Data protection information
In the following, we would like to inform you about the processing of personal data in connection with our website as well as our portal for registered users and the associated app, hereinafter jointly referred to as the "Online Offering".
Controller
ONLOGIST GmbH
Managing Directors: Felix Müller, Moritz Pagendarm
Alter Wandrahm 13
20457 Hamburg
Phone: +49 (0)40 74 30 51 81
Email: info@onlogist.com
Data Protection Officer
Christoph Curvers, Löwenstraße 7, 20251 Hamburg
Email: datenschutz@onlogist.com
1. Privacy at a glance
General information
The following notes provide a simple overview of what happens to your personal data when you visit our website or use our online services as a registered user. Personal data is any data that can be used to personally identify you.
How do we collect your data?
Your data is collected, on the one hand, by you providing it to us (e.g. contact form, registration in the portal, contract initiation). Other data is collected automatically, or, where required, following your consent, by our IT systems when you visit our online offering, for example technical data such as browser type, operating system or access time.
What do we use your data for?
Some of the data is collected to ensure error-free provision of our online offering. Further data is processed to analyse user behaviour and to carry out and process the contractual and billing relationships initiated or existing via the portal between the users involved, as well - within the portal - for the AI-supported review of documents and receipts as part of the billing service.
What rights do you have regarding your data?
You have the right at any time to obtain, free of charge, information about the origin, recipients and purpose of your stored personal data (Art. 15 GDPR). You also have a right to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You may revoke any consent given at any time with future effect. Furthermore, you have the right to lodge a complaint with the competent supervisory authority (Art. 77 GDPR).
A. General information on data processing
A.1 Personal data
According to Art. 4(1) GDPR, personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
This includes, for example, name, address, telephone number and email address, but also whereabouts, IP address or bank details. When using our portal, we require your name, address and further information for a contract or preliminary contract between us and you, or between the user parties, so that we can provide the requested services.
A.2 Processing of personal data
We process the personal data of our users generally only to the extent that this is necessary for the provision of a functioning online offering and the provision of our content and services. Processing regularly takes place only with your consent as a user, unless storage and processing is permitted by statutory provisions, in particular Art. 6(1)(b), (c) or (f) GDPR.
A.3 Disclosure of personal data to third parties and recipients
Your personal data will only be disclosed if there is a legal basis under data protection law for doing so. Disclosure may in particular take place:
- to processors who process personal data on our behalf and in accordance with our instructions,
- to independently responsible parties, insofar as this is necessary for the performance of the contract or due to statutory obligations,
- to other recipients, if you have consented or we are legally or officially obliged to do so.
Insofar as we use external service providers who process personal data on our behalf, this is done on the basis of data processing agreements pursuant to Art. 28 GDPR. These service providers process personal data exclusively in accordance with our instructions and only to the extent necessary to perform their respective services.
ONLOGIST only passes on your data to such private third parties who provide services in the name of and on behalf of ONLOGIST and who are listed in this privacy policy. Our employees and service providers are obliged to maintain confidentiality and to protect the personal and company-related data entrusted to them.
We carefully review, on a case-by-case basis, which third-party services we use and whether personal data is disclosed in the process. We include such processing in this privacy policy in accordance with applicable requirements.
Insofar as we use external processors to provide our platform services - in particular providers of AI-supported processing systems - the disclosure of personal data to these providers is based on data processing agreements pursuant to Art. 28 GDPR. These providers process your data exclusively in accordance with our instructions and for the purposes we determine. Where this involves a transfer to third countries outside the EU or EEA, we ensure an adequate level of data protection through appropriate safeguards within the meaning of Art. 46 GDPR (in particular EU Standard Contractual Clauses). The relevant providers can be found in the list of recipients under Section I.
A.4 Note on data transfer to the USA and other third countries
We partly use services from providers based outside the European Union or the European Economic Area, or who process data there. Insofar as personal data is transferred to third countries in this context, this is done in compliance with the statutory requirements. Where no adequacy decision exists for the third country concerned, we base the transfer in particular on appropriate safeguards within the meaning of Art. 46 GDPR, namely the European Commission's Standard Contractual Clauses. Where a provider is certified under a recognised data protection framework, the transfer may also be based on this. We would like to point out that, despite contractual and organisational safeguards, a level of data protection equivalent to that within the European Union cannot be guaranteed in all cases of third-country transfers.
A.5 Automatic collection of technical data (server log files)
Each time our online offering is accessed, our system automatically collects data and information from the computer system of the accessing computer. This data is not stored together with other personal data of the user.
The following data is stored for organisational and technical reasons:
• Your IP address
• Browser type and version used
• Your operating system (name, version)
• Your Internet service provider
• Date and time of access
• Websites from which your system accesses our online offering (referrer URL)
• Host name of the accessing computer
• Screen resolution, if applicable
• Names of retrieved files/content
The legal basis for the temporary storage of the data and log files is our legitimate interest pursuant to Art. 6(1)(f) GDPR. The collection of this data and its storage in log files is technically necessary for the secure and technically required operation of our online offering; there is accordingly no possibility of objection. Technical data is automatically deleted after 30 days.
A.6 General information on the legal bases of data processing
If you have consented to the processing of your personal data, processing takes place on the basis of Art. 6(1)(a) GDPR; where special categories of personal data are processed, additionally on the basis of Art. 9(2)(a) GDPR. Where consent is required for the storage of cookies or access to information on your terminal device, this additionally takes place on the basis of Section 25(1) TDDDG (German Telecommunications-Digital-Services-Data-Protection Act). Where your data is required for the performance of a contract or the implementation of pre-contractual measures, processing takes place on the basis of Art. 6(1)(b) GDPR. Where we are legally obliged to process personal data, this takes place on the basis of Art. 6(1)(c) GDPR. In all other cases, we base processing on our legitimate interest pursuant to Art. 6(1)(f) GDPR. The following sections provide detailed information on the respective applicable legal basis.
A.7 Purpose
ONLOGIST processes your personal data only for the purposes set out in this notice and on the basis of the respective legal bases indicated.
A.8 Use of AI-supported systems (overview)
We partly use automated systems in the portal that are based on artificial intelligence (AI) technologies. These systems assist us in reviewing documents and receipts as well as in processing billing procedures and the registration of service providers. Their use is subject to applicable data protection requirements and, where relevant, AI law requirements, in particular Regulation (EU) 2024/1689 on artificial intelligence (AI Act). Details on this - purpose, functioning, legal basis and your rights - can be found in Section E.4.
In no case does an AI system make a final decision without human review and control. Final decision-making authority always remains with an ONLOGIST employee or with you as the user.
A.9 Encrypted transmission
In the case of online collection and processing of personal data, information is transmitted in encrypted form (via HTTPS). Our online offering automatically enforces encrypted transmission of all content throughout. Encryption technologies that correspond to the current state of the art are used; security measures are continuously reviewed.
A.10 Storage period (general)
Unless a more specific storage period is stated within this privacy policy, your personal data will remain with us until the purpose of the data processing no longer applies. In the event of a legitimate request for erasure or revocation of consent, your data will be deleted, provided there are no other legally permissible grounds for storage (e.g. tax or commercial law retention periods); in this case, deletion takes place once the grounds no longer apply.
B. Hosting and Content Delivery Networks (CDN)
For the provision and delivery of our online offering, we use infrastructure and hosting services from the following technical service providers:
Amazon Web Services (AWS)
The provider is Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, 1855 Luxembourg.
When using our online offering, personal data may be processed on AWS servers; personal data may also be transferred to companies affiliated with AWS in third countries. In this case, data transfer is based on EU Standard Contractual Clauses.
The legal basis for the use of hosting and infrastructure services is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and efficient provision of our online offering.
Amazon CloudFront CDN
We use the Amazon CloudFront content delivery network. The provider is also Amazon Web Services EMEA SARL. CloudFront routes the transfer of information between your browser and our online offering via a globally distributed network, thereby increasing availability and performance.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the high-performance, stable and secure delivery of our online offering. For data transfer to third countries, see AWS above.
Hetzner
The provider is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen.
Use is made for the purpose of the secure, stable and efficient provision of our online offering. The legal basis is Art. 6(1)(f) GDPR and, insofar as processing is necessary for the performance of contractual services, additionally Art. 6(1)(b) GDPR.
NETWAYS Managed Services GmbH (NMS)
The provider is NETWAYS Managed Services GmbH, Deutschherrnstr. 15-19, 90429 Nuremberg.
When using our online offering, personal data may be processed on NMS servers; personal data may also be transferred to companies affiliated with NMS in third countries. In this case, data transfer is based on EU Standard Contractual Clauses.
The legal basis for the use of hosting and infrastructure services is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and efficient provision of our online offering.
STRATO
The provider is STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin. When you visit our online offering, STRATO collects various log files including your IP address. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the reliable presentation of our online offering.
C. Cookies and consent management
C.1 Use of cookies
Insofar as cookies or comparable technologies are technically necessary, their use is based on Section 25(2) No. 2 TDDDG. The subsequent processing of personal data is based on Art. 6(1)(f) GDPR; our legitimate interest lies in the technically error-free and secure provision of our online offering. We only use all non-technically-necessary cookies and comparable technologies on the basis of your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
Some cookies are deleted after you close your browser (transient cookies, including session cookies). Other cookies (persistent cookies) remain on your terminal device and allow your browser to be recognised on your next visit. You can set your browser so that you are informed about the setting of cookies, allow cookies only in individual cases, exclude them altogether, or have them automatically deleted when you close your browser. Please note that disabling cookies may impair the functionality of our online offering.
An overview of the cookies used, their providers, purpose and storage period, your current consent status, and the option to revoke your consent with future effect can be found in our cookie notice at https://www.onlogist.com/cookie-erklaerung
C.2 Consent management with Cookiebot
Our online offering uses Cookiebot's consent technology to obtain and document, in a manner compliant with data protection law, your consent to the storage of certain cookies or the use of certain technologies. The provider is Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark.
When our online offering is accessed, a connection is established to Cookiebot's servers. Cookiebot then stores a cookie in your browser in order to be able to assign consents granted to you or their revocation. The data is stored until you request us to delete it, you delete the Cookiebot cookie yourself, or the purpose no longer applies. Mandatory statutory retention obligations remain unaffected.
The legal basis is Art. 6(1)(c) GDPR, insofar as we are legally obliged to obtain and document consent, and additionally Art. 6(1)(f) GDPR with regard to the legally compliant organisation of our consent management.
D. Analytics tools, tracking and advertising
Note on scope of application: The analytics, tracking and marketing services described below are used exclusively on the publicly accessible areas of our online offering. These services are not used in the logged-in portal area for registered users, unless otherwise specified below.
Google Tag Manager
We use Google Tag Manager, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, for the technical integration and management of further services and scripts. Google Tag Manager itself does not create user profiles and does not carry out any independent analyses. Insofar as services requiring consent are integrated via Google Tag Manager, this only takes place after your consent; the legal basis in this respect is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
Google Analytics
We use Google Analytics, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, for reach measurement and analysis of the use of our online offering. Google Analytics in particular enables us to evaluate page views, dwell times, the origin of the visit, as well as technical information on the devices and browsers used. Google Analytics uses cookies and comparable technologies to recognise users and devices. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Consent can be revoked at any time with future effect.
Insofar as personal data is transferred to third countries in connection with the use of Google Analytics, this is done on the basis of appropriate safeguards pursuant to Art. 46 GDPR.
We have activated IP anonymisation. As a result, your IP address is generally shortened within the EU or EEA prior to any further processing.
Where the "Google Signals" feature is activated, additional aggregated information on cross-device user behaviour, interests and demographic characteristics may be provided. We only receive this information in aggregated form. This, too, is only used on the basis of your consent.
Google Ads, remarketing and conversion tracking
We use Google Ads, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, for performance measurement, audience building and re-engaging users. In particular, cookies, similar technologies and - where used - hashed customer data may be used for this purpose. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
Meta Pixel, formerly Facebook Pixel, incl. advanced matching
We use Meta technologies for reach measurement, conversion measurement, audience building and re-engaging users. This may involve processing information on visits to our website, devices used, technical identifiers, and - where used - hashed contact information.
The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
Insofar as Meta jointly determines the purposes and means of processing with us in connection with the collection and transmission of data, this constitutes joint controllership pursuant to Art. 26 GDPR; a corresponding controller addendum on joint controllership is in place.
Meta Conversion API, formerly Facebook Conversion API
We use the Meta Conversion API, a service of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, to record interactions with our online offering in order to improve the advertising performance of our ads on Facebook and other Meta services. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR.
Meta Custom Audiences, formerly Facebook Custom Audiences
We use Custom Audiences, a service of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, to define target audiences (including lookalike audiences) for advertising on Facebook. The legal basis is consent pursuant to Art. 6(1)(a) GDPR.
LinkedIn Insight Tag
We use LinkedIn Insight Tags, a service of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, D02 AD98, Ireland, to analyse professional details of website visitors registered with LinkedIn, for conversion purposes and for retargeting. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR.
E. Portal-specific data processing for registered service providers and clients
E.1 Processing of your IP address by the web servers
Your IP address is processed insofar as this is technically necessary to deliver the content of our portal to your device and to ensure the security of operations. Storage takes place for the duration of the usage session and, where necessary, additionally in server log files pursuant to Section A.5.
E.2 Registration in the portal
You can register in the portal in order to use its functions. We only use the data entered for the purpose of setting up, providing and managing your user account and for carrying out the respective usage relationship. Mandatory fields must be completed in full; otherwise we will reject the registration. We use the email address provided to inform you of important changes.
The legal basis is Art. 6(1)(b) GDPR (performance of the usage relationship, if applicable initiation of further contracts). The data is stored for as long as you are registered, and then deleted; statutory retention periods remain unaffected.
E.3 Mobile app - location and movement data
Users of the mobile app give the following consent:
"I agree that ONLOGIST collects location and movement data from my smartphone in order to provide clients with order-related information, such as estimated arrival times and information on driving behaviour."
This consent is voluntary and may be revoked at any time without giving reasons pursuant to Art. 7(3) GDPR. Please note that certain mobile functions of the platform - in particular those that require order-related status and arrival information - cannot be provided without this data processing, so that an order cannot be assigned in this case.
E.4 AI-supported systems in the portal
We use AI-supported functions in the portal to support certain review procedures and processing steps. These systems serve to prepare, structure and plausibility-check information; a final professional decision is not made exclusively by automated means.
E.4.1 AI-supported receipt processing
Process:
- OCR extraction: After the receipt (e.g. fuel receipts, toll charges, hotel invoices, parking fees, local transport costs, vehicle cleaning) is uploaded, the receipt content is read out using an OCR procedure on the service provider's device.
- AI-supported categorisation: The extracted receipt data is transmitted via an encrypted API interface to an external AI model, which extracts and categorises relevant information (net/gross amount, type of service, date, location, quantity refuelled if applicable).
- System-side plausibility check: An automated, rule-based procedure (without AI) compares location, date and quantity with the order data; in the event of discrepancies, an automatic query is sent to the service provider.
- Automatic completion of receipt fields with the categorised data.
- Manual post-processing: The service provider can check and adjust the data at any time. Receipts are only submitted for further review after being checked and approved.
Data processed: Date/time of the transaction, location (allows inference of whereabouts), type of service, transaction amount, quantity, name/identification details of the service provider (if included on the receipt).
Purpose: Efficient, low-error and transparent processing of expense reimbursements as part of the billing service.
Legal basis: Art. 6(1)(b) GDPR (performance of the usage contract).
Recipient: The provider of the AI model is listed in the list of recipients under Section I; transmission takes place on the basis of a data processing agreement pursuant to Art. 28 GDPR.
No fully automated decision (Art. 22 GDPR): The AI output serves exclusively for the pre-filled display; the service provider can fully adjust the data before submission.
Notice pursuant to Art. 50 AI Act: The AI support is recognisable as such in the system; the result can be viewed and adjusted before submission.
E.4.2 AI-supported receipt review on behalf of clients
Process:
- Transmission of the submitted receipt files via an encrypted API interface to the external AI model.
- OCR extraction and categorisation as per E.4.1.
- Automatic comparison of the extracted data with the receipt data provided by the service provider.
- Categorisation of discrepancies in a traffic-light system (no/minor/significant discrepancy) with a description of the finding.
- Review by the authorised user of the client; this user can adopt or override the AI categorisation.
- Feedback on change requests to the service provider for renewed approval.
Purpose: Automated pre-review of receipts as part of billing control; ensuring correct billing and preventing misuse.
Legal basis: Art. 6(1)(b) GDPR (client usage contract/service provider billing relationship), additionally Art. 6(1)(f) GDPR.
Recipient: As per E.4.1. The processed receipt data and review results are made accessible to the respective client as an independently responsible party (Art. 4 No. 7 GDPR) in the context of contract performance.
No binding AI decision: The AI output constitutes a review recommendation, which must always be manually reviewed, adopted or overridden by the client user.
Notice pursuant to Art. 50 AI Act: The pre-review is carried out by an AI system; results are marked as such and do not constitute final findings.
E.4.3 AI-supported review of service provider profiles during registration
Process:
- Document upload: company details, trade licence, driving licence, extended certificate of good conduct, proof of tax number.
- AI-supported document extraction via an encrypted API interface; extraction of predefined data fields.
- Comparison of data with the details entered during registration.
- Overall assessment and recommendation regarding activation or requesting additional/corrected documents.
- Final decision by an ONLOGIST service employee, who is not bound by the AI recommendation.
Data processed:
- General company data (company name, legal form, address, contact details)
- Trade licence (commercial activity, if applicable date of birth/place of residence of the holder)
- Driving licence (name, date of birth, date of issue/expiry, categories, photograph)
- Extended certificate of good conduct (personal data, if applicable criminal convictions/entries)
- Tax number/proof thereof
Special categories of data:
- Certificate of good conduct (Art. 10 GDPR): Processing solely to verify personal suitability requirements for platform participation, on the basis of Art. 10 GDPR in conjunction with relevant national provisions and, where necessary, explicit consent analogous to Art. 9(2)(a) GDPR. Only information relevant to the suitability check is processed; no further storage takes place.
- Photograph on the driving licence: Is currently not processed for biometric identification or biometric matching. In the event of a future introduction of biometric image processing, this notice will be updated and, where applicable, explicit consent pursuant to Art. 9(2)(a) GDPR will be obtained.
Purpose: Ensuring that only suitable, identifiable and reliable service providers operate on the platform; protection of clients and platform integrity.
Legal bases are Art. 6(1)(b) GDPR for general registration data as well as Art. 10 GDPR in conjunction with national provisions, additionally Art. 9(2)(a) GDPR analogously for certificate-of-good-conduct data.
Recipient: As stated above under E.4.1, data processing agreement pursuant to Art. 28 GDPR; in the case of third-country transfer, safeguards pursuant to Art. 46 GDPR.
No fully automated decision (Art. 22(1) GDPR): The binding decision on activation/rejection is always made by an ONLOGIST employee, who may deviate from the AI recommendation.
You have the right to request at any time that the decision on your profile activation be made exclusively manually by an employee, without involvement of the AI recommendation. Please send requests to service@onlogist.com
Notice pursuant to Art. 50(1) AI Act: The AI system used is to be classified as a high-risk AI system within the meaning of Annex III No. 4 of the AI Act, as it is used in the field of selecting natural persons seeking access to self-employment. As operator pursuant to Art. 3 No. 4 of the AI Act, ONLOGIST ensures that human oversight pursuant to Art. 26 of the AI Act is guaranteed, that the technical documentation and logging obligations of the AI Act are fulfilled, and that a data protection impact assessment (DPIA) pursuant to Art. 35 GDPR has been carried out.
Storage period: Documents uploaded during the registration process are not permanently stored in the AI system after the review is completed. Storage in the ONLOGIST system takes place for the duration of the usage relationship as well as statutory retention periods. Data from the certificate of good conduct is deleted after the review is completed and is not stored permanently.
F. Other services and plugins used
Asana
We use Asana, a service of Asana Inc., 633 Folsom Street Suite 100, San Francisco, CA 94107-3600, USA, for the internal organisation of workflows and the structured processing of enquiries and matters. Only the personal data required for the respective matter is processed. The legal basis is Art. 6(1)(f) GDPR.
Braun Heider GmbH
We use services provided by Braun Heider GmbH, Klingholzstr. 18, 65189 Wiesbaden, for hosting our services as well as for system administration and maintenance of hardware and software. The legal basis is Art. 6(1)(b) GDPR.
GGW
We use services provided by GGW GmbH, Chilehaus B, Fischertwiete 1, 20095 Hamburg, insofar as this is necessary for handling insurance-related matters or claims. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the efficient handling of insurance-related matters.
HubSpot CRM
We use HubSpot, a service of HubSpot Inc., 25 First Street, Cambridge, MA 02141, USA, to manage contacts, process enquiries and - where activated - to document and evaluate sales- and communication-related interactions. Insofar as cookies or comparable technologies are used in this context, this is based on your consent; otherwise we base processing on Art. 6(1)(b), or in the alternative (f) GDPR.
IDnow
We use services provided by IDnow GmbH, Auenstraße 100, 80469 Munich, for identity verification as part of the registration and approval process, insofar as this is necessary to fulfil statutory requirements. The legal basis is Art. 6(1)(c) GDPR.
Mailchimp
We use Mailchimp, a service of The Rocket Science Group, LLC, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA, to send newsletters. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR.
Pingen
We use services provided by Pingen GmbH, Badenerstrasse 47, 8004 Zurich, Switzerland, for the postal dispatch of invoices. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the efficient design of our mailing processes.
RHD Factoring
We use services provided by RHD Rechnungsstelle AG, Am Wall 96-98, 28195 Bremen, insofar as this is necessary for the provision of factoring services for the timely payment of remuneration to service providers. The legal basis is Art. 6(1)(b) GDPR.
Sisense
We use services provided by Sisense Inc., 1359 Broadway FL 4, New York, NY 10018-8339, USA, to evaluate business metrics and produce reports. Personal data is only processed insofar as this is necessary for the respective analysis; the legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the need for robust business metrics for company management.
Slack
We use Slack, a service of Slack Technologies Ltd., Salesforce Tower 60 R801, North Dock, Dublin, Ireland, for internal communication and collaboration among our employees. Personal data is only processed insofar as this is necessary for internal communication. The legal basis is Art. 6(1)(f) GDPR.
Smallinvoice
We use Smallinvoice, a service of Lourens Systems GmbH, Badenerstrasse 47, 8004 Zurich, Switzerland, for creating and sending invoices. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the efficient handling of our accounting.
Smashleads
We use Smashleads, a service of smashleads UG (haftungsbeschränkt), Kiebitzweg 5, 50354 Hürth, to generate and manage prospect enquiries. Contact data, communication content and technical usage data may be processed. The legal basis is Art. 6(1)(f) GDPR; insofar as cookies or comparable technologies are used in this context, this is only done on the basis of your consent.
Teams
We use Teams, a service of Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, to conduct audio, video and online conferences. Participant master data, technical connection data, communication content and - where used - chat, file and sharing content is processed. The legal basis is Art. 6(1)(b) GDPR, insofar as communication takes place in connection with existing or initiated contractual relationships, and additionally Art. 6(1)(f) GDPR. Where a recording or other function requiring consent is used, this is only done on the basis of your consent.
Twilio
We use Twilio, a service of Twilio Inc., 375 Beale St, Suite 300, San Francisco, CA 94105, USA, to send SMS messages to validate mobile phone numbers during the registration process. The legal basis is Art. 6(1)(b) GDPR.
Zapier
We use Zapier, a service of Zapier Inc., Market St. #62411, San Francisco, CA 94104-5401, USA, for the technical connection, synchronisation and automation of applications, systems and data flows. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the efficient design of our business processes.
Zendesk
We use Zendesk, a service of Zendesk, Inc., 1019 Market Street, San Francisco, CA 94103, USA, to process user enquiries and chat communication. In doing so, we process the data you provide as part of your enquiry, in particular contact details, the content of your enquiry and - when using the chat function - technical connection data such as your IP address. The legal basis is Art. 6(1)(f) GDPR.
G. eCommerce, payment providers and contract data
Processing of customer and contract data
We collect, process and use personal customer and contract data to establish, structure and amend our contractual relationships. The legal basis is Art. 6(1)(b) GDPR.
Contact form, telephone, postal and email enquiries
If you contact us by contact form, email, telephone or fax, we store your details, including contact data, to process your enquiry and for any follow-up questions. The legal basis is Art. 6(1)(b) GDPR, insofar as the enquiry is related to contract performance or pre-contractual measures; otherwise our legitimate interest in effective processing pursuant to Art. 6(1)(f) GDPR, whereby our legitimate interest lies in the efficient and traceable processing of enquiries, and, where requested, your consent pursuant to Art. 6(1)(a) GDPR.
In the case of telephone contact, your telephone number (if transmitted) is stored as a communication date in the call history and automatically deleted after 90 days; the relevant legal basis is Art. 6(1)(a) or (f) GDPR.
As a general rule, we do not pass on the aforementioned data to third parties without authorisation. Disclosure only takes place if there is a legal basis for doing so, if this is necessary to process your enquiry, or if you have consented.
H. Handling of applicant data
We process personal data of applicants exclusively for the purpose of conducting the application procedure. This includes, in particular, contact data, communication data, application documents, and interview and evaluation notes, insofar as these are necessary for the decision on establishing an employment relationship. The legal basis is Section 26 BDSG (German Federal Data Protection Act) as well as Art. 6(1)(b) GDPR; where consent has been given, additionally Art. 6(1)(a) GDPR.
In the event of a successful application, the data is stored on the basis of Section 26 BDSG and Art. 6(1)(b) GDPR for the purpose of carrying out the employment relationship.
In the event of a rejection or withdrawal of the application, we generally store your data for up to six months after completion of the application procedure, unless longer storage is permissible on the basis of consent or due to statutory or procedural requirements.
I. Recipients of personal data
Personal data is disclosed - depending on the processing operation - to the categories of recipients listed below. Insofar as service providers process personal data on our behalf, this is done on the basis of Art. 28 GDPR. Where recipients process data under joint or their own responsibility under data protection law, this is marked accordingly.
I.1 Processors with whom a data processing agreement pursuant to Art. 28 GDPR has been concluded
| Company | Address | Purpose |
|---|---|---|
| Amazon Web Services EMEA SARL | 38 Avenue John F. Kennedy, 1855 Luxembourg | Hosting/CDN |
| Appsflyer Ltd. | 14 Maskit St, 6th Floor, POB 12371 Herzliya 4673314 Israel | Behavioural and marketing tracking |
| Asana Inc. | 633 Folsom Street Suite 100, San Francisco, CA 94107-3600 USA | Project management |
| Ascentiel International S.L. | C/ Pollensa 2, edificio Artemisa, Of. 15-16 28290 Las Rozas de Madrid Spain | Insurance broker |
| AXA AXA Seguros Generales S.A | Calle Monseñor Palmer, 1 07014 Palma de Mallorca Spain | Motor vehicle liability insurance |
| Baloise Assurance Luxembourg S.A. | 8, rue du Château d'Eau 3364 Leudelange Luxembourg | Motor vehicle liability insurance |
| Braun Heider GmbH | Klingholzstr. 18 65189 Wiesbaden Germany | System administration/IT operations |
| Cloudflare Inc. | 101 Townsend Street San Francisco, CA 94107 USA | Website security plugin |
| Deepl SE | Maarweg 165 50825 Cologne Germany | Translation tool |
| ERGO Versicherung AG | Stresemannstr. 111 10963 Berlin Germany | Liability insurance |
| GGW GmbH | Chilehaus B, Fischertwiete 1 20095 Hamburg Germany | Insurance broker |
| Global Assekuranz Nord GmbH | Friesenweg 24 22763 Hamburg Germany | Insurance broker |
| Google Ireland Limited | Gordon House, Barrow Street, Dublin 4 Ireland | Analytics/marketing/tag manager |
| Hetzner Online GmbH | Industriestr. 25 91710 Gunzenhausen Germany | Hosting |
| Hubspot Inc. | 25 First Street Cambridge, MA 02141 USA | CRM |
| IDnow GmbH | Auenstraße 100 80469 Munich Germany | Identity verification |
| KASKO Germany UG (haftungsbeschränkt) | Hoheluftchaussee 95 20253 Hamburg Germany | IT agency developing software solutions for insurance and transmitting data |
| LinkedIn Ireland Unlimited Company | Wilton Place Dublin 2, D02 AD98 Ireland | Insight Tag |
| Lourens Systems GmbH | Badenerstrasse 47 8004 Zurich Switzerland | Invoicing (Smallinvoice) |
| Mailchimp (The Rocket Science Group, LLC) | 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA | Newsletter dispatch |
| Meta Platforms Ireland Limited | 4 Grand Canal Square, Dublin 2 Ireland | Meta Pixel/Conversion API/Custom Audiences |
| Microblink LLC Croatia | Strojarska cesta 20 10000 Zagreb Croatia | Driving licence scanning tool |
| Microsoft Corporation | One Microsoft Way, Redmond, WA 98052-6399, USA | Teams/various services |
| NETWAYS Managed Services GmbH | Deutschherrnstr. 15-19 90429 Nuremberg | Hosting/CDN |
| Pingen GmbH | Badenerstrasse 47 8004 Zurich Switzerland | Postal dispatch |
| RHD Rechnungsstelle AG | Am Wall 96-98 28195 Bremen Germany | Factoring |
| Sisense Inc. | 1359 Broadway FL 4 NY 10018-8339 USA | Business analytics |
| Slack Technologies Ltd. | Salesforce Tower 60 R801, North Dock, Dublin Ireland | Internal communication |
| STRATO AG | Otto-Ostrowski-Straße 7 10249 Berlin Germany | Hosting |
| The MSA Group/ MSA MIZAR S.P.A. | Via Sangro 15 20132 Milano Italy | Claims management |
| T-Systems International GmbH | Friedrich-Ebert-Allee 140 53113 Bonn Germany | Hosting |
| Twilio Inc. | 375 Beale St, Suite 300 San Francisco, CA 94105 USA | SMS validation |
| Usercentrics A/S | Havnegade 39 1058 Copenhagen Denmark | Consent management platform (Cookiebot) |
| VIG platform partners GmbH | Schottenring 30 1010 Vienna Austria | Insurance agent |
| Zapier Inc. | Market St. #62411 San Francisco, CA 94104-5401 USA | Tool integration |
| ZENDESK, Inc. | 1019 Market St San Francisco, CA 94103 USA | Support/CRM/chat/telephone system |
I.2 Processors for AI-supported receipt processing/review (Section E.4) and document verification, with whom a data processing agreement pursuant to Art. 28 GDPR has been concluded
| Company | Address | Purpose |
|---|---|---|
| OpenAI Ireland Ltd. | 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland | Automated analysis and plausibility checking of receipts and registration documents |
J. Rights of the data subject
You may revoke consent given at any time via our consent management. You can also restrict or prevent the storage of cookies through the relevant settings in your browser. However, both of the aforementioned measures may impair the functionality of our online offering. As a data subject, you also have the following rights:
Right of access (Art. 15 GDPR)
You have the right to request confirmation from us as to whether personal data concerning you is being processed, as well as access to this data and the further information referred to in Art. 15 GDPR.
Right to rectification (Art. 16 GDPR)
You have the right to demand the immediate rectification of inaccurate data concerning you, as well as the completion of incomplete data.
Right to erasure (Art. 17 GDPR)
You have the right to demand the immediate erasure of data concerning you, provided the requirements of Art. 17 GDPR are met.
Right to restriction of processing (Art. 18 GDPR)
Under certain conditions, you have the right to demand the restriction of processing, in particular:
- for as long as you dispute the accuracy of your data (for the duration of the verification),
- if processing is/was unlawful and you request restriction instead of erasure,
- if we no longer need the data but you require it for the establishment, exercise or defence of legal claims,
- for as long as an objection pursuant to Art. 21(1) GDPR has been lodged, pending verification of whether our legitimate grounds override yours.
Restricted data will - apart from being stored - only be processed with your consent or for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest.
Right to data portability (Art. 20 GDPR)
You have the right to receive the data concerning you that you have provided to us on the basis of consent or in the performance of a contract, in a structured, commonly used, machine-readable format, or to request its transmission to another controller, insofar as technically feasible.
Right to object (Art. 21 GDPR)
You have the right, on grounds relating to your particular situation, to object at any time to the processing of data concerning you which is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions (Art. 21(1) GDPR). We will then no longer process your data unless we can demonstrate compelling legitimate grounds for processing which override your interests, or the processing serves to establish, exercise or defend legal claims.
If your data is processed for direct marketing purposes, you have the right to object at any time; this also applies to profiling related to such direct marketing (Art. 21(2) GDPR). Following an objection, your data will no longer be used for direct marketing purposes.
Note on Google Analytics: You can object to the collection and use of your data by Google Analytics at any time with future effect: http://tools.google.com/dlpage/gaoptout?hl=de.
You can also prevent the use of the aforementioned third-party tools by disabling the acceptance of cookies in your browser or by installing a corresponding browser add-on. This may impair your ability to use our online offering.
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing infringes the GDPR. This right exists without prejudice to any other administrative or judicial remedy.
The supervisory authority with local jurisdiction for ONLOGIST is:
The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Str. 22
20459 Hamburg
Withdrawal of your consent
Where processing is based on your consent, you may withdraw it at any time with future effect. The lawfulness of processing carried out prior to withdrawal remains unaffected.
Provision of personal data
Unless otherwise stated in this privacy policy, you are neither legally nor contractually obliged to provide personal data. However, without the provision of certain data, we may not be able to offer certain functions or services, or only to a limited extent.
We reserve the right to adapt this privacy policy where this becomes necessary due to factual or legal changes. The version published on our online offering shall apply in each case.
If you wish to exercise any right to which you are entitled, please contact the controller named above. To simplify processing, please provide proof of your identity so that we can assign your request to a specific data subject.
Version 1.02, as of: 24 August 2026
This English version is provided for your convenience. In the event of any discrepancy or inconsistency, the German version shall prevail.