Legal

Privacy policy

What we record when you visit this website, what we process on behalf of customers inside the application, on which legal basis, for how long, and how you exercise your rights under the GDPR.

  • Application data is hosted in the European Union
  • No third-party advertising, analytics or tracking services on this website
  • No external font, script or icon CDNs — assets are served from our own infrastructure
  • A data processing agreement under Art. 28 GDPR is offered to every customer

Questions

Asked by data protection officers and by visitors

Does this website use cookies, analytics or tracking?

It uses only strictly necessary cookies and session storage for session handling, load balancing and protection against cross-site request forgery. There is no advertising network, no analytics or statistics service, no tag manager, no social media plugin and no cross-site tracking. Fonts and scripts are served from our own infrastructure, so no external CDN receives your IP address.

Where is my data stored, and does it leave the EU?

Application data is hosted in data centres inside the European Union. Documents and attachments are held in EU-region object storage, encrypted in transit and at rest. We do not transfer personal data outside the EU or EEA without a valid transfer mechanism under Chapter V GDPR. Any processor operating outside the EEA is named in our sub-processor list with the safeguard relied on.

Do you offer a data processing agreement under Art. 28 GDPR?

Yes. A data processing agreement, in German an Auftragsverarbeitungsvertrag, is offered to and concluded with every customer before processing begins. It covers instructions, confidentiality, technical and organisational measures, sub-processors, assistance with data subject requests, and return or deletion at the end of the contract. Ask for the current template through the contact page.

I am a tenant. Who do I contact about my data?

Your landlord or managing agent, not us. They operate the workspace, decide what is recorded in it and are the controller for it. We process that data only on their documented instructions as a processor. If you cannot identify the controller, write to us with what you know and we will forward your request rather than answer it ourselves.

How long is server log data kept?

Server log data is retained for the period stated in the retention table on this page and then deleted automatically by rotation. A log segment is kept longer only where it forms part of a documented security incident, and only for as long as that incident is being investigated or defended. Logs are not merged with other data sources or used to profile visitors.

What happens to our data when we stop using the service?

You can export your data during the agreed export window after termination. Once that window closes, we delete or return the data as instructed under the data processing agreement, and it disappears from backups as the backup generation rotates out. The commercial detail, including the length of the window, is set out in the terms and conditions.

Due diligence

Questions a policy page cannot answer

If your data protection officer needs the processor list, the technical and organisational measures or the current DPA template before a decision, ask and we will send them.