Privacy Policy
Last updated: 13 August 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and other data protection provisions is:
Sophera Consulting
Max Fey
Elsdorfer Straße 29
50126 Bergheim
Germany
Telephone: +49 322 21802200
Email: ai@sopheraconsulting.de
VAT ID: DE357873793
1.1 Data protection officer
As a sole proprietorship, Sophera Consulting has currently not appointed a data protection officer (DPO), because the statutory conditions for a mandatory appointment are not met:
- At least 20 persons are not permanently engaged in the automated processing of personal data (§ 38(1) BDSG, German Federal Data Protection Act).
- The core activity does not consist of the regular and systematic monitoring of data subjects on a large scale (Art. 37(1)(b) GDPR).
- The core activity does not consist of the large-scale processing of special categories of personal data (Art. 37(1)(c) GDPR, Art. 9 GDPR).
- No commercial processing for the purpose of transfer or market/opinion research takes place (§ 38(1) sentence 2 BDSG).
Data Protection Impact Assessment: For processing operations involving an elevated risk, namely session recording by Microsoft Clarity (section 6.2), the AI-supported initial assessment in the Automation Check (section 7) and the consolidation of prospect data (section 8.14), we have carried out and documented a Data Protection Impact Assessment (DPIA) in accordance with Art. 35 GDPR. It is reviewed annually as well as upon any material change to the processing. We will submit it to the competent supervisory authority on request. The outcome: the processing operations are permissible, the residual risk is low, and prior consultation of the supervisory authority under Art. 36 GDPR is not required.
Contact for data protection enquiries: For questions about data protection, the exercise of your data subject rights (Art. 15–22 GDPR) or the withdrawal of consent you have given, please contact directly:
Max Fey (owner and controller)
Email: ai@sopheraconsulting.de
Should the circumstances of our company change (e.g. the hiring of additional staff or the commencement of high-risk processing activities), we will appoint a data protection officer without undue delay and disclose this transparently at this point.
2. Scope
This Privacy Policy applies to the online offering of Sophera Consulting under the domains sopheraconsulting.de and sopheraconsulting.com as well as to all associated subpages (hereinafter the “Website”). Sophera Consulting provides consulting and implementation services in the areas of AI workflow automation, process optimisation, digitalisation consulting, AI training as well as support & maintenance. The following information explains which personal data we collect within the scope of this offering, on what legal basis this takes place and for what purpose the processing is carried out.
3. General information and mandatory disclosures
3.1 SSL and TLS encryption
For security reasons and to protect the transmission of confidential content, this Website uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address bar of your browser changes from “http://” to “https://” and a padlock symbol appears in your browser bar. When SSL or TLS encryption is active, the data you transmit to us cannot be read by third parties.
3.2 Retention period for personal data
Unless a more specific retention period is stated within this Privacy Policy, your personal data will remain with us until the purpose of the data processing ceases to apply. If you assert a justified request for erasure or withdraw your consent to data processing, your data will be deleted unless we have other legally permissible grounds for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, erasure will take place once those grounds cease to apply.
Overview of retention periods by data type:
- Server log files: 14 days, followed by automatic erasure (Art. 6(1)(f) GDPR)
- IP addresses used for rate limiting: max. 120 seconds in memory, no persistent storage
- Contact form enquiries: until the enquiry has been dealt with, max. 3 years (limitation period under § 195 BGB, German Civil Code)
- Appointment bookings and meetings: 12 months after the appointment, provided no business relationship has been established
- Automation Check (AI configurator): 24 months (cf. section 7.3)
- Customer data (Supabase, Pipedrive): for the duration of the business relationship plus statutory retention periods
- Invoicing and accounting data (Lexoffice, Stripe): 10 years pursuant to § 147 AO (German Fiscal Code), § 257 HGB (German Commercial Code)
- Business letters and email correspondence: 6 years pursuant to § 257 HGB
- Cookie consent (consent record): 12 months, after which consent is requested again
- Microsoft Clarity (cookies, session recordings): max. 12 months
- Portal user data after deactivation: 90 days grace period, followed by technical erasure, provided no statutory retention obligations conflict
- Confirmation link for the Automation Check: 24 hours for the confirmation, result link 30 days from confirmation
3.3 Legal bases for data processing
Where we obtain the consent of the data subject for processing operations involving personal data, Art. 6(1)(a) GDPR serves as the legal basis.
Where the processing of personal data is necessary for the performance of a contract to which the data subject is party, or in order to take steps prior to entering into a contract, the processing is based on Art. 6(1)(b) GDPR.
Where processing of personal data is necessary for compliance with a legal obligation to which our company is subject, Art. 6(1)(c) GDPR serves as the legal basis.
Where processing is necessary to safeguard a legitimate interest of our company or of a third party, and where the interests, fundamental rights and freedoms of the data subject do not override that first-mentioned interest, Art. 6(1)(f) GDPR serves as the legal basis for the processing.
4. Rights of the data subject
As a data subject, you have the following rights under the GDPR:
4.1 Right of access (Art. 15 GDPR)
You have the right to request confirmation as to whether we process personal data concerning you. If this is the case, you are entitled to access that data as well as to the information listed in detail in Art. 15(1) GDPR.
4.2 Right to rectification (Art. 16 GDPR)
You have the right to obtain the rectification of inaccurate personal data without undue delay. Taking into account the purposes of the processing, you also have the right to request that incomplete personal data be completed.
4.3 Right to erasure (Art. 17 GDPR)
You have the right to request that personal data concerning you be erased without undue delay, provided one of the grounds set out in Art. 17(1) GDPR applies and the processing is not necessary under Art. 17(3) GDPR.
4.4 Right to restriction of processing (Art. 18 GDPR)
You have the right to request the restriction of the processing of your personal data where one of the conditions set out in Art. 18(1) GDPR applies, in particular where you contest the accuracy of the data, the processing is unlawful, we no longer need the data or you have objected to the processing.
4.5 Right to data portability (Art. 20 GDPR)
You have the right to receive the personal data concerning you which you have provided to us in a structured, commonly used and machine-readable format. You also have the right to transmit that data to another controller, provided the processing is based on consent or on a contract and is carried out by automated means.
4.6 Right to object (Art. 21 GDPR)
Where we process your personal data on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right under Art. 21 GDPR to object to the processing at any time. This requires grounds relating to your particular situation. This also applies to profiling based on that provision.
Where we process your personal data for the purposes of direct marketing, you have the right to object at any time and without giving reasons. This also applies to profiling to the extent that it is related to direct marketing.
4.7 Right to withdraw consent given (Art. 7(3) GDPR)
You have the right to withdraw consent to data processing once given at any time with effect for the future. The withdrawal does not affect the lawfulness of the processing carried out on the basis of the consent up to the point of withdrawal.
4.8 Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement.
The supervisory authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestr. 2–4
40213 Düsseldorf
Telephone: +49 211 38424-0
Email: poststelle@ldi.nrw.de
4.9 Automated decision-making and profiling (Art. 22 GDPR)
An automated individual decision producing legal effects concerning you or similarly significantly affecting you (Art. 22(1) GDPR) does not take place. So that you can nevertheless fully understand our processing, we disclose the automated procedures we use:
a) Initial assessment in the Automation Check. Your process description is evaluated by an AI system (Anthropic Claude, see section 7.2). The system estimates an automation potential as a percentage and a possible monthly saving in euros. These figures are a non-binding orientation, not a commitment and not a decision about a contractual relationship.
b) Pre-sorting in the CRM. After you submit the Automation Check, we automatically create a record in our CRM system. The saving estimated by the AI system is adopted as the provisional value of the case and the record is assigned to an internal processing stage. This serves solely the internal prioritisation of our follow-up. Whether an offer is made, and on what terms, is in every case decided by a human.
c) Reach measurement. Microsoft Clarity (section 6.2) evaluates usage behaviour in aggregated form. This data is not combined with your contact details to form a personality profile.
You may at any time request information about the assessment stored about you at ai@sopheraconsulting.de, request its rectification or erasure and object to the pre-sorting described above.
5. Hosting
5.1 Vercel
Our Website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA (“Vercel”). Vercel is a platform-as-a-service solution for hosting web applications.
When you visit our Website, the host automatically collects technical access data (known as server log files). These include in particular:
- IP address of the requesting device
- date and time of the request
- URL accessed and referrer URL
- browser type and version as well as operating system
- volume of data transferred
The collection of this data is technically necessary in order to display our Website to you and to ensure stability and security.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure and efficient web presence).
Transfer of data to the USA: Vercel is certified under the EU-US Data Privacy Framework. The transfer of personal data to the USA takes place on the basis of the adequacy decision of the European Commission pursuant to Art. 45 GDPR. Further information on data protection at Vercel can be found at: https://vercel.com/legal/privacy-policy
Data processing: We have concluded a data processing agreement (DPA) with Vercel that meets the requirements of Art. 28 GDPR.
6. Data collection on this Website
6.1 Technically necessary cookies
Our Website uses technically necessary cookies that are required to ensure the basic functions of the Website – in particular the language selection (German/English) via the internationalisation function (next-intl) and the storage of your cookie consent.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the technically error-free provision and optimisation of the Website. For technically necessary cookies, consent under § 25(2) TDDDG (German Digital Services Data Protection Act) is not required.
6.2 Analytics cookies (Microsoft Clarity)
Provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.
Purpose: We use Microsoft Clarity to analyse usage behaviour on our Website. Clarity creates heatmaps and session recordings (session replay) that help us to improve usability.
Note on profiling (Art. 4(4) GDPR): The session replays recorded by Clarity (mouse movements, click behaviour, scroll depth) may be classified as profiling in the data protection sense, as they enable a systematic evaluation of user behaviour. An automated individual decision with legal effect for you within the meaning of Art. 22 GDPR does, however, not take place (see section 4.9). In the standard configuration we use, Clarity masks entries in form fields so that your input is not recorded in plain text. You can object to this processing at any time via the cookie banner; you will find the link to it in the page footer.
Data processed: click behaviour, scroll depth, mouse movements, page views, device and browser information, IP address (anonymised).
Data sharing: Microsoft Clarity may link the collected data with other Microsoft services (including Microsoft Advertising/Bing) and pass it on to third parties in order to provide aggregated analytics and advertising services. Details can be found in the Microsoft privacy statement.
Retention period: The cookies set by Clarity have a storage period of up to 1 year.
Legal basis: Art. 6(1)(a) GDPR (consent) as well as § 25(1) TDDDG. Clarity is only activated after your express consent via the cookie banner. You can withdraw your consent at any time.
Note: Microsoft Clarity is not a technically necessary cookie. The service serves exclusively to analyse user behaviour and is not required for the operation of the Website. It is activated exclusively with your active consent; a legitimate interest under Art. 6(1)(f) GDPR expressly does not exist.
Microsoft is certified under the EU-US Data Privacy Framework.
6.2a Google Tag Manager
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).
Purpose: We use Google Tag Manager (GTM-MVSDH957) to manage marketing and analytics tags on our Website. The Tag Manager itself does not store cookies and does not collect personal data. It serves as a management tool that triggers other tags (e.g. Google Analytics, conversion tracking).
Legal basis: Art. 6(1)(a) GDPR (consent). Google Tag Manager is only activated after your express consent via the cookie banner (category “Marketing”). Without your consent, no tags are loaded.
Data sharing: Google is certified under the EU-US Data Privacy Framework. Further information on data protection at Google can be found at https://policies.google.com/privacy.
6.3 Note on data sharing by third-party providers
The analytics and marketing services used on this Website (Microsoft Clarity, Google Ads, Meta, LinkedIn, TikTok) may share the collected data with their respective partner networks and process it for their own purposes. This includes in particular:
- Microsoft: sharing with Microsoft Advertising, Bing and affiliated services
- Google: sharing with Google Ads, the Google Analytics network and affiliated services
- Meta: sharing with the Meta advertising network (Facebook, Instagram)
- LinkedIn: sharing with the LinkedIn Marketing Solutions network
These transfers take place exclusively on the basis of your prior consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR).
Some of the providers named are subsidiaries of US corporations. In the course of data processing, data may be passed on to the respective parent companies in the USA:
- Meta Platforms Ireland Limited → Meta Platforms, Inc. (USA)
- LinkedIn Ireland Unlimited Company → LinkedIn Corporation (USA)
- Google Ireland Limited → Google LLC (USA)
- Microsoft Ireland Operations Limited → Microsoft Corporation (USA)
These transfers take place on the basis of the EU-US Data Privacy Framework (DPF) pursuant to Art. 45 GDPR. All the US parent companies named are certified under the DPF. Details on third country transfers can be found in section 11.
6.4 AI crawlers and LLM access
At /llms.txt we provide a machine-readable file that makes structured information about our Website and services available to AI systems (e.g. ChatGPT, Perplexity, Claude, Google AI Overviews). This file contains exclusively publicly available company information and no personal data.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in visibility in AI-supported search systems).
6.5 Server log files
The hosting provider automatically collects and stores information in what are known as server log files, which your browser transmits automatically when you visit the Website (cf. section 5.1). We do not merge this data with other data sources.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security and error-free operation of the Website).
6.6 Contact form
If you send us an enquiry via the contact form provided on the Website, the following personal data is collected:
- Name
- Email address
- Company (optional)
- Content of your message
Purpose: The collection serves to process and answer your enquiry, including any follow-up questions.
Legal basis: Where your enquiry serves to take steps prior to entering into a contract, Art. 6(1)(b) GDPR is the legal basis. Otherwise, we process your data on the basis of our legitimate interest in the effective handling of enquiries addressed to us pursuant to Art. 6(1)(f) GDPR.
Retention period: The data collected in the contact form will be deleted as soon as your enquiry has been conclusively dealt with and no statutory retention obligations conflict.
Protective measures: To protect against automated spam enquiries we use a server-side honeypot technique as well as IP-based rate limiting. The IP address is held in memory exclusively for the duration of the rate limiting (max. 60 seconds) and is discarded afterwards.
6.7 Enquiry by email or telephone
If you contact us by email or telephone, your enquiry together with all personal data arising from it (name, enquiry, telephone number, email address) will be stored and processed by us for the purpose of handling your request. This data will not be passed on to third parties without your express consent.
Legal basis: Art. 6(1)(b) GDPR (initiation and performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in the efficient handling of enquiries).
Retention period: The data will be deleted as soon as the enquiry has been conclusively dealt with and no statutory retention obligations conflict.
7. Automation Check (AI configurator)
On our Website we provide an interactive AI-supported configurator (“Automation Check”) with which you can obtain a non-binding initial assessment of the automation potential of your business processes.
7.1 Data collected
When you use the Automation Check, the following data is collected:
- Name (optional)
- Email address (mandatory)
- Telephone number (mandatory)
- Description of the business process to be automated (free text)
- Preferred solution type (SaaS, custom development or open source)
- Systems currently in use (optional)
- Estimated monthly cost of the process (optional)
7.2 Processing by Anthropic (Claude API)
The process description you enter is transmitted to the API of the provider Anthropic PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA (“Anthropic”) in order to produce the automation analysis. Anthropic processes the data exclusively to generate the analysis and, in accordance with the terms of use of the API, does not store the transmitted input for its own training purposes.
Data transmitted: process description, solution type, where applicable current systems and monthly costs. Your email address, telephone number and your name are not transmitted to Anthropic.
Transfer of data to the USA: Anthropic is certified under the EU-US Data Privacy Framework. The data transfer takes place on the basis of the adequacy decision of the European Commission pursuant to Art. 45 GDPR.
Further information on data protection at Anthropic can be found at: https://www.anthropic.com/privacy
7.3 Delivery of the analysis by email
The result of the AI-supported analysis is sent to you by email to the email address you have provided. We use an SMTP service to send the email. The email contains the data you entered as well as the generated initial assessment.
Legal basis: Art. 6(1)(a) GDPR (consent). By actively entering your data and submitting the form, you consent to the processing described. You can withdraw this consent at any time with effect for the future.
Storage and disclosure: The data collected in the course of the Automation Check is stored in our database (Supabase, Frankfurt region — see section 11a) in order to process your enquiry and deliver the analysis. In addition, we create a record of your contact details and your process description in our CRM system Pipedrive (see section 8.13) and of your contact details in our accounting software Lexoffice (see section 8.12) in order to document a possible business relationship being initiated.
Retention period: We store this data for the duration of the initiation of business. If no business relationship arises within 24 months, we delete it. Statutory retention obligations (§ 147 AO, § 257 HGB) remain unaffected. You can request erasure at any time at ai@sopheraconsulting.de. The IP-based rate limiting (max. 120 seconds) serves exclusively to protect against misuse.
7.4 Note on the content of the analysis
The initial assessment generated by the AI system constitutes an automated, non-binding orientation aid and does not replace individual advice. No legal claims can be derived from the analysis.
7.5 Funding consultancy (partner service)
Description of the service: Within the framework of the partner service “funding consultancy”, Sophera Consulting refers clients to external, certified funding consultants (hereinafter “funding partners”). In this respect, Sophera Consulting is not the provider of the funding consultancy but an intermediary.
Data processed: In the course of the referral, the following personal data is transmitted to the funding partner:
- First and last name
- Email address
- Telephone number
- Details of the planned digitalisation project (insofar as communicated in the initial consultation)
- Company data (industry, size, location — insofar as relevant for the funding assessment)
Legal basis: Art. 6(1)(a) GDPR (consent). The transfer of your data to the funding partner takes place exclusively after your express consent, which you give in the course of booking an appointment. You can withdraw your consent at any time with effect for the future.
Recipients: The funding partners are independent controllers within the meaning of Art. 4(7) GDPR. Sophera Consulting has concluded joint controllership arrangements pursuant to Art. 26 GDPR or data processing agreements pursuant to Art. 28 GDPR with the partners, insofar as required.
Retention period: The referral data is stored by Sophera Consulting for the duration of the business relationship. After completion or discontinuation of the funding process and expiry of statutory retention periods, the data is deleted.
Right to object: You can object to the transfer of data to the funding partner at any time (ai@sopheraconsulting.de). In that case, the funding consultancy cannot be continued.
7.6 Customer portal, onboarding and digital offers
Purpose: Sophera Consulting offers its customers an access-restricted customer portal, digital acceptance of offers as well as automated onboarding after a contract is concluded. These functions facilitate project delivery and provide a transparent overview of ongoing projects, milestones and payments.
Data processed:
- Contact data (name, email, telephone, company, address)
- Project data (project name, description, milestones, payment status)
- Onboarding questionnaires (company data, current systems, project goals, schedule)
- Offer data (services, amounts, date of acceptance)
- Generated PDF documents (invoices, offers)
Access control: Access takes place via cryptographically secure tokens (UUID v4) that are sent by email to the respective customer. The tokens are assigned exclusively to the respective customer and do not allow access to the data of other customers.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract).
Retention period: Project data is stored for the duration of the business relationship as well as the statutory retention periods (10 years pursuant to § 147 AO, § 257 HGB). Onboarding data is deleted after project completion, provided no further legal obligations exist.
8. Use of third-party services
In the course of our business activities we use various third-party services in order to provide our services efficiently and professionally. Below we inform you about the services used, the respective purposes of the processing and the relevant legal bases.
8.1 Google Workspace (Gmail, Google Drive, Google Calendar, Google Meet)
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: We use Google Workspace for business email communication (Gmail), the storage and exchange of documents (Google Drive), scheduling (Google Calendar) as well as for holding video conferences (Google Meet).
Data processed: name, email address, communication content, appointment details, shared documents, IP address, device and browser information.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in efficient business communication).
Google is certified under the EU-US Data Privacy Framework (DPF). We have concluded a data processing agreement (Data Processing Amendment) with Google pursuant to Art. 28 GDPR.
8.1a AI-supported meeting notes (Gemini in Google Meet)
Purpose: In video conferences via Google Meet, the “AI-supported meeting notes” function (Google Gemini) can be activated on request and with the express consent of all participants. It automatically creates a written transcript and a summary of the conversation.
Data processed: audio content of the conversation, transcripts and summaries generated from it, participant names, timestamps, spoken content of all those involved.
Legal basis: Art. 6(1)(a) GDPR (consent). The function is only activated if all participants expressly agree to the recording and processing. In addition, § 201 StGB (German Criminal Code, confidentiality of the spoken word) applies: recording takes place exclusively with the consent of all those involved.
Information provided before every recording:
- Before the start of every meeting, all participants are actively informed about the planned recording
- Consent is obtained orally or in writing and documented
- Participants can withdraw their consent at any time, in which case the recording is stopped
- Notes and transcripts are used exclusively for documentation purposes within the scope of the respective consultancy
- They are not passed on to third parties without renewed consent
Retention period: Transcripts and notes are stored for the duration of the business relationship as well as the statutory retention periods and are then deleted automatically. On request, recordings can be deleted at any time.
Note on the EU AI Act: Since 2 August 2026, the transparency obligations of Art. 50 of Regulation (EU) 2024/1689 have applied. We label AI transcripts and summaries accordingly as AI-generated. An overview of where we use AI and how we make this apparent can be found in section 14.
Data processing by Google: Google processes the audio data in accordance with the Google Workspace privacy terms. Under the data processing agreement (DPA, see 8.1), the data is used exclusively to provide the agreed service and not to train the AI models.
Activation and opt-out: The AI-supported meeting notes are NOT activated automatically for every meeting. Before each meeting, all participants are actively asked and must expressly agree. Any participant can have the recording stopped at any time during the meeting. Refusing consent does not lead to the meeting being cancelled.
Storage location: Transcripts and summaries are stored in Google Drive within the Sophera Consulting Workspace (EU servers) and are accessible exclusively to authorised staff.
Retention period: Transcripts are deleted after completion of the respective consultancy or the respective project. At the request of a participant, transcripts are deleted without undue delay.
8.2 Google AI (Gemini, Vertex AI)
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: AI-supported analysis and automation within the scope of customer projects. The services are used to optimise processes, generate texts and analyse data.
Data processed: process descriptions, business data of the customer (only with the customer’s prior consent), where applicable anonymised or pseudonymised data sets.
Legal basis: Art. 6(1)(a) GDPR (consent) as well as Art. 6(1)(b) GDPR (performance of a contract).
Important note: When certain Google AI services are used, data entered may be used to train AI models unless this has been excluded via the API configuration with data governance settings. For customer-related projects we primarily use the API variant with model training deactivated.
8.3 Anthropic (Claude API)
Provider: Anthropic PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA.
Purpose: In addition to the use described in section 7.2 within the scope of the Automation Check, we also use the Claude API for further customer projects, in particular for AI-supported text generation, analysis and process automation.
Data processed: process descriptions, business data of the customer (only within the scope of the respective project assignment).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in the efficient provision of services).
No training: When the API is used, no input data is used to train AI models in accordance with the Anthropic API Terms of Service. Anthropic is certified under the EU-US Data Privacy Framework.
Data processing: We have concluded a data processing agreement (DPA) with Anthropic pursuant to Art. 28 GDPR (Anthropic Data Processing Addendum, as of 2026). Further information on data protection at Anthropic can be found at: https://www.anthropic.com/privacy
8.4 OpenAI (ChatGPT, GPT API)
Provider: OpenAI OpCo, LLC, 3180 18th Street, San Francisco, CA 94110, USA.
Purpose: AI-supported text generation, analysis, code generation and process automation within the scope of customer projects.
Data processed: process descriptions, text input, business data of the customer (only within the scope of the respective project assignment).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in the efficient provision of services).
No training when using the API: In accordance with the OpenAI API Terms of Use, no input data is used to train AI models when the API is used. OpenAI is certified under the EU-US Data Privacy Framework.
8.5 Clay
Provider: Clay Inc., USA.
Purpose: Data enrichment and lead research in the B2B sector. Clay is used to research and enrich publicly available business contact data.
Data processed: business contact data such as name, position, company, business email address.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in customer acquisition in the B2B sector). The legitimate interest arises from the necessity of identifying and approaching potential business customers.
Notice pursuant to Art. 14 GDPR: Insofar as we collect personal data not directly from the data subject but from publicly accessible sources or via Clay, we inform the data subject about the data processing pursuant to Art. 14 GDPR upon first contact.
8.6 Dieserver AI / n8n
Purpose: Workflow automation and process orchestration. n8n is used to connect various services and systems with one another and to implement automated processes.
Operation: Depending on the project requirements, n8n is operated self-hosted or as a cloud variant.
Data processed: The type of data processed depends on the specific workflow and may include customer data (name, email address, business data).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract within the scope of customer projects).
8.7 Microsoft Outlook and Microsoft Teams
Provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.
Purpose: Email communication (Microsoft Outlook), video conferencing, chat and collaboration (Microsoft Teams).
Data processed: name, email address, communication content, appointment details, IP address, device and browser information.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in efficient business communication).
Microsoft is certified under the EU-US Data Privacy Framework. We have concluded a data processing agreement with Microsoft pursuant to Art. 28 GDPR (Microsoft Products and Services Data Protection Addendum).
8.8 Zoom
Provider: Zoom Video Communications, Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA.
Purpose: Holding video conferences and online meetings with customers and business partners.
Data processed: name, email address, IP address, device and browser information, where applicable audio/video data during the conference.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract).
Zoom is certified under the EU-US Data Privacy Framework. Further information on data protection at Zoom can be found at: https://explore.zoom.us/de/privacy/
8.9 Own CRM system for customer acquisition
Operator: Sophera Consulting (self-hosted).
Purpose: Management of customer enquiries, leads, project data and communication histories in order to maintain existing and potential business relationships.
Data processed: name, email address, telephone number, company, communication history, project details.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract and steps taken prior to entering into a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in efficient customer management).
Retention period: The data is stored until the expiry of statutory retention periods (in particular § 147 AO, § 257 HGB) or until withdrawal by the data subject.
8.10 Email and SMS communication
Email: For business email communication we use Google Workspace (Gmail) and Microsoft Outlook (cf. sections 8.1 and 8.7).
SMS: For appointment confirmations and urgent business messages, SMS may be sent via a third-party gateway.
Purpose: Business communication, appointment confirmations, project-related correspondence.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract).
8.11 Payment processing (Stripe)
Provider: Stripe Technology Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland.
Purpose: We use Stripe for the secure processing of online payments. If you make a payment via our Website, your payment data is processed directly by Stripe.
Data processed: payment data (credit card number, IBAN), name, email address, IP address, transaction amount and details.
Data sharing: Your payment data is transmitted directly to Stripe and processed by Stripe in accordance with their privacy policy. Sophera Consulting does not store complete credit card or account details.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract). The processing is necessary in order to carry out the payment.
Retention period: Transaction data is stored for the duration of the statutory retention periods (10 years pursuant to HGB/AO).
Stripe is certified under the EU-US Data Privacy Framework. Details: stripe.com/de/privacy
8.12 Accounting (Lexoffice / Lexware)
Provider: Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg, Germany (address as of 2026).
Purpose: We use Lexoffice for accounting, invoicing and customer management. If you place an order or make a payment, your data is automatically created in Lexoffice as a contact and, where applicable, as an invoice.
Data processed: first and last name, email address, telephone number, customer number (assigned automatically), invoice amounts, project designation, payment status, invoice date.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) as well as Art. 6(1)(c) GDPR (compliance with statutory accounting obligations pursuant to HGB/AO).
Retention period: Invoice data is stored for the duration of the statutory retention periods (10 years pursuant to § 147 AO, § 257 HGB).
Lexware is a German company based in Freiburg. Data processing takes place exclusively in Germany or the EU.
8.13 Customer relationship management / CRM (Pipedrive)
Provider: Pipedrive OÜ, Mustamäe tee 3a, 10615 Tallinn, Estonia (EU company, address as of 2026).
Purpose: We use Pipedrive as a CRM system to manage customer relationships and sales processes. If you get in touch with us — e.g. via the Automation Check, an appointment booking or a payment — your data is automatically recorded in Pipedrive as a contact and, where applicable, as a deal.
Data processed: first and last name, email address, telephone number, type of enquiry (booking, Automation Check, payment), project designation, where applicable automation potential and estimated saving, deal status and value.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract and steps taken prior to entering into a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in efficient customer relationship management).
Retention period: Contact and deal data is stored for the duration of the business relationship and deleted after it ends in accordance with the statutory retention periods.
Pipedrive is an EU company based in Estonia. The data is processed on servers within the EU. Pipedrive is certified to SOC 2 Type II.
8.14 Data linkage between systems
In order to handle our business processes efficiently, the systems named above are linked with one another. Below we provide transparent information about the data flow:
- Website → Supabase: Your contact and booking data is stored in our database (Supabase, EU servers).
- Supabase → Lexoffice: When an order is placed or a payment is made, contact data and invoicing information is transmitted automatically to Lexoffice in order to create invoices and comply with accounting obligations.
- Supabase → Pipedrive: Contact data and project information is recorded automatically in Pipedrive as a customer relationship in order to ensure efficient support.
- Stripe → Supabase / Lexoffice: Payment confirmations are transmitted by Stripe to our systems in order to finalise invoices and update the payment status.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(c) GDPR (statutory accounting obligations) as well as Art. 6(1)(f) GDPR (legitimate interest in efficient business processes).
Synchronisation frequency: Data synchronisation between the systems takes place in real time (event-based via webhooks). When a record is created or changed in one system, the information is automatically passed on to the linked systems.
Bidirectionality: The data flows are partly bidirectional:
- Pipedrive ↔ Supabase: lead data and deal status are synchronised in both directions
- Stripe → Supabase: payment status is transmitted one-way from Stripe to Supabase (webhook)
- Lexoffice ↔ Supabase: customer numbers and invoice IDs are synchronised
Erasure: If a record is erased at the request of the data subject, the erasure is carried out in all linked systems. The request can be addressed to ai@sopheraconsulting.de.
All data transfers are encrypted (TLS/HTTPS). We have concluded data processing agreements (DPAs) pursuant to Art. 28 GDPR with all service providers, insofar as required. All services used process data within the EU or are certified under the EU-US Data Privacy Framework.
8.15 Telephony (Placetel)
Provider: Placetel GmbH, Brüsseler Straße 1, 50674 Köln, Germany (a company of NFON AG).
Purpose: Cloud telephone system for business voice communication (incoming and outgoing calls, voicemail, call distribution).
Data processed: telephone numbers (our own and those of the calling person), time of the call, call duration, connection data, where applicable voicemail recordings.
Server location: Germany. No transfer of data to third countries.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract and steps taken prior to entering into a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in efficient business communication).
Retention period: Connection data for a maximum of 7 days (§ 9 TDDDG), unless required for longer for billing purposes. We create call recordings only with the express prior consent of all participants (§ 201 StGB) and delete them without undue delay on request.
Data processing: A data processing agreement pursuant to Art. 28 GDPR has been concluded with Placetel. Further information: placetel.de/datenschutz
8.16 Cloud infrastructure for customer projects (GCP, AWS)
For the delivery of customer projects we use cloud infrastructure from the following providers, depending on the requirements. These services do not concern the operation of this Website but the services provided for customers.
Google Cloud Platform (GCP) — Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, with data processing by Google LLC, USA. Depending on the project, Cloud Storage, Compute Engine, Cloud Run, Cloud SQL, BigQuery as well as Vertex AI (cf. section 8.2) are used.
Amazon Web Services (AWS) — Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg, with data processing by Amazon Web Services Inc., USA. Depending on the project, S3, EC2, Lambda, RDS, CloudFront as well as Amazon Bedrock are used.
Region: We preferably select EU regions (GCP: europe-west3 Frankfurt, europe-west1 Belgium; AWS: eu-central-1 Frankfurt, eu-west-1 Ireland). Should a technical requirement exceptionally not permit an EU region, we will inform the customers concerned separately before it is used.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract within the scope of customer projects) as well as Art. 6(1)(f) GDPR (legitimate interest in operating scalable infrastructure).
Data processing: Data processing agreements pursuant to Art. 28 GDPR exist with both providers (Google Cloud Data Processing Addendum, AWS Data Processing Addendum). Both are certified under the EU-US Data Privacy Framework (cf. section 11).
9. Online marketing and advertising
Sophera Consulting uses various online marketing tools in order to increase the visibility of its own services and to approach potential customers. Below we provide information about the services used.
9.1 Google Search Console
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: Analysis of the visibility of our Website in Google Search and technical SEO optimisation.
Data processed: search queries (exclusively aggregated), click data, impressions. No personal data of Website visitors is transmitted to us. The data is fully anonymised and serves exclusively technical optimisation.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in optimising our web presence).
9.2 Google Ads
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: Placement of paid search ads and conversion tracking to measure advertising effectiveness.
Data processed: IP address (truncated), cookie ID, conversion data (e.g. whether an enquiry was made via an ad).
Consent: The use of Google Ads conversion tracking requires your prior consent pursuant to § 25(1) TDDDG. Conversion tracking is only activated after your express consent via the cookie banner.
Legal basis: Art. 6(1)(a) GDPR (consent).
Opt-out: You can deactivate personalised advertising in the Google Ads settings: https://adssettings.google.com
9.3 Meta Ads (Facebook, Instagram) and Meta apps
Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
Purpose: Placement of advertisements on Facebook, Instagram, Messenger and WhatsApp. Where applicable, use of Custom Audiences to address relevant target groups.
Data processed: usage data, interaction data, where applicable data from Custom Audience lists.
Consent: The use of Meta tracking technologies (e.g. Meta Pixel) requires your prior consent. Tracking is only activated after consent has been given via the cookie banner.
Legal basis: Art. 6(1)(a) GDPR (consent).
Joint controllership: Insofar as we operate a Facebook company page (fan page), joint controllership pursuant to Art. 26 GDPR exists between us and Meta Platforms Ireland Limited. For this purpose Meta provides what are known as Page Insights addenda, in which the respective responsibilities are set out. This is based on the case law of the CJEU (judgment of 05.06.2018 – C-210/16).
Further information on data protection at Meta can be found at: https://www.facebook.com/privacy/policy
9.4 LinkedIn and LinkedIn Ads
Provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.
Purpose: B2B marketing, placement of advertisements and lead generation on the LinkedIn platform.
Data processed: profile visits, interaction data, where applicable data from lead gen forms (name, email address, position, company).
Consent: The use of LinkedIn tracking technologies (e.g. LinkedIn Insight Tag) requires your prior consent. Tracking is only activated after consent has been given via the cookie banner.
Legal basis: Art. 6(1)(a) GDPR (consent).
Joint controllership: For our LinkedIn company page, joint controllership pursuant to Art. 26 GDPR exists between us and LinkedIn Ireland Unlimited Company.
9.5 TikTok
Provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland.
Purpose: Advertising and increasing brand awareness.
Data processed: usage data, interaction data, where applicable pixel data.
Consent: The use of TikTok tracking technologies requires your prior express consent.
Legal basis: Art. 6(1)(a) GDPR (consent).
Special note: TikTok is subject to particular scrutiny by European data protection authorities. It cannot be ruled out that data is transmitted to servers in the People’s Republic of China, where there is no level of data protection comparable to that of the EU. We therefore use TikTok only with the express consent of the data subjects and limit the data processing to the necessary minimum.
9.6 General note on advertising tracking
All marketing cookies and tracking pixels (e.g. Google Ads conversion tracking, Meta Pixel, LinkedIn Insight Tag, TikTok Pixel) are activated on this Website only after your express consent via the cookie banner. Without your consent, no advertising tracking takes place.
You can adjust your cookie settings or withdraw your consent at any time via the cookie banner. In addition, the following opt-out options are available to you:
- Google: https://adssettings.google.com
- Meta: https://www.facebook.com/settings?tab=ads
- LinkedIn: https://www.linkedin.com/psettings/advertising
- General: https://youronlinechoices.eu
9.7 IndexNow (Bing/Google indexing)
Provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA (for Bing).
Purpose: IndexNow is an open protocol with which we automatically inform search engines about new or updated content on our Website. This accelerates indexing at Bing, Yandex, DuckDuckGo and other IndexNow-capable search engines.
Data processed: exclusively URLs of our public Website content. No personal data is transmitted.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in efficient indexing of our content in search engines).
10. Disclosure of data to third parties
Your personal data is disclosed to third parties exclusively in the following cases:
- Vercel Inc. (hosting, cf. section 5.1) – data processing pursuant to Art. 28 GDPR
- Anthropic PBC (AI analysis, cf. sections 7.2 and 8.3) – exclusively process descriptions within the scope of the Automation Check; for customer projects only within the scope of the project assignment
- OpenAI OpCo, LLC (AI services, cf. section 8.4) – processing within the scope of customer projects
- Google Ireland Limited (Google Workspace, Google AI, Google Ads, Google Search Console, cf. sections 8.1, 8.2, 9.1 and 9.2)
- Microsoft Ireland Operations Limited (Outlook, Teams, cf. section 8.7)
- Zoom Video Communications, Inc. (video conferencing, cf. section 8.8)
- Clay Inc. (lead research, cf. section 8.5)
- Meta Platforms Ireland Limited (advertisements, cf. section 9.3)
- LinkedIn Ireland Unlimited Company (advertisements, cf. section 9.4)
- TikTok Technology Limited (advertising, cf. section 9.5)
- SMTP service provider (email delivery)
- Supabase Inc. (database, server location: Frankfurt/Germany) — data processing pursuant to Art. 28 GDPR
- Vercel Speed Insights (anonymised performance measurement, no personal data)
Beyond this, no data is disclosed to third parties unless we are legally obliged to do so (e.g. disclosure to law enforcement authorities under § 24 BDSG) or you have expressly consented.
11. Transfer of data to third countries
Within the scope of the processing operations described in this Privacy Policy, personal data is transferred to companies in the United States of America. This concerns in particular the following service providers:
- Vercel Inc. (hosting) – DPF-certified
- Anthropic PBC (AI services) – DPF-certified
- OpenAI OpCo, LLC (AI services) – DPF-certified
- Google Ireland Limited (Google group, data transfer to Google LLC, USA) – DPF-certified
- Microsoft Ireland Operations Limited (data transfer to Microsoft Corp., USA) – DPF-certified
- Zoom Video Communications, Inc. (video conferencing) – DPF-certified
- Clay Inc. (lead research) – safeguarded by EU standard contractual clauses pursuant to Art. 46(2)(c) GDPR
- Meta Platforms, Inc. (parent company, USA) – DPF-certified
- LinkedIn Corporation (parent company, USA) – DPF-certified
- Amazon Web Services EMEA SARL, Luxembourg (cloud infrastructure for customer projects, cf. section 8.16 — data transfer to Amazon Web Services Inc., USA) – DPF-certified, additionally safeguarded by EU standard contractual clauses pursuant to Art. 46(2)(c) GDPR
On 10 July 2023, the European Commission adopted the adequacy decision for the EU-US Data Privacy Framework (DPF) pursuant to Art. 45 GDPR. On this basis, an adequate level of data protection is ensured for data transfers to the DPF-certified companies.
Special case TikTok: In the case of TikTok, it cannot be ruled out that data is transferred to the People’s Republic of China. There is currently no adequacy decision of the European Commission for China. The data transfer therefore takes place exclusively on the basis of your express consent pursuant to Art. 49(1)(a) GDPR.
Should the adequacy decision for the DPF cease to be valid, we will without undue delay ensure appropriate safeguards pursuant to Art. 46 GDPR (in particular EU standard contractual clauses) or discontinue the data transfer.
11a. Data storage (Supabase)
For the storage of contact data, appointment bookings and configurator enquiries we use the database service Supabase (Supabase Inc., USA). The database is operated in the Frankfurt, Germany (eu-central-1) region; the stored data is therefore located within the EU. Access by Supabase Inc. from the USA (for example in the course of support or maintenance) cannot be completely ruled out; the safeguards described in section 11 apply in this respect.
Data stored: name, email address, telephone number, company (optional), appointment booking data, process descriptions and analysis results from the Automation Check.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract) and Art. 6(1)(f) GDPR (legitimate interest in the efficient management of customer enquiries).
Retention period: Contact data is stored for as long as a business relationship exists or statutory retention periods apply. You can request the erasure of your data at any time.
Data processing: We have concluded a data processing agreement (DPA) with Supabase pursuant to Art. 28 GDPR. The DPA is available at: https://supabase.com/dpa. Although Supabase is a US company, the data is processed and stored exclusively on servers in Frankfurt/Germany.
11b. Vercel Analytics (website analysis)
We use Vercel Analytics, a privacy-friendly analytics service provided by Vercel Inc. (USA), to evaluate Website usage. Vercel Analytics works without cookies and without fingerprinting. No personal data is collected — the evaluation takes place exclusively on the basis of aggregated, anonymised data.
Data collected: page views, referrer (where visitors come from), device type, country (estimated, without storing IP addresses) — fully anonymised.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in analysing Website usage for optimisation purposes). As neither cookies are set nor personal data is processed, consent under § 25 TDDDG is not required.
11c. Vercel Speed Insights (performance measurement)
We use Vercel Speed Insights, a service provided by Vercel Inc. (USA), for the anonymised measurement of Website performance (Core Web Vitals). Only technical performance data is collected — no personal data, no cookies, no tracking.
Data collected: loading times (LCP, FID, CLS), device type (desktop/mobile), connection speed — fully anonymised, without IP addresses or user identification.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the technical optimisation of the Website). As no personal data is processed, consent under § 25 TDDDG is not required.
12. Data security
We use appropriate technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or against unauthorised access by third parties. Our security measures include in particular:
- End-to-end TLS encryption of all data traffic
- Server-side honeypot techniques and IP-based rate limiting to protect against misuse
- Validation and filtering of all user input at server level
- No persistent storage of IP addresses beyond the duration of the rate limiting
- Use of up-to-date frameworks and regular updates of software components
13. Validity and amendment of this Privacy Policy
This Privacy Policy is dated 13 August 2026. Due to the further development of our Website and our services, or due to changed statutory or regulatory requirements, it may become necessary to amend this Privacy Policy. The current version can be accessed at any time at sopheraconsulting.de/datenschutz.
14. AI transparency (Art. 50 EU AI Act)
Since 2 August 2026, the transparency obligations of Art. 50 of Regulation (EU) 2024/1689 (the “EU AI Act”) have applied. We use AI at the following points and make this apparent in each case:
a) Automation Check (AI configurator). The Automation Check on our home page is carried out by an AI system (Anthropic Claude). You are not interacting with a human there. We point this out to you immediately at the beginning of the interaction. The assessment produced is AI-generated and labelled as such. Details on the data processing can be found in section 7 and on the automated evaluation in section 4.9.
b) Blog articles. The specialist articles in our blog are created with AI support. Every article concerned carries a visible notice as well as a machine-readable marking in the source code.
c) Meeting notes. Notes and summaries from video conferences are generated by Google Gemini (see section 8.1a) and labelled as AI-generated.
No emotion recognition, no biometric categorisation. We use systems within the meaning of Art. 50(3) EU AI Act neither on this Website nor in our customer communication. Likewise, we do not create deepfakes within the meaning of Art. 50(4) EU AI Act.
We answer questions about our use of AI at ai@sopheraconsulting.de.
If you have any questions about data protection, you can contact us at any time: ai@sopheraconsulting.de