective purposes.
For Hauffe OS, the general rule is storage during the active contract term, additionally during a reactivation window of 12 months after expiry and thereafter deletion or anonymization, unless statutory retention obligations prevent this.
Billing and invoice data may be stored for longer due to statutory retention obligations.
Data subjects have, in accordance with the GDPR, in particular the right of access, rectification, deletion, restriction of processing, data portability, objection, withdrawal of consent and complaint to a data protection supervisory authority.
Requests can be sent to [email protected].
Data subjects have the right to lodge a complaint with a data protection supervisory authority if they believe that the processing of their personal data violates data protection law.
We may update this Privacy Policy if technical, legal or organizational changes occur.
The current version is available on hauffe.io or app.hauffe.io.