HAUFFEHAUFFE
ProductsHow It WorksKnowledgeReferencesAbout HAUFFE
Sign inGet startedEnglishDeutsch
ProductsHow It WorksKnowledgeReferencesAbout HAUFFESign inExecutive Discovery

HAUFFE Legal

Privacy Policy for hauffe.io and app.hauffe.io

Privacy Policy for hauffe.io and app.hauffe.io, including website, app, Customer Value Calculation, Stripe and HAUFFE Admin grants.

Last updated: 07 July 2026.

1. Controller

The controller responsible for processing personal data is:

Hauffe OS

Torben Hauffe

Am Karlsberg 18

26676 Barßel

Germany

Email: [email protected]

VAT ID: DE145207754

2. Data Protection Officer

No data protection officer is currently appointed.

3. General Information on Data Processing

We process personal data only to the extent necessary to provide our website, our application, perform contracts, handle billing, communicate, maintain security or comply with legal obligations.

Processing is carried out in particular on the basis of Art. 6(1)(b) GDPR, Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR.

4. Visiting hauffe.io

When visiting our website, technically necessary data may be processed, in particular IP address, date and time of access, browser type and version, operating system, referrer URL, pages accessed and technical log data.

Processing serves technical delivery, security, error analysis and stability of the website. The legal basis is Art. 6(1)(f) GDPR.

5. Use of app.hauffe.io

When using the application app.hauffe.io, we process in particular name, email address, company, user role, workspace affiliation, login and session data, invited departments and users, entries relating to customer value criteria, weightings, department answers, evaluations, segment logic, score logic, export data and technical protocol and security data.

Processing is carried out to provide the application, perform the contract, create evaluations and exports and secure and improve the application. The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.

6. Customer Value Calculation and Business Data

Hauffe OS processes data that customers or their users enter into the application. This may include business assessments, department evaluations, criteria, weightings, segmentations and evaluations.

The customer is responsible for ensuring that the data introduced by the customer may be processed lawfully and that no inadmissible or unnecessary personal data is entered.

Hauffe OS should generally not be used for special categories of personal data within the meaning of Art. 9 GDPR.

7. Payment Processing through Stripe

We use Stripe for payment processing, invoice creation, subscription management, payment method management and, where applicable, for the Stripe Customer Portal.

In connection with payment, in particular name, email address, billing address, company data, VAT ID or tax data, payment data, invoice data, product and package information, transaction data and technical data for fraud prevention and security may be processed.

Processing is carried out for contract performance and payment processing on the basis of Art. 6(1)(b) GDPR, to comply with legal obligations on the basis of Art. 6(1)(c) GDPR and for security and fraud prevention measures on the basis of Art. 6(1)(f) GDPR.

8. Stripe Customer Portal

Through the Stripe Customer Portal, customers can in particular view and download invoices, update payment details, manage or cancel subscriptions and update billing information.

Access to the Stripe Customer Portal is provided through server-side portal sessions. Data entered there is processed by Stripe.

9. HAUFFE Admin Grants

In certain cases, a HAUFFE Admin may manually grant access, for example for manual invoices, special agreements, demo access, goodwill, migration or support.

In this context, in particular workspace ID, the admin user's user ID, time of grant, reason for grant, term, package, number of departments and internal notes may be processed.

Processing serves contract performance, traceability, access control and prevention of misuse. The legal basis is Art. 6(1)(b) and Art. 6(1)(f) GDPR.

10. Email Communication

If you contact us by email, we process your information to handle the request. This includes in particular email address, name, company, message content and communication times.

The legal basis is Art. 6(1)(b) GDPR where the communication relates to a contract, and Art. 6(1)(f) GDPR for general communication.

11. Technically Necessary Cookies and Local Storage

Cookies or comparable technologies may be used for login, security, session management and technical functionality.

These are required to provide the application and securely authenticate users. The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.

12. Hosting and Technical Infrastructure

Technical service providers are used to provide the website and application. Server, log, security and connection data may be processed in this context.

Processing is carried out to provide, secure and stabilize the services. The legal basis is Art. 6(1)(f) GDPR.

13. Security and Log Data

For application security, we process technical log data, in particular to detect errors, misuse, unauthorized access or security incidents.

Processing is carried out on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR.

14. Processors and Recipients

Personal data may be transferred to technical service providers where this is necessary for operation, security, payment, support or contract processing.

This may include in particular hosting and infrastructure providers, payment service provider Stripe, email and communication services, security and monitoring services and technical development and support providers.

Where required, data processing agreements are concluded with processors.

15. Third-Country Transfers

When using international service providers, in particular Stripe or technical infrastructure providers, processing may take place outside the European Union or the European Economic Area.

Where data is transferred to third countries, this is done on the basis of appropriate safeguards, in particular standard contractual clauses, adequacy decisions or other mechanisms permitted under the GDPR.

16. Retention Period

We store personal data only for as long as necessary for the respective purposes.

For Hauffe OS, the general rule is storage during the active contract term, additionally during a reactivation window of 12 months after expiry and thereafter deletion or anonymization, unless statutory retention obligations prevent this.

Billing and invoice data may be stored for longer due to statutory retention obligations.

17. Rights of Data Subjects

Data subjects have, in accordance with the GDPR, in particular the right of access, rectification, deletion, restriction of processing, data portability, objection, withdrawal of consent and complaint to a data protection supervisory authority.

Requests can be sent to [email protected].

18. Right to Lodge a Complaint

Data subjects have the right to lodge a complaint with a data protection supervisory authority if they believe that the processing of their personal data violates data protection law.

19. Changes to this Privacy Policy

We may update this Privacy Policy if technical, legal or organizational changes occur.

The current version is available on hauffe.io or app.hauffe.io.

HAUFFEHAUFFE
HomeExecutive DiscoveryProductsPricingKnowledgeFrameworksInsightsReferencesCustomer Value ManagementExecutive inquiries[email protected]Legal NoticePrivacyTerms and ConditionsCookies
© 2026 HAUFFEBuilding Better Decisions.

HAUFFE

Cookie settings

We use necessary technologies to operate this website. Analytics and marketing are only used if you consent. Privacy Policy

HAUFFE

Cookie settings

Necessary

Required for language preference, security and core website functions.

Analytics

Helps us understand how the website is used and which content is relevant.

Marketing

Enables future campaign measurement and relevant communication.

Privacy Policy