Privacy Policy
This Privacy Policy explains how DLEGATE Solutions GmbH ("DLEGATE", "we", "us") processes Personal Data when you use our website, register for an account, or use our software services.
The term "Personal Data" refers to any information relating to an identified or identifiable natural person, as defined in the General Data Protection Regulation (“GDPR”).
1. Overview of Data Protection
1.1 General Information
This Privacy Policy provides an overview of what happens to your Personal Data when you interact with our website and services. It explains what data we collect, how we use it, and what rights you have under applicable data protection laws. We process Personal Data in accordance with applicable data protection laws and this Privacy Policy, applying appropriate safeguards to protect such data.
1.2 Roles under Data Protection Law
Depending on the context:
- DLEGATE acts as a Controller when processing Personal Data for its own purposes (e.g. website operation, account registration, customer support, marketing, billing administration).
- DLEGATE acts as a Processor when processing Personal Data on behalf of Customers within the SaaS platform, in accordance with the applicable Data Processing Agreement.
Further details are provided in Section 5.
2. Responsible Party (Controller)
The controller responsible for data processing under this Privacy Policy is:
DLEGATE Solutions GmbH
Kirchsteinstr. 17b
83661 Lenggries
Germany
Email: contact@dlegate.de
3. How We Collect Personal Data
3.1 Data You Provide Directly
We collect Personal Data when you provide the data directly, for example when:
- contacting us,
- registering for an account,
- requesting information or support,
- scheduling appointments.
3.2 Server Log Files and Automatically Collected Data
When you access our website or use our services, our systems automatically collect and store certain technical information in server log files.
This information may include:
- browser type and version
- operating system
- referrer URL
- hostname or device identifier
- date and time of access
- IP address
This data is processed for the purposes of ensuring the security, stability, and technical operation of our systems, as well as for troubleshooting and preventing misuse.
The legal basis for this processing is Art. 6(1)(f) GDPR, based on our legitimate interest in providing secure and reliable services. Server log data is not combined with other data sources for profiling purposes and is retained only for as long as necessary to achieve the stated purposes, unless longer retention is required by law.
3.3 Cookies and Consent Technologies
We use cookies and similar technologies to collect certain information automatically when you access our website or services.
Detailed information about the types of cookies used, their purposes, storage duration, and the applicable legal bases is provided in Section 7 (Cookies and Similar Technologies) of this Privacy Policy.
4. Purpose and Legal Bases of Processing
We process Personal Data for the following purposes and legal bases:
| Purpose | Legal Basis |
|---|---|
| Operation and security of website and services | Art. 6(1)(f) GDPR |
| Account registration and administration | Art. 6(1)(b) GDPR |
| Performance of contracts and pre-contractual measures | Art. 6(1)(b) GDPR |
| Customer support and communication | Art. 6(1)(b) or (f) GDPR |
| Analytics and service optimisation | Art. 6(1)(f) GDPR or consent |
| Compliance with legal obligations | Art. 6(1)(c) GDPR |
| Marketing and promotional communications | Art. 6(1)(a) GDPR (where required) |
Where consent is required, it may be withdrawn at any time with effect for the future.
5. Use of the DLEGATE SaaS Platform
5.1 Purpose of Processing and Roles
When Users register for and use the DLEGATE SaaS platform, Personal Data is processed in order to create and manage user accounts, provide access to the Service, ensure operational security, and support contractual performance. This includes, in particular, identification and contact details, account and access information, and service-related metadata.
The SaaS platform is provided to business customers (the "Customer"), who may authorize individual users (e.g. employees or contractors, "Users", also referred to as "Team Members") to access and use the platform on their behalf. To the extent such Personal Data is processed in the context of Customer-controlled use of the SaaS platform, DLEGATE acts as a processor on behalf of the respective Customer in accordance with the applicable Data Processing Agreement. In this context, the Customer determines the purposes and means of processing and remains the data controller.
DLEGATE acts as an independent controller only where Personal Data is processed for its own purposes, such as account registration prior to activation, billing, fraud prevention, customer support, and legal compliance, in accordance with Art. 6(1)(b), (c), or (f) GDPR, as applicable.
5.2 Registration, Free-Tier Use, and Pre-Contractual Processing
If a registration process is initiated but not completed, the Personal Data already provided during the sign-up process is processed solely for the purpose of managing pre-contractual steps pursuant to Art. 6(1)(b) GDPR. Such pre-contractual data is automatically deleted after a limited period unless the registration is completed or statutory retention obligations apply.
To verify eligibility for the Free-Tier Plan and to prevent repeated or fraudulent registrations, DLEGATE may process limited account-related information, including name, company name, business email address, and email domain, together with an internal indicator showing whether the Free-Tier Plan has already been used.
This processing is based on Article 6(1)(f) GDPR, reflecting DLEGATE’s legitimate interest in preventing misuse of the Free-Tier Plan. Such data may be retained for up to twelve (12) months after account closure for audit and fraud-prevention purposes and is not used for marketing.
5.3 Processing within SaaS Usage (Processor Role)
Personal Data processed within the scope of Customer-controlled use of the SaaS platform, including data uploaded, generated, or captured during service usage, is processed by DLEGATE solely as a processor on behalf of the respective Customer. In such cases, the Customer remains the data controller. The respective roles and responsibilities are governed by the Data Processing Agreement (DPA), which forms part of the contractual relationship between DLEGATE and the Customer.
5.4 User Account Management and Deactivation
User accounts within the SaaS platform are created and managed by the respective Customer. The Customer may add, modify, or deactivate Users at any time.
When a User account is deactivated, access to the SaaS platform is immediately removed and no further login is possible.
As part of account creation, a system-generated internal identifier (pseudonymous token) is automatically assigned to each User. This identifier is not directly derived from the User’s name or email address and does not, by itself, identify an individual. It is used by the system to ensure data integrity, maintain traceability of actions performed within the Service, and support access control and attribution of system events.
Upon deactivation of a User account, directly identifying data such as name and email address are deleted. The system-generated internal identifier remains associated with historical records created by the User (such as cases, uploaded content, and activity logs) to ensure continuity, consistency, and traceability of Customer data.
Documents already generated by the system (for example PDF reports linked to cases) may continue to display the User’s name as it existed at the time of creation, as such documents form part of the Customer’s historical records.
This processing is necessary to:
- maintain the integrity and continuity of Customer data,
- ensure traceability and accountability of actions performed within the Service, and
- support compliance with legal obligations and the establishment, exercise, or defence of legal claims.
Where appropriate, personal data relating to deactivated Users may be restricted, minimised, or pseudonymized in accordance with the Customer’s instructions and applicable data protection laws. Further retention and deletion principles are governed by Section 14 (Data Retention).
6. Hosting and Infrastructure
6.1 Cloud Infrastructure
Our services are hosted using cloud infrastructure providers, including providers operating within the EU/EEA including standard infrastructure providers (e.g. cloud hosting providers).
Where Personal Data is transferred outside the EU/EEA, appropriate safeguards are applied, such as Standard Contractual Clauses adopted by the European Commission, or other lawful transfer mechanisms under the GDPR.
6.2 Data Processing Agreements
Where required, we have entered into data processing agreements with infrastructure and service providers to ensure GDPR-compliant processing on our instructions.
7. Cookies and Similar Technologies
7.1 General Information
Cookies are small text files stored on your device when you visit a website or use online services. We also use similar technologies, including local storage and session storage, to enable secure and functional operation of our website and SaaS platform.
Cookies may be temporary (session cookies) or stored for a longer period (persistent cookies). Cookies may be set by us (first-party cookies) or by integrated service providers (third-party cookies).
No persistent cookies or tracking mechanisms are set before authentication, except those strictly required to enable secure login flows (such as temporary authentication state handling or security validation mechanisms).
7.2 Types of Cookies and Legal Basis
We use the following categories of cookies and similar technologies:
Strictly necessary cookies and storage mechanisms
These are required for the secure operation of our website and SaaS platform and cannot be disabled without affecting functionality. They include in particular:
- Authentication and session management cookies, including cookies used during login, authentication flow coordination, and post-login session maintenance
- Session cookies used by the application to maintain authenticated user sessions
- Security-related cookies such as CSRF protection or anti-abuse mechanisms
- Browser storage mechanisms (including local storage and session storage) used to store authentication tokens (e.g. access, ID, and refresh tokens)
These are based on:
- Art. 6(1)(b) GDPR (contract performance),
- Art. 6(1)(f) GDPR (security and integrity of services)
- § 25(2) TDDDG (strictly necessary storage)
They are necessary for user authentication, secure login and session management, prevention of unauthorised access, stable operation of the SaaS platform.
Optional cookies
Where used, optional cookies (e.g. analytics or optimisation cookies) are only set with your consent on the legal basis of
- Art. 6(1)(a) GDPR
- § 25(1) TDDDG
Consent may be withdrawn at any time with effect for the future.
7.3 Authentication and Session Management
When using the SaaS platform, authentication is handled via an identity provider. During the login process, temporary authentication cookies may be used to complete the secure authentication flow. After successful login, authentication and session state are maintained using:
- Access Token
- ID Token
- Refresh Token
These tokens are stored in the browser’s local storage or equivalent secure storage mechanisms.
In addition, a session cookie is used to maintain server-side session continuity across requests.
Authentication within the SaaS platform relies on secure session mechanisms, including cookies and tokens issued after successful login.
These mechanisms are strictly necessary for the operation of the Service.
7.4 Consent Management and Control
Strictly necessary cookies and storage mechanisms are used without consent, as they are required for the operation of the Service.
Optional cookies are only used where consent has been obtained.
You may control or delete cookies and browser storage at any time via your browser settings. This may affect login functionality and session persistence.
8. Analytics
We use privacy-friendly analytics tools operated under our control to analyse usage patterns and improve our services.
Where analytics processing is based on consent, data is processed only after such consent has been obtained pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG, where applicable. Where analytics is necessary for basic service optimisation and does not require consent, processing is based on Art. 6(1)(f) GDPR, reflecting our legitimate interest in improving our services.
Where applicable, we may also process anonymised or aggregated data derived from the use of our services for analytics, security, and service improvement purposes, provided such data does not identify any individual or Customer.
9. Communication and Contact
When you contact us (for example via contact form, email, or telephone), we process the information you provide, including contact details and the content of your inquiry, in order to handle and respond to your request.
The legal basis for this processing is Article 6(1)(b) GDPR where the request relates to a contractual or pre-contractual relationship, and Article 6(1)(f) GDPR for general inquiries, based on our legitimate interest in responding to communications.
Personal Data processed in this context is retained only for as long as necessary to handle the inquiry, unless statutory retention obligations apply.
10. Payment Processing
Where a Customer upgrades to a paid subscription, payment processing is carried out by an external Payment Service Provider acting as an independent controller under applicable data protection laws.
Payment-related Personal Data, such as payment card or bank information, is processed exclusively by the Payment Service Provider for the purpose of performing the payment transaction and administering the subscription, in accordance with its own terms and privacy policy.
DLEGATE does not process or store payment card information.
The processing of Personal Data by the Payment Service Provider in this context is based on Article 6(1)(b) GDPR, as it is necessary for the performance of a contract.
11. Invoicing and Accounting
For the creation, transmission, and administration of invoices, including electronic invoices ("e-invoices"), DLEGATE uses third-party accounting and invoicing service providers acting as processors on behalf of DLEGATE for this purpose, pursuant to Art. 28 GDPR.
Invoice data may include the Customer's business contact details, such as name and email address of the individual referenced as the billing or account contact. This processing is based on Art. 6(1)(b) and Art. 6(1)(c) GDPR (performance of contract and compliance with statutory bookkeeping and tax retention obligations).
This processing is separate from, and outside the scope of, the Data Processing Agreement governing Customer Data processed within the SaaS platform, as DLEGATE acts as an independent Controller for billing and accounting purposes.
12. Internal IT and Collaboration Tools
For internal document storage, team collaboration, and business email communication, DLEGATE uses cloud-based productivity and collaboration service providers, acting as processors on behalf of DLEGATE pursuant to Art. 28 GDPR.
Personal Data processed in this context may include business contact details of Customers, Users, prospects, and other correspondents (e.g. names and email addresses), as well as the content of business correspondence and internally stored documents, to the extent exchanged with or held by DLEGATE for business administration purposes.
This processing is based on Art. 6(1)(b) GDPR (performance of contract and pre-contractual measures) and Art. 6(1)(f) GDPR (DLEGATE's legitimate interest in efficient and secure internal operations), as applicable.
Data is processed within Germany/the EU. Where Personal Data processed via these tools is nonetheless transferred outside the EU/EEA (e.g. in connection with limited support or maintenance functions), such transfers are subject to appropriate safeguards, including Standard Contractual Clauses adopted by the European Commission or other lawful transfer mechanisms.
These tools are used solely for DLEGATE's internal business operations and are not used to process Customer Data within the DLEGATE LiveCall SaaS platform. This processing is therefore separate from, and outside the scope of, the Data Processing Agreement governing the SaaS platform.
13. Data Recipients
Personal Data may be disclosed to:
- service providers acting as processors, including providers engaged for invoicing and accounting purposes, and providers engaged for internal collaboration, document storage, and business email communication,
- professional advisors (e.g. legal, tax),
- public authorities where legally required.
Data is shared only where a valid legal basis exists and, where applicable, subject to contractual safeguards.
14. Data Retention
14.1 General Retention Principle
Unless a specific retention period is stated in this Privacy Policy, Personal Data is retained only for as long as necessary to fulfil the purposes for which it was collected or otherwise processed. Once such purposes no longer apply, Personal Data is deleted or anonymised, unless further retention is required by applicable law, in particular statutory retention obligations.
14.2 User Account Deactivation (Within an Active Customer Relationship)
User accounts are managed by the respective Customer. When a User account is deactivated by the Customer, access to the SaaS platform is immediately removed and no further login is possible.
Upon deactivation, directly identifying data relating to the User, such as name and email address, is deleted or anonymised.
System-related records associated with the User, including system-generated identifiers and related activity data, may be retained in pseudonymised form where necessary to ensure:
- the integrity and consistency of system data,
- traceability of actions performed within the Service, and
- auditability of historical processes.
Documents generated prior to deactivation (e.g. PDF reports linked to cases) may continue to display the User’s name as recorded at the time of creation, as these form part of the Customer’s historical records.
Where appropriate, personal data relating to deactivated Users may be further restricted, minimised, or pseudonymised in accordance with the Customer’s instructions and applicable data protection laws.
14.3 End of Contract / Termination of Customer Relationship
Where the contractual relationship between DLEGATE and a Customer is terminated or expires, the Customer may export its data during the applicable post-termination access period as defined in the Terms of Service.
After expiry of this period, all Customer data is deleted or anonymised, unless retention is required:
- for compliance with legal obligations, or
- for the establishment, exercise, or defence of legal claims.
Any remaining technical logs are retained only in anonymised or aggregated form and do not constitute Personal Data.
15. International Data Transfers
Where Personal Data is transferred to recipients outside the EU/EEA, such transfers are protected by appropriate safeguards in accordance with Articles 44–49 GDPR.
16. Data Subject Rights
Under the GDPR, you have the right to request access to your Personal Data in accordance with Article 15, the right to request rectification of inaccurate or incomplete Personal Data under Article 16, the right to request erasure of your Personal Data pursuant to Article 17, and the right to request restriction of processing in accordance with Article 18. You also have the right to receive Personal Data that you have provided to us in a structured, commonly used, and machine-readable format and to transmit such data to another controller in accordance with Article 20. Where processing is based on legitimate interests, you have the right to object to such processing pursuant to Article 21. Where Personal Data is processed by DLEGATE solely as a processor on behalf of a Customer, data subject requests must be directed to the respective Customer as the responsible controller. Where processing is based on your consent, you may withdraw that consent at any time with effect for the future. In addition, you have the right to lodge a complaint with a competent supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement.
17. Security
We implement appropriate technical and organisational measures to protect Personal Data against unauthorised access, loss, or misuse, in accordance with Article 32 GDPR. These measures include, among others, encryption of data in transit using industry-standard SSL/TLS protocols, access controls, and secure infrastructure. Data transmitted between your device and our services is protected against unauthorised third-party access.
Despite the implementation of appropriate technical and organisational measures, no method of data transmission over the internet or electronic storage is completely secure; residual risks cannot be entirely excluded.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, technical, or organisational changes.
The current version is always made available through our services.
19. Contact
If you have questions about this Privacy Policy or our data processing practices, please contact:
DLEGATE Solutions GmbH
Email: contact@dlegate.de