Privacy Policy

Data protection information

In the following, we would like to inform you about the processing of personal data in connection with our website as well as our portal for registered users and the associated app, hereinafter jointly referred to as the "Online Offering".

Controller

ONLOGIST GmbH
Managing Directors: Felix Müller, Moritz Pagendarm
Alter Wandrahm 13
20457 Hamburg
Phone: +49 (0)40 74 30 51 81
Email: info@onlogist.com

Data Protection Officer

Christoph Curvers, Löwenstraße 7, 20251 Hamburg
Email: datenschutz@onlogist.com


1. Privacy at a glance

General information

The following notes provide a simple overview of what happens to your personal data when you visit our website or use our online services as a registered user. Personal data is any data that can be used to personally identify you.

How do we collect your data?

Your data is collected, on the one hand, by you providing it to us (e.g. contact form, registration in the portal, contract initiation). Other data is collected automatically, or, where required, following your consent, by our IT systems when you visit our online offering, for example technical data such as browser type, operating system or access time.

What do we use your data for?

Some of the data is collected to ensure error-free provision of our online offering. Further data is processed to analyse user behaviour and to carry out and process the contractual and billing relationships initiated or existing via the portal between the users involved, as well - within the portal - for the AI-supported review of documents and receipts as part of the billing service.

What rights do you have regarding your data?

You have the right at any time to obtain, free of charge, information about the origin, recipients and purpose of your stored personal data (Art. 15 GDPR). You also have a right to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You may revoke any consent given at any time with future effect. Furthermore, you have the right to lodge a complaint with the competent supervisory authority (Art. 77 GDPR).

A. General information on data processing

A.1 Personal data

According to Art. 4(1) GDPR, personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

This includes, for example, name, address, telephone number and email address, but also whereabouts, IP address or bank details. When using our portal, we require your name, address and further information for a contract or preliminary contract between us and you, or between the user parties, so that we can provide the requested services.

A.2 Processing of personal data

We process the personal data of our users generally only to the extent that this is necessary for the provision of a functioning online offering and the provision of our content and services. Processing regularly takes place only with your consent as a user, unless storage and processing is permitted by statutory provisions, in particular Art. 6(1)(b), (c) or (f) GDPR.

A.3 Disclosure of personal data to third parties and recipients

Your personal data will only be disclosed if there is a legal basis under data protection law for doing so. Disclosure may in particular take place:

  • to processors who process personal data on our behalf and in accordance with our instructions,
  • to independently responsible parties, insofar as this is necessary for the performance of the contract or due to statutory obligations,
  • to other recipients, if you have consented or we are legally or officially obliged to do so.

Insofar as we use external service providers who process personal data on our behalf, this is done on the basis of data processing agreements pursuant to Art. 28 GDPR. These service providers process personal data exclusively in accordance with our instructions and only to the extent necessary to perform their respective services.

ONLOGIST only passes on your data to such private third parties who provide services in the name of and on behalf of ONLOGIST and who are listed in this privacy policy. Our employees and service providers are obliged to maintain confidentiality and to protect the personal and company-related data entrusted to them.

We carefully review, on a case-by-case basis, which third-party services we use and whether personal data is disclosed in the process. We include such processing in this privacy policy in accordance with applicable requirements.

Insofar as we use external processors to provide our platform services - in particular providers of AI-supported processing systems - the disclosure of personal data to these providers is based on data processing agreements pursuant to Art. 28 GDPR. These providers process your data exclusively in accordance with our instructions and for the purposes we determine. Where this involves a transfer to third countries outside the EU or EEA, we ensure an adequate level of data protection through appropriate safeguards within the meaning of Art. 46 GDPR (in particular EU Standard Contractual Clauses). The relevant providers can be found in the list of recipients under Section I.

A.4 Note on data transfer to the USA and other third countries

We partly use services from providers based outside the European Union or the European Economic Area, or who process data there. Insofar as personal data is transferred to third countries in this context, this is done in compliance with the statutory requirements. Where no adequacy decision exists for the third country concerned, we base the transfer in particular on appropriate safeguards within the meaning of Art. 46 GDPR, namely the European Commission's Standard Contractual Clauses. Where a provider is certified under a recognised data protection framework, the transfer may also be based on this. We would like to point out that, despite contractual and organisational safeguards, a level of data protection equivalent to that within the European Union cannot be guaranteed in all cases of third-country transfers.

A.5 Automatic collection of technical data (server log files)

Each time our online offering is accessed, our system automatically collects data and information from the computer system of the accessing computer. This data is not stored together with other personal data of the user.

The following data is stored for organisational and technical reasons:

• Your IP address

• Browser type and version used

• Your operating system (name, version)

• Your Internet service provider

• Date and time of access

• Websites from which your system accesses our online offering (referrer URL)

• Host name of the accessing computer

• Screen resolution, if applicable

• Names of retrieved files/content

The legal basis for the temporary storage of the data and log files is our legitimate interest pursuant to Art. 6(1)(f) GDPR. The collection of this data and its storage in log files is technically necessary for the secure and technically required operation of our online offering; there is accordingly no possibility of objection. Technical data is automatically deleted after 30 days.

A.6 General information on the legal bases of data processing

If you have consented to the processing of your personal data, processing takes place on the basis of Art. 6(1)(a) GDPR; where special categories of personal data are processed, additionally on the basis of Art. 9(2)(a) GDPR. Where consent is required for the storage of cookies or access to information on your terminal device, this additionally takes place on the basis of Section 25(1) TDDDG (German Telecommunications-Digital-Services-Data-Protection Act). Where your data is required for the performance of a contract or the implementation of pre-contractual measures, processing takes place on the basis of Art. 6(1)(b) GDPR. Where we are legally obliged to process personal data, this takes place on the basis of Art. 6(1)(c) GDPR. In all other cases, we base processing on our legitimate interest pursuant to Art. 6(1)(f) GDPR. The following sections provide detailed information on the respective applicable legal basis.

A.7 Purpose

ONLOGIST processes your personal data only for the purposes set out in this notice and on the basis of the respective legal bases indicated.

A.8 Use of AI-supported systems (overview)

We partly use automated systems in the portal that are based on artificial intelligence (AI) technologies. These systems assist us in reviewing documents and receipts as well as in processing billing procedures and the registration of service providers. Their use is subject to applicable data protection requirements and, where relevant, AI law requirements, in particular Regulation (EU) 2024/1689 on artificial intelligence (AI Act). Details on this - purpose, functioning, legal basis and your rights - can be found in Section E.4.

In no case does an AI system make a final decision without human review and control. Final decision-making authority always remains with an ONLOGIST employee or with you as the user.

A.9 Encrypted transmission

In the case of online collection and processing of personal data, information is transmitted in encrypted form (via HTTPS). Our online offering automatically enforces encrypted transmission of all content throughout. Encryption technologies that correspond to the current state of the art are used; security measures are continuously reviewed.

A.10 Storage period (general)

Unless a more specific storage period is stated within this privacy policy, your personal data will remain with us until the purpose of the data processing no longer applies. In the event of a legitimate request for erasure or revocation of consent, your data will be deleted, provided there are no other legally permissible grounds for storage (e.g. tax or commercial law retention periods); in this case, deletion takes place once the grounds no longer apply.

B. Hosting and Content Delivery Networks (CDN)

For the provision and delivery of our online offering, we use infrastructure and hosting services from the following technical service providers:

Amazon Web Services (AWS)

The provider is Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, 1855 Luxembourg.

When using our online offering, personal data may be processed on AWS servers; personal data may also be transferred to companies affiliated with AWS in third countries. In this case, data transfer is based on EU Standard Contractual Clauses.

The legal basis for the use of hosting and infrastructure services is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and efficient provision of our online offering.

Amazon CloudFront CDN

We use the Amazon CloudFront content delivery network. The provider is also Amazon Web Services EMEA SARL. CloudFront routes the transfer of information between your browser and our online offering via a globally distributed network, thereby increasing availability and performance.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the high-performance, stable and secure delivery of our online offering. For data transfer to third countries, see AWS above.

Hetzner

The provider is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen.

Use is made for the purpose of the secure, stable and efficient provision of our online offering. The legal basis is Art. 6(1)(f) GDPR and, insofar as processing is necessary for the performance of contractual services, additionally Art. 6(1)(b) GDPR.

NETWAYS Managed Services GmbH (NMS)

The provider is NETWAYS Managed Services GmbH, Deutschherrnstr. 15-19, 90429 Nuremberg.

When using our online offering, personal data may be processed on NMS servers; personal data may also be transferred to companies affiliated with NMS in third countries. In this case, data transfer is based on EU Standard Contractual Clauses.

The legal basis for the use of hosting and infrastructure services is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and efficient provision of our online offering.

STRATO

The provider is STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin. When you visit our online offering, STRATO collects various log files including your IP address. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the reliable presentation of our online offering.

C. Cookies and consent management

C.1 Use of cookies

Insofar as cookies or comparable technologies are technically necessary, their use is based on Section 25(2) No. 2 TDDDG. The subsequent processing of personal data is based on Art. 6(1)(f) GDPR; our legitimate interest lies in the technically error-free and secure provision of our online offering. We only use all non-technically-necessary cookies and comparable technologies on the basis of your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.

Some cookies are deleted after you close your browser (transient cookies, including session cookies). Other cookies (persistent cookies) remain on your terminal device and allow your browser to be recognised on your next visit. You can set your browser so that you are informed about the setting of cookies, allow cookies only in individual cases, exclude them altogether, or have them automatically deleted when you close your browser. Please note that disabling cookies may impair the functionality of our online offering.

An overview of the cookies used, their providers, purpose and storage period, your current consent status, and the option to revoke your consent with future effect can be found in our cookie notice at https://www.onlogist.com/cookie-erklaerung

C.2 Consent management with Cookiebot

Our online offering uses Cookiebot's consent technology to obtain and document, in a manner compliant with data protection law, your consent to the storage of certain cookies or the use of certain technologies. The provider is Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark.

When our online offering is accessed, a connection is established to Cookiebot's servers. Cookiebot then stores a cookie in your browser in order to be able to assign consents granted to you or their revocation. The data is stored until you request us to delete it, you delete the Cookiebot cookie yourself, or the purpose no longer applies. Mandatory statutory retention obligations remain unaffected.

The legal basis is Art. 6(1)(c) GDPR, insofar as we are legally obliged to obtain and document consent, and additionally Art. 6(1)(f) GDPR with regard to the legally compliant organisation of our consent management.

D. Analytics tools, tracking and advertising

Note on scope of application: The analytics, tracking and marketing services described below are used exclusively on the publicly accessible areas of our online offering. These services are not used in the logged-in portal area for registered users, unless otherwise specified below.

Google Tag Manager

We use Google Tag Manager, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, for the technical integration and management of further services and scripts. Google Tag Manager itself does not create user profiles and does not carry out any independent analyses. Insofar as services requiring consent are integrated via Google Tag Manager, this only takes place after your consent; the legal basis in this respect is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.

Google Analytics

We use Google Analytics, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, for reach measurement and analysis of the use of our online offering. Google Analytics in particular enables us to evaluate page views, dwell times, the origin of the visit, as well as technical information on the devices and browsers used. Google Analytics uses cookies and comparable technologies to recognise users and devices. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Consent can be revoked at any time with future effect.

Insofar as personal data is transferred to third countries in connection with the use of Google Analytics, this is done on the basis of appropriate safeguards pursuant to Art. 46 GDPR.

We have activated IP anonymisation. As a result, your IP address is generally shortened within the EU or EEA prior to any further processing.

Where the "Google Signals" feature is activated, additional aggregated information on cross-device user behaviour, interests and demographic characteristics may be provided. We only receive this information in aggregated form. This, too, is only used on the basis of your consent.

Google Ads, remarketing and conversion tracking

We use Google Ads, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, for performance measurement, audience building and re-engaging users. In particular, cookies, similar technologies and - where used - hashed customer data may be used for this purpose. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.

Meta Pixel, formerly Facebook Pixel, incl. advanced matching

We use Meta technologies for reach measurement, conversion measurement, audience building and re-engaging users. This may involve processing information on visits to our website, devices used, technical identifiers, and - where used - hashed contact information.
The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
Insofar as Meta jointly determines the purposes and means of processing with us in connection with the collection and transmission of data, this constitutes joint controllership pursuant to Art. 26 GDPR; a corresponding controller addendum on joint controllership is in place.

Meta Conversion API, formerly Facebook Conversion API

We use the Meta Conversion API, a service of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, to record interactions with our online offering in order to improve the advertising performance of our ads on Facebook and other Meta services. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR.

Meta Custom Audiences, formerly Facebook Custom Audiences

We use Custom Audiences, a service of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, to define target audiences (including lookalike audiences) for advertising on Facebook. The legal basis is consent pursuant to Art. 6(1)(a) GDPR.

LinkedIn Insight Tag

We use LinkedIn Insight Tags, a service of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, D02 AD98, Ireland, to analyse professional details of website visitors registered with LinkedIn, for conversion purposes and for retargeting. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR.

E. Portal-specific data processing for registered service providers and clients

E.1 Processing of your IP address by the web servers

Your IP address is processed insofar as this is technically necessary to deliver the content of our portal to your device and to ensure the security of operations. Storage takes place for the duration of the usage session and, where necessary, additionally in server log files pursuant to Section A.5.

E.2 Registration in the portal

You can register in the portal in order to use its functions. We only use the data entered for the purpose of setting up, providing and managing your user account and for carrying out the respective usage relationship. Mandatory fields must be completed in full; otherwise we will reject the registration. We use the email address provided to inform you of important changes.

The legal basis is Art. 6(1)(b) GDPR (performance of the usage relationship, if applicable initiation of further contracts). The data is stored for as long as you are registered, and then deleted; statutory retention periods remain unaffected.

E.3 Mobile app - location and movement data

Users of the mobile app give the following consent:

"I agree that ONLOGIST collects location and movement data from my smartphone in order to provide clients with order-related information, such as estimated arrival times and information on driving behaviour."

This consent is voluntary and may be revoked at any time without giving reasons pursuant to Art. 7(3) GDPR. Please note that certain mobile functions of the platform - in particular those that require order-related status and arrival information - cannot be provided without this data processing, so that an order cannot be assigned in this case.

E.4 AI-supported systems in the portal

We use AI-supported functions in the portal to support certain review procedures and processing steps. These systems serve to prepare, structure and plausibility-check information; a final professional decision is not made exclusively by automated means.

E.4.1 AI-supported receipt processing

Process:

  1. OCR extraction: After the receipt (e.g. fuel receipts, toll charges, hotel invoices, parking fees, local transport costs, vehicle cleaning) is uploaded, the receipt content is read out using an OCR procedure on the service provider's device.
  2. AI-supported categorisation: The extracted receipt data is transmitted via an encrypted API interface to an external AI model, which extracts and categorises relevant information (net/gross amount, type of service, date, location, quantity refuelled if applicable).
  3. System-side plausibility check: An automated, rule-based procedure (without AI) compares location, date and quantity with the order data; in the event of discrepancies, an automatic query is sent to the service provider.
  4. Automatic completion of receipt fields with the categorised data.
  5. Manual post-processing: The service provider can check and adjust the data at any time. Receipts are only submitted for further review after being checked and approved.

Data processed: Date/time of the transaction, location (allows inference of whereabouts), type of service, transaction amount, quantity, name/identification details of the service provider (if included on the receipt).

Purpose: Efficient, low-error and transparent processing of expense reimbursements as part of the billing service.

Legal basis: Art. 6(1)(b) GDPR (performance of the usage contract).

Recipient: The provider of the AI model is listed in the list of recipients under Section I; transmission takes place on the basis of a data processing agreement pursuant to Art. 28 GDPR.

No fully automated decision (Art. 22 GDPR): The AI output serves exclusively for the pre-filled display; the service provider can fully adjust the data before submission.

Notice pursuant to Art. 50 AI Act: The AI support is recognisable as such in the system; the result can be viewed and adjusted before submission.

E.4.2 AI-supported receipt review on behalf of clients

Process:

  1. Transmission of the submitted receipt files via an encrypted API interface to the external AI model.
  2. OCR extraction and categorisation as per E.4.1.
  3. Automatic comparison of the extracted data with the receipt data provided by the service provider.
  4. Categorisation of discrepancies in a traffic-light system (no/minor/significant discrepancy) with a description of the finding.
  5. Review by the authorised user of the client; this user can adopt or override the AI categorisation.
  6. Feedback on change requests to the service provider for renewed approval.

Purpose: Automated pre-review of receipts as part of billing control; ensuring correct billing and preventing misuse.

Legal basis: Art. 6(1)(b) GDPR (client usage contract/service provider billing relationship), additionally Art. 6(1)(f) GDPR.

Recipient: As per E.4.1. The processed receipt data and review results are made accessible to the respective client as an independently responsible party (Art. 4 No. 7 GDPR) in the context of contract performance.

No binding AI decision: The AI output constitutes a review recommendation, which must always be manually reviewed, adopted or overridden by the client user.

Notice pursuant to Art. 50 AI Act: The pre-review is carried out by an AI system; results are marked as such and do not constitute final findings.

E.4.3 AI-supported review of service provider profiles during registration

Process:

  1. Document upload: company details, trade licence, driving licence, extended certificate of good conduct, proof of tax number.
  2. AI-supported document extraction via an encrypted API interface; extraction of predefined data fields.
  3. Comparison of data with the details entered during registration.
  4. Overall assessment and recommendation regarding activation or requesting additional/corrected documents.
  5. Final decision by an ONLOGIST service employee, who is not bound by the AI recommendation.

Data processed:

  1. General company data (company name, legal form, address, contact details)
  2. Trade licence (commercial activity, if applicable date of birth/place of residence of the holder)
  3. Driving licence (name, date of birth, date of issue/expiry, categories, photograph)
  4. Extended certificate of good conduct (personal data, if applicable criminal convictions/entries)
  5. Tax number/proof thereof

Special categories of data:

  1. Certificate of good conduct (Art. 10 GDPR): Processing solely to verify personal suitability requirements for platform participation, on the basis of Art. 10 GDPR in conjunction with relevant national provisions and, where necessary, explicit consent analogous to Art. 9(2)(a) GDPR. Only information relevant to the suitability check is processed; no further storage takes place.
  2. Photograph on the driving licence: Is currently not processed for biometric identification or biometric matching. In the event of a future introduction of biometric image processing, this notice will be updated and, where applicable, explicit consent pursuant to Art. 9(2)(a) GDPR will be obtained.

Purpose: Ensuring that only suitable, identifiable and reliable service providers operate on the platform; protection of clients and platform integrity.

Legal bases are Art. 6(1)(b) GDPR for general registration data as well as Art. 10 GDPR in conjunction with national provisions, additionally Art. 9(2)(a) GDPR analogously for certificate-of-good-conduct data.

Recipient: As stated above under E.4.1, data processing agreement pursuant to Art. 28 GDPR; in the case of third-country transfer, safeguards pursuant to Art. 46 GDPR.

No fully automated decision (Art. 22(1) GDPR): The binding decision on activation/rejection is always made by an ONLOGIST employee, who may deviate from the AI recommendation.

You have the right to request at any time that the decision on your profile activation be made exclusively manually by an employee, without involvement of the AI recommendation. Please send requests to service@onlogist.com

Notice pursuant to Art. 50(1) AI Act: The AI system used is to be classified as a high-risk AI system within the meaning of Annex III No. 4 of the AI Act, as it is used in the field of selecting natural persons seeking access to self-employment. As operator pursuant to Art. 3 No. 4 of the AI Act, ONLOGIST ensures that human oversight pursuant to Art. 26 of the AI Act is guaranteed, that the technical documentation and logging obligations of the AI Act are fulfilled, and that a data protection impact assessment (DPIA) pursuant to Art. 35 GDPR has been carried out.

Storage period: Documents uploaded during the registration process are not permanently stored in the AI system after the review is completed. Storage in the ONLOGIST system takes place for the duration of the usage relationship as well as statutory retention periods. Data from the certificate of good conduct is deleted after the review is completed and is not stored permanently.

F. Other services and plugins used

Asana

We use Asana, a service of Asana Inc., 633 Folsom Street Suite 100, San Francisco, CA 94107-3600, USA, for the internal organisation of workflows and the structured processing of enquiries and matters. Only the personal data required for the respective matter is processed. The legal basis is Art. 6(1)(f) GDPR.

Braun Heider GmbH

We use services provided by Braun Heider GmbH, Klingholzstr. 18, 65189 Wiesbaden, for hosting our services as well as for system administration and maintenance of hardware and software. The legal basis is Art. 6(1)(b) GDPR.

GGW

We use services provided by GGW GmbH, Chilehaus B, Fischertwiete 1, 20095 Hamburg, insofar as this is necessary for handling insurance-related matters or claims. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the efficient handling of insurance-related matters.

HubSpot CRM

We use HubSpot, a service of HubSpot Inc., 25 First Street, Cambridge, MA 02141, USA, to manage contacts, process enquiries and - where activated - to document and evaluate sales- and communication-related interactions. Insofar as cookies or comparable technologies are used in this context, this is based on your consent; otherwise we base processing on Art. 6(1)(b), or in the alternative (f) GDPR.

IDnow

We use services provided by IDnow GmbH, Auenstraße 100, 80469 Munich, for identity verification as part of the registration and approval process, insofar as this is necessary to fulfil statutory requirements. The legal basis is Art. 6(1)(c) GDPR.

Mailchimp

We use Mailchimp, a service of The Rocket Science Group, LLC, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA, to send newsletters. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR.

Pingen

We use services provided by Pingen GmbH, Badenerstrasse 47, 8004 Zurich, Switzerland, for the postal dispatch of invoices. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the efficient design of our mailing processes.

RHD Factoring

We use services provided by RHD Rechnungsstelle AG, Am Wall 96-98, 28195 Bremen, insofar as this is necessary for the provision of factoring services for the timely payment of remuneration to service providers. The legal basis is Art. 6(1)(b) GDPR.


Sisense

We use services provided by Sisense Inc., 1359 Broadway FL 4, New York, NY 10018-8339, USA, to evaluate business metrics and produce reports. Personal data is only processed insofar as this is necessary for the respective analysis; the legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the need for robust business metrics for company management.

Slack

We use Slack, a service of Slack Technologies Ltd., Salesforce Tower 60 R801, North Dock, Dublin, Ireland, for internal communication and collaboration among our employees. Personal data is only processed insofar as this is necessary for internal communication. The legal basis is Art. 6(1)(f) GDPR.

Smallinvoice

We use Smallinvoice, a service of Lourens Systems GmbH, Badenerstrasse 47, 8004 Zurich, Switzerland, for creating and sending invoices. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the efficient handling of our accounting.

Smashleads

We use Smashleads, a service of smashleads UG (haftungsbeschränkt), Kiebitzweg 5, 50354 Hürth, to generate and manage prospect enquiries. Contact data, communication content and technical usage data may be processed. The legal basis is Art. 6(1)(f) GDPR; insofar as cookies or comparable technologies are used in this context, this is only done on the basis of your consent.

Teams

We use Teams, a service of Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, to conduct audio, video and online conferences. Participant master data, technical connection data, communication content and - where used - chat, file and sharing content is processed. The legal basis is Art. 6(1)(b) GDPR, insofar as communication takes place in connection with existing or initiated contractual relationships, and additionally Art. 6(1)(f) GDPR. Where a recording or other function requiring consent is used, this is only done on the basis of your consent.

Twilio

We use Twilio, a service of Twilio Inc., 375 Beale St, Suite 300, San Francisco, CA 94105, USA, to send SMS messages to validate mobile phone numbers during the registration process. The legal basis is Art. 6(1)(b) GDPR.

Zapier

We use Zapier, a service of Zapier Inc., Market St. #62411, San Francisco, CA 94104-5401, USA, for the technical connection, synchronisation and automation of applications, systems and data flows. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the efficient design of our business processes.

Zendesk

We use Zendesk, a service of Zendesk, Inc., 1019 Market Street, San Francisco, CA 94103, USA, to process user enquiries and chat communication. In doing so, we process the data you provide as part of your enquiry, in particular contact details, the content of your enquiry and - when using the chat function - technical connection data such as your IP address. The legal basis is Art. 6(1)(f) GDPR.

G. eCommerce, payment providers and contract data

Processing of customer and contract data

We collect, process and use personal customer and contract data to establish, structure and amend our contractual relationships. The legal basis is Art. 6(1)(b) GDPR.

Contact form, telephone, postal and email enquiries

If you contact us by contact form, email, telephone or fax, we store your details, including contact data, to process your enquiry and for any follow-up questions. The legal basis is Art. 6(1)(b) GDPR, insofar as the enquiry is related to contract performance or pre-contractual measures; otherwise our legitimate interest in effective processing pursuant to Art. 6(1)(f) GDPR, whereby our legitimate interest lies in the efficient and traceable processing of enquiries, and, where requested, your consent pursuant to Art. 6(1)(a) GDPR.

In the case of telephone contact, your telephone number (if transmitted) is stored as a communication date in the call history and automatically deleted after 90 days; the relevant legal basis is Art. 6(1)(a) or (f) GDPR.

As a general rule, we do not pass on the aforementioned data to third parties without authorisation. Disclosure only takes place if there is a legal basis for doing so, if this is necessary to process your enquiry, or if you have consented.

H. Handling of applicant data

We process personal data of applicants exclusively for the purpose of conducting the application procedure. This includes, in particular, contact data, communication data, application documents, and interview and evaluation notes, insofar as these are necessary for the decision on establishing an employment relationship. The legal basis is Section 26 BDSG (German Federal Data Protection Act) as well as Art. 6(1)(b) GDPR; where consent has been given, additionally Art. 6(1)(a) GDPR.

In the event of a successful application, the data is stored on the basis of Section 26 BDSG and Art. 6(1)(b) GDPR for the purpose of carrying out the employment relationship.

In the event of a rejection or withdrawal of the application, we generally store your data for up to six months after completion of the application procedure, unless longer storage is permissible on the basis of consent or due to statutory or procedural requirements.

I. Recipients of personal data

Personal data is disclosed - depending on the processing operation - to the categories of recipients listed below. Insofar as service providers process personal data on our behalf, this is done on the basis of Art. 28 GDPR. Where recipients process data under joint or their own responsibility under data protection law, this is marked accordingly.

I.1 Processors with whom a data processing agreement pursuant to Art. 28 GDPR has been concluded

CompanyAddressPurpose
Amazon Web Services EMEA SARL38 Avenue John F. Kennedy, 1855 LuxembourgHosting/CDN
Appsflyer Ltd.14 Maskit St, 6th Floor, POB 12371 Herzliya 4673314
Israel
Behavioural and marketing tracking
Asana Inc.633 Folsom Street Suite 100, San Francisco, CA 94107-3600
USA
Project management
Ascentiel International S.L.C/ Pollensa 2, edificio Artemisa, Of. 15-16
28290 Las Rozas de Madrid
Spain
Insurance broker
AXA AXA Seguros Generales S.ACalle Monseñor Palmer, 1 07014 Palma de Mallorca
Spain
Motor vehicle liability insurance
Baloise Assurance Luxembourg S.A.8, rue du Château d'Eau
3364 Leudelange
Luxembourg
Motor vehicle liability insurance
Braun Heider GmbHKlingholzstr. 18
65189 Wiesbaden
Germany
System administration/IT operations
Cloudflare Inc.101 Townsend Street
San Francisco, CA 94107 USA
Website security plugin
Deepl SEMaarweg 165
50825 Cologne
Germany
Translation tool
ERGO Versicherung AGStresemannstr. 111
10963 Berlin
Germany
Liability insurance
GGW GmbHChilehaus B, Fischertwiete 1
20095 Hamburg
Germany
Insurance broker
Global Assekuranz Nord GmbHFriesenweg 24
22763 Hamburg
Germany
Insurance broker
Google Ireland LimitedGordon House, Barrow Street, Dublin 4
Ireland
Analytics/marketing/tag manager
Hetzner Online GmbHIndustriestr. 25
91710 Gunzenhausen
Germany
Hosting
Hubspot Inc.25 First Street
Cambridge, MA 02141
USA
CRM
IDnow GmbHAuenstraße 100
80469 Munich
Germany
Identity verification
KASKO Germany UG (haftungsbeschränkt)Hoheluftchaussee 95
20253 Hamburg
Germany
IT agency developing software solutions for insurance and transmitting data
LinkedIn Ireland Unlimited CompanyWilton Place
Dublin 2, D02 AD98
Ireland
Insight Tag
Lourens Systems GmbHBadenerstrasse 47
8004 Zurich
Switzerland
Invoicing (Smallinvoice)
Mailchimp (The Rocket Science Group, LLC)675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USANewsletter dispatch
Meta Platforms Ireland Limited4 Grand Canal Square, Dublin 2
Ireland
Meta Pixel/Conversion API/Custom Audiences
Microblink LLC CroatiaStrojarska cesta 20
10000 Zagreb
Croatia
Driving licence scanning tool
Microsoft CorporationOne Microsoft Way, Redmond, WA 98052-6399, USATeams/various services
NETWAYS Managed Services GmbHDeutschherrnstr. 15-19 90429 NurembergHosting/CDN
Pingen GmbHBadenerstrasse 47
8004 Zurich
Switzerland
Postal dispatch
RHD Rechnungsstelle AGAm Wall 96-98
28195 Bremen
Germany
Factoring
Sisense Inc.1359 Broadway FL 4
NY 10018-8339
USA
Business analytics
Slack Technologies Ltd.Salesforce Tower 60 R801, North Dock, Dublin
Ireland
Internal communication
STRATO AGOtto-Ostrowski-Straße 7 10249 Berlin
Germany
Hosting
The MSA Group/ MSA MIZAR S.P.A.Via Sangro 15
20132 Milano
Italy
Claims management
T-Systems International GmbHFriedrich-Ebert-Allee 140
53113 Bonn
Germany
Hosting
Twilio Inc.375 Beale St, Suite 300
San Francisco, CA 94105
USA
SMS validation
Usercentrics A/SHavnegade 39
1058 Copenhagen
Denmark
Consent management platform (Cookiebot)
VIG platform partners GmbHSchottenring 30
1010 Vienna
Austria
Insurance agent
Zapier Inc.Market St. #62411
San Francisco, CA 94104-5401
USA
Tool integration
ZENDESK, Inc.1019 Market St
San Francisco, CA 94103 USA
Support/CRM/chat/telephone system

I.2 Processors for AI-supported receipt processing/review (Section E.4) and document verification, with whom a data processing agreement pursuant to Art. 28 GDPR has been concluded

CompanyAddressPurpose
OpenAI Ireland Ltd.1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, IrelandAutomated analysis and plausibility checking of receipts and registration documents

J. Rights of the data subject

You may revoke consent given at any time via our consent management. You can also restrict or prevent the storage of cookies through the relevant settings in your browser. However, both of the aforementioned measures may impair the functionality of our online offering. As a data subject, you also have the following rights:

Right of access (Art. 15 GDPR)

You have the right to request confirmation from us as to whether personal data concerning you is being processed, as well as access to this data and the further information referred to in Art. 15 GDPR.

Right to rectification (Art. 16 GDPR)

You have the right to demand the immediate rectification of inaccurate data concerning you, as well as the completion of incomplete data.

Right to erasure (Art. 17 GDPR)

You have the right to demand the immediate erasure of data concerning you, provided the requirements of Art. 17 GDPR are met.

Right to restriction of processing (Art. 18 GDPR)

Under certain conditions, you have the right to demand the restriction of processing, in particular:

  1. for as long as you dispute the accuracy of your data (for the duration of the verification),
  2. if processing is/was unlawful and you request restriction instead of erasure,
  3. if we no longer need the data but you require it for the establishment, exercise or defence of legal claims,
  4. for as long as an objection pursuant to Art. 21(1) GDPR has been lodged, pending verification of whether our legitimate grounds override yours.

Restricted data will - apart from being stored - only be processed with your consent or for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest.

Right to data portability (Art. 20 GDPR)

You have the right to receive the data concerning you that you have provided to us on the basis of consent or in the performance of a contract, in a structured, commonly used, machine-readable format, or to request its transmission to another controller, insofar as technically feasible.

Right to object (Art. 21 GDPR)

You have the right, on grounds relating to your particular situation, to object at any time to the processing of data concerning you which is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions (Art. 21(1) GDPR). We will then no longer process your data unless we can demonstrate compelling legitimate grounds for processing which override your interests, or the processing serves to establish, exercise or defend legal claims.

If your data is processed for direct marketing purposes, you have the right to object at any time; this also applies to profiling related to such direct marketing (Art. 21(2) GDPR). Following an objection, your data will no longer be used for direct marketing purposes.

Note on Google Analytics: You can object to the collection and use of your data by Google Analytics at any time with future effect: http://tools.google.com/dlpage/gaoptout?hl=de.

You can also prevent the use of the aforementioned third-party tools by disabling the acceptance of cookies in your browser or by installing a corresponding browser add-on. This may impair your ability to use our online offering.

Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing infringes the GDPR. This right exists without prejudice to any other administrative or judicial remedy.

The supervisory authority with local jurisdiction for ONLOGIST is:

The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Str. 22
20459 Hamburg

Withdrawal of your consent

Where processing is based on your consent, you may withdraw it at any time with future effect. The lawfulness of processing carried out prior to withdrawal remains unaffected.

Provision of personal data

Unless otherwise stated in this privacy policy, you are neither legally nor contractually obliged to provide personal data. However, without the provision of certain data, we may not be able to offer certain functions or services, or only to a limited extent.

We reserve the right to adapt this privacy policy where this becomes necessary due to factual or legal changes. The version published on our online offering shall apply in each case.

If you wish to exercise any right to which you are entitled, please contact the controller named above. To simplify processing, please provide proof of your identity so that we can assign your request to a specific data subject.

Version 1.02, as of: 24 August 2026

This English version is provided for your convenience. In the event of any discrepancy or inconsistency, the German version shall prevail.

Cookie Declaration

A complete and always up-to-date overview of all cookies used on this website (including service, provider, purpose and storage duration) can be found in our Cookie Declaration. There you can also adjust or withdraw your consent at any time.