Software Privacy Policy
Applies not to the use of the website zep.de, but to the use of the platform zep-online.de
Privacy Notice – Platform
(Last updated: 23.04.2025)
ZEP GmbH (hereinafter: “we”, “us”) is pleased that you are visiting our platform (hereinafter: “Website”).
Our principle is to collect only what we need and to process this information exclusively in order to provide you with the service you have signed up for.
1. Controller
The controller responsible for the processing of personal data on our Website within the meaning of the General Data Protection Regulation (hereinafter: “GDPR”) is
ZEP GmbH
Stuttgarter Str. 41
71254 Ditzingen
Germany
2. Data Protection Officer
Our appointed data protection officer is:
Kertos GmbH
Briennerstraße 41
80333 München
Germany
Email: dsb@kertos.io
3. What is personal data?
Personal data is any information relating to an identified or identifiable natural person. This includes, for example, information such as your name, age, address, telephone number, date of birth, email address or IP address. Information that we cannot link to you (or can only link to you with disproportionate effort), e.g. because the information has been anonymised, is not personal data. The processing of personal data (e.g. its collection, retrieval, use, storage or transmission) always requires a legal basis, such as your consent.
4. Data processing on our Website
Provision and use of the Website
a. Scope and purpose of data processing
We collect and use personal data of our users only to the extent technically necessary to provide a functional Website and our content and services or information.
When you access and use our Website, we collect personal data that your browser automatically transmits to our server. This information is temporarily stored in a so-called log file.
The following information is collected without any action on your part and stored until it is automatically deleted:
- IP address of the requesting computer,
- date and time of access,
- name and URL of the file retrieved,
- website from which access is made (referrer URL),
- the browser used and, where applicable, your computer’s operating system and the name of your access provider.
We process the aforementioned data for the following purposes:
- Ensuring a smooth connection to the Website
- Ensuring convenient use of our Website
- For IT security purposes
b. Legal basis
Art. 6(1)(f) GDPR serves as the legal basis. The processing of the aforementioned data is necessary for the provision of a website and to enable its secure and convenient use, and thus serves to protect a legitimate interest of our company.
c. Storage period and data deletion
As soon as the aforementioned data is no longer required for displaying the Website, it is deleted (after 30 days at the latest). The collection of data for the provision of the Website and the storage of data in log files is strictly necessary for the operation of the Website. The user therefore has no possibility to object. Further storage takes place in individual cases where required by law.
d. Third parties
AWS
For hosting the platform, we use an external service provider, Amazon Web Services, Inc., a company of Amazon.com, Inc., 2021 7TH Ave, Seattle, WA 98121, USA (hereinafter: “Amazon”). Your personal data is passed on to Amazon in order to provide the services. The rented instances on Amazon’s servers are located within the European Union. Nevertheless, it cannot be ruled out that data may be forwarded to Amazon servers in the USA. It is therefore possible that the personal data collected may be transferred to the United States. There is an adequacy decision of the European Commission for data transfers to the USA, the EU-U.S. Data Privacy Framework. “Amazon” is certified under this framework, which is why such transfers are based on the legal basis of Art. 45 GDPR.
For further information, please refer to Amazon’s privacy policy https://aws.amazon.com/privacy/ or ask us about the data processing agreement (DPA) concluded.
In order to speed up the loading time of our platform and to protect it against distributed denial-of-service attacks (an attack on our system by means of a large number of requests), we use the content delivery network “CloudFlare”, provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107 (hereinafter: “Cloudflare”).
The use of Cloudflare involves the processing of the following personal data:
- the web page accessed
- the browser type used
- the operating system
- the referrer URL
- the IP address
- the requesting provider
Your personal data is processed only on the basis of your express consent pursuant to Art. 6(1)(a) GDPR. You are entitled to withdraw your consent at any time. However, this does not affect the lawfulness of processing carried out before the withdrawal.
The information is generally transferred to and stored on a Cloudflare server in the USA. For data transfers to the USA, there is an adequacy decision of the European Commission, the EU-U.S. Data Privacy Framework. “Cloudflare” is certified under this framework, which is why such transfers are based on the legal basis of Art. 45 GDPR.
Further information on data protection at “Cloudflare” can be found at: https://www.cloudflare.com/privacypolicy/
Cello
On our Website, we use the service “cello”, provided by Powerplay GmbH, Sumpfmeisenweg 3A, 81249 München, Germany (hereinafter referred to as “cello”). When the service is used, the following data is transmitted to cello:
- Access data
- User data of the user account
- Information on the use of the platform
The purpose of “cello” is to manage and participate in referral programmes and to provide further services and products. The service supports the management of referral programmes and helps us to offer additional services to our customers. The information is generally stored and processed on cello servers in the European Union.
Following transmission, the data is processed in accordance with the applicable data protection laws, in particular the GDPR. cello concludes a data processing agreement with the user.
We have a legitimate interest within the meaning of Art. 6(1)(f) GDPR in the efficient management of referral programmes and the provision of additional services to our customers.
Further information on data protection at cello can be found in its privacy policy at: https://cello.so/privacy-policy/
4. Contact
a. Scope and purpose of data processing
On our Website, we offer you the opportunity to contact us by email. If you contact us, the personal data you provide, such as your salutation, name, the content of the email and your email address, will be processed.
We process this data in order to be able to handle your enquiry properly. If you contact us by email, your personal data will not be passed on to third parties.
b. Legal basis
The data processing described above for the purpose of contacting us is carried out on the basis of Art. 6(1)(f) GDPR, on the basis of our legitimate interest in being able to handle your enquiry. If your enquiry serves to prepare the conclusion of a contract, Art. 6(1)(b) GDPR is an additional legal basis.
c. Storage period and data deletion
As soon as your enquiry has been dealt with and the matter has been conclusively resolved, your personal data processed via the contact form will be deleted. Further storage may take place in individual cases where required by law or necessary for the performance of a contract.
5. Support
On our Website, we use the service “Stonly”, provided by Stonly SAS, 128 Rue La Boétie, 75008 Paris, France. When the service is used, the following data is transmitted to Stonly SAS:
- IP address
- Browser information
- Device information
- Usage statistics of the Stonly guides
The purpose of “Stonly” is to provide interactive guides and assistance for our users. The service helps to improve the user experience and enables us to offer our customers effective self-help options. The information is generally transferred to and stored on a Stonly server in the European Union.
Following transmission, the data is stored for the duration of the use of the service and then deleted.
We have a legitimate interest within the meaning of Art. 6(1)(f) GDPR in optimising our customer service and improving user-friendliness.
Further information on data protection at Stonly can be found at: https://stonly.com/privacy-policy/
6. Cookies
a. Scope and purpose of data processing
We use cookies on our Website.
A cookie is a set of information that is stored on your computer when you visit our Website and that enables your browser to be re-identified. Cookies store information such as your language settings for the duration of your visit to our Website or the entries you make there.
There are different types of cookies. Session cookies are temporary cookies that are stored in the user’s internet browser until the browser window is closed and the session cookies are deleted. Permanent or persistent cookies are used for repeat visits and are stored in the user’s browser for a predefined period of time. First-party cookies are set by the website the user is visiting. Only that website is permitted to read information from the cookies. Third-party cookies are set by organisations other than the operator of the website the user is visiting.
A distinction can also be made between technically necessary, functional and advertising cookies. The former are necessary to ensure basic functions of the website (e.g. storing the language setting). Functional cookies collect information about the user’s behaviour and whether they receive error messages. Advertising cookies, on the other hand, are used to offer the user tailored advertising.
b. Legal basis
Given the purposes of use described, the legal basis for the processing of personal data using technically necessary cookies is Art. 6(1)(f) GDPR, as we have an interest in the user-friendly presentation of our Website.
c. Storage period and data deletion
As soon as the data transmitted to us via the cookies is no longer required to fulfil the purposes described above, this information is deleted. Further storage takes place in individual cases where required by law.
d. Configuration of browser settings
Most browsers are set to accept cookies by default. However, you can configure your browser so that it accepts only certain cookies or no cookies at all. Please note, however, that you may no longer be able to use all functions of our Website if you disable cookies on our Website via your browser settings. You can also use your browser settings to delete cookies already stored in your browser or to display their storage period. It is also possible to set your browser to notify you before cookies are stored. As the various browsers may differ in their respective functions, we ask you to use the help menu of your browser for the configuration options.
e. Cookie list
| NAME | Provider | Purpose | Duration |
|---|---|---|---|
| csrf | Stonly | The purpose is to store an ID for unique user identification by preventing CSRF attacks. | Session |
| _splunk_rum_sid | Cello | The purpose is to store an ID for unique user identification through session monitoring. | 1 day |
| PHPSESSID | ZEP | Identifies a specific session of a specific user and enables changes to be made without logging in again. | Session |
6. International data transfer
We process your data primarily within the European Union (EU) and the European Economic Area (EEA). However, some of our service providers may be located outside the EEA in so-called “third countries”. The General Data Protection Regulation imposes strict requirements on the transfer of personal data to third countries. All of our data recipients must meet these requirements. Before we transfer your data to a service provider in a third country, each service provider is first reviewed with regard to its level of data protection. A service provider is only selected if it can demonstrate an adequate level of data protection outside the EEA. Irrespective of whether our service providers are located within the EEA or in third countries, each service provider must conclude a data processing agreement with us. Additional requirements must be met for service providers outside the EEA. Pursuant to Art. 44 et seq. GDPR, personal data may be transferred to service providers that meet at least one of the following conditions:
- The European Commission has decided that the third country ensures an adequate level of protection (e.g. Israel and Canada).
- Standard contractual clauses have been included in our contract with the data recipient (including any supplementary measures, where necessary).
- Other appropriate safeguards pursuant to Art. 46 GDPR are provided (e.g. binding corporate rules).
- In special exceptional cases pursuant to Art. 49 GDPR
7. Recipients of personal data
Within our company, only those persons who need your personal data for the respective stated purposes have access to it. Your personal data is only passed on to external recipients if we are legally permitted to do so or if you have given your consent. Below you will find an overview of the respective recipients:
- Processors: Group companies or external service providers, e.g. in the areas of technical infrastructure and operations, maintenance and payment processing, which are carefully selected and monitored. Processors may only use the data in accordance with our instructions.
- Public bodies: Authorities and state institutions, such as tax authorities, public prosecutors’ offices or courts, to which we transfer (or are required to transfer) personal data, e.g. to comply with legal obligations or to protect legitimate interests
8. Data security and security measures
We are committed to treating your personal data confidentially. In order to prevent manipulation, loss or misuse of your data stored with us, we take extensive technical and organisational security measures, which are regularly reviewed and adapted to technological progress.
However, we would like to point out that, due to the structure of the internet, it is possible that the rules of data protection and the above-mentioned security measures are not observed by other persons or institutions outside our area of responsibility. In particular, unencrypted data – e.g. when transmitted by email – can be viewed by third parties. We have no technical influence over this. It is your responsibility as a user to protect the data you provide against misuse by means of encryption or in some other way.
9. Data storage
The personal data of the data subject is erased or blocked as soon as the purpose of storage ceases to apply. Storage may also take place if this has been provided for by the European or national legislator in EU regulations, laws or other provisions to which the controller is subject. The data is also blocked or erased when a storage period prescribed by the aforementioned provisions expires, unless further storage of the data is necessary for the conclusion or performance of a contract.
10. Rights of the data subject
With regard to your personal data, you have the following statutory rights vis-à-vis us:
Right of access
You have the right to obtain confirmation as to whether we are processing personal data concerning you. If this is the case, you have the right of access to this personal data and to further information, e.g. about the purposes of processing, the recipients and the envisaged storage period or the criteria used to determine that period.
Right to rectification
You have the right to obtain the rectification of inaccurate data without undue delay. Taking into account the purposes of the processing, you have the right to have incomplete data completed.
Right to erasure (“right to be forgotten”)
You have the right to request erasure if the processing is not necessary. This is the case, for example, if your data is no longer needed for the original purposes, if you have withdrawn your declaration of consent under data protection law, or if the data has been processed unlawfully.
Right to restriction of processing
You have the right to request restriction of processing, e.g. if you believe that the personal data is inaccurate.
Right to data portability
You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format.
Right to object
You have the right to object at any time, on grounds relating to your particular situation, to the processing of certain personal data concerning you. Where personal data is processed for direct marketing purposes, you as the data subject have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling to the extent that it is related to such direct marketing.
Right to withdraw your consent under data protection law
You may withdraw your consent to the processing of your personal data at any time with effect for the future. However, this does not affect the lawfulness of the processing carried out before the withdrawal.
Without prejudice to these rights, you have the right to lodge a complaint with a supervisory authority at any time if you consider that the processing of your personal data infringes data protection regulations.
11. Change history
| Date | Version | Reason for change |
|---|---|---|
| 06.01.2025 | 1.0 | First version of the revised privacy notice in the new format |