✓ Strict Data Minimization & Security by Design
We strictly avoid tracking cookies, third-party analytics scripts, and advertising networks. All core services, stylesheets, and fonts are self-hosted on secure servers located within Germany / European Union.
1. Controller
The controller responsible for data processing on this website and associated application services under the General Data Protection Regulation (GDPR) is:
2. Server Hosting & Log Files
When visiting this website, our web servers automatically log technical request data to ensure stable operation and cybersecurity (Art. 6 (1) lit. f GDPR):
- IP address of the accessing client
- Date and exact timestamp of the request
- Requested URL path and HTTP status code
- Transferred data volume in bytes
- Referrer URL (if provided by client browser)
- User-Agent (browser type and operating system)
Log files are processed exclusively for security diagnostics, attack prevention, and debugging, and are automatically rotated and deleted.
3. Cookies & Local Storage
We do NOT use tracking, profiling, or third-party marketing cookies. We only use technically necessary session cookies (e.g. for authentication in the Business Portal), which are legally permitted without prior consent pursuant to Section 25 (2) No. 2 TDDDG (German Telecommunications Telemedia Data Protection Act).
4. Contact Forms & Project Inquiries
When submitting project inquiries for custom development, e-invoicing, label printing, contract management, or sanctions compliance, the data you enter (name, company, email, phone, requirements) is processed pursuant to Art. 6 (1) lit. b GDPR (pre-contractual measures and contract performance).
5. Business Suite & User Account Processing
Users registered in our Business Suite can manage tenants, customers (debtors), suppliers (creditors), quotes, and invoices.
- Account Data: Name, E-Mail-Adresse, sicher gehashte Passwörter (Bcrypt/Argon2).
- Master Data: Firmennamen, Anschriften, USt-IdNr., Steuernummern, Bankverbindungen (IBAN/BIC), Ansprechpartner.
- Invoicing & Accounting Data: Rechnungsbeträge, Positionen, Steuersätze, Fälligkeiten und Zahlungsstatus.
Legal basis: Art. 6 (1) lit. b GDPR (fulfillment of user contract) and Art. 6 (1) lit. c GDPR in conjunction with statutory retention obligations under German tax law (Section 147 AO, Section 14b UStG).
6. E-Invoicing (EN 16931) & DATEV Hub
Our software processes e-invoices according to the European standard EN 16931 (XRechnung and ZUGFeRD XML). Generated DATEV export files (EXTF 700 format, SKR03 / SKR04) contain structured posting batches and master data to be forwarded to certified tax advisors.
7. PSD2 Open Banking & Payment Processing
To enable automated invoice reconciliation and payment initiation, the application provides integration with PSD2-regulated banking interfaces (such as GoCardless Bank Account Data API / formerly Nordigen):
- Read-only Account Information (AIS): Abruf von Kontoständen und Umsatzdaten (Datum, Betrag, Verwendungszweck, IBAN des Zahlers) ausschließlich nach ausdrücklicher Autorisierung durch den Nutzer (Art. 6 Abs. 1 lit. a und b DSGVO).
- Payment Initiation & SEPA: Generierung von ISO 20022 XML-Dateien (`pain.001`) und EPC-QR-Codes (GiroCode) zur fehlerfreien Anweisung von Lieferantenüberweisungen.
- Security: Bank-Zugangsdaten (PIN/TAN) werden zu keinem Zeitpunkt auf unseren Servern gespeichert, sondern verbleiben ausschließlich im zertifizierten Autorisierungsdialog Ihrer Bank.
8. Data Processing Agreement (DPA / AVV)
For enterprise clients processing personal data of third parties (e.g. customer data) within the Siedelmann Business Suite, we provide a compliant Data Processing Agreement (DPA) pursuant to Art. 28 GDPR upon request at stefan@siedelmann.com.
9. Retention Periods & Deletion
We process and store personal data only for the period necessary to achieve the purpose of storage, or as required by European directives or national laws. Accounting documents and tax-relevant records are retained for 8 or 10 years in compliance with Section 147 AO and Section 257 HGB.
10. Your Rights as a Data Subject
Under the GDPR, you have the following rights regarding your personal data:
- Art. 15 DSGVO: Right of access to your stored data
- Art. 16 DSGVO: Right to rectification of incorrect data
- Art. 17 DSGVO: Right to erasure (Right to be forgotten)
- Art. 18 DSGVO: Right to restriction of processing
- Art. 20 DSGVO: Right to data portability in a structured format
- Art. 21 DSGVO: Right to object to processing based on legitimate interests
- Art. 7 Abs. 3 DSGVO: Right to withdraw consent at any time
To exercise your rights, simply send an email to stefan@siedelmann.com.
11. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. The responsible supervisory authority for our registered office is:
12. Validity and Changes to this Privacy Policy
This privacy policy is currently valid as of October 2026. Due to the further development of our website and applications or due to changed legal requirements, it may become necessary to adapt this policy.