Legal

Privacy notice

This notice applies to the website tridion-benefits.de. For processing in our application at app.tridion-benefits.de, the privacy information provided there applies, together with the agreements with your employer or your broker.

This is a courtesy translation. In case of any discrepancy, the German version is the legally binding one. Zur deutschen Fassung

1. Controller

tridion benefits GmbH, Emil-Hoffmann-Straße 1a, 50996 Cologne, Germany
Managing Director: Achim Trude
Phone +49 2236 961530
datenschutz@tridion-benefits.de

Data protection officer: Stephan Frank Consulting, Kopernikusplatz 11, 90459 Nuremberg, Germany

2. Visiting the website (server log files)

When you access our pages, our hosting provider automatically processes data transmitted by your browser: IP address, date and time, the address requested, the volume of data transferred, the referrer and details of your browser and operating system.

Purpose: delivering the pages, operational security and defence against attacks.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in secure and uninterrupted operation.
Retention: we operate no logging of our own and do not access this data. Processing takes place solely at the hosting provider, which deletes the data at short notice — regularly within seven days.

3. Hosting

This website is hosted by Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA. Netlify processes the data named under point 2 on our behalf as a processor (Art. 28 GDPR).

Transfers to third countries: processing in the USA cannot be excluded. The transfer is based on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR) together with supplementary safeguards. Netlify, Inc. is additionally certified under the EU-US Data Privacy Framework; for transfers to certified US companies an adequacy decision of the European Commission is in place.

4. Cookies and similar technologies

This website sets no cookies for analytics or marketing purposes and embeds no tracking services. No information within the meaning of § 25(1) TDDDG is stored on or read from your device beyond what is strictly necessary to operate the site. A consent banner is therefore not required.

Should analytics or marketing services be used in future, a consent solution will be put in place beforehand and this notice amended.

5. Contacting us

If you contact us by email or through a form, we process your details in order to handle the enquiry.

Legal basis: Art. 6(1)(b) GDPR for pre-contractual enquiries, otherwise Art. 6(1)(f) GDPR.
Retention: until the matter is concluded, and beyond that within commercial and tax retention periods.

6. Booking a demonstration

To book appointments we link to a calendar operated by Pipedrive OÜ (Mustamäe tee 3a, 10615 Tallinn, Estonia). Your details are only processed there once you follow that link; Pipedrive's own privacy notice then applies in addition. Nothing is embedded on our own page, so no data is transmitted without your action.

7. Buying a licence (payment processing)

If you book a licence, we forward you for payment to Stripe Payments Europe, Ltd. (North Wall Quay, Dublin 1, Ireland). You enter your payment details there exclusively; we neither receive nor store complete payment data.

To create your access we process the master data transmitted from the purchase in our application environment at Supabase. The database runs in the region eu-central-1 (Frankfurt am Main, Germany), so the data remains within the European Union. The provider is Supabase, Inc. (USA), with which a data processing agreement including standard contractual clauses is in place.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for the retention of invoice data Art. 6(1)(c) GDPR in conjunction with commercial and tax obligations.

8. Disclosure of data

Data is disclosed only where necessary to perform the contract, where you have consented, or where we are legally obliged to do so. Recipients are in particular the service providers named above and — within insurance intermediation — the insurance undertakings you have instructed. We do not sell data.

9. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20), as well as the right to withdraw consent at any time with effect for the future (Art. 7(3) GDPR).

Right to object under Art. 21 GDPR: where we process data on the basis of legitimate interests, you may object at any time on grounds relating to your particular situation.

A message to the address above is sufficient to exercise these rights.

10. Right to complain to a supervisory authority

You may complain to a data protection supervisory authority. The authority responsible for us is:

State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
www.ldi.nrw.de

11. Whether provision is required

Providing your data is neither legally nor contractually required. Without the details necessary for an enquiry or for entering into a contract, however, we cannot deal with your request. Automated decision-making including profiling under Art. 22 GDPR does not take place.

As at: August 2026. We will amend this notice as soon as the processing or the legal position changes.