Privacy Policy

Last updated: August 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection provisions is:

Deimann Com GmbH
Randstraße 75, 22525 Hamburg
Germany
Phone: upon request
Email: [email protected]
Managing Director: Janik Deimann
Register court: Amtsgericht Hamburg (Hamburg Local Court), HRB 164162
VAT identification number: DE332747716

Insofar as Deimann Com GmbH processes personal data on behalf of and under the instructions of its customers as part of the B2B lead research service (Section B), it is not Deimann Com GmbH but the respective customer who is the controller; for details, see Section B.

2. Data Protection Officer

Our Data Protection Officer is:
Rechtsanwalt Jan Marschner
Rechtsanwaltskanzlei Jan Marschner, Markt 9, D-04109 Leipzig, Germany
Phone: +49 (0) 341 - 2618 9373

You can reach our Data Protection Officer at: [email protected]

For general questions about data protection or to exercise your data subject rights, you can also contact our internal point of contact: [email protected]

3. Scope of this Privacy Policy

This Privacy Policy describes two separate processing contexts:

  • Section A: The processing of data of the users of our website and our platform (customers, prospects, website visitors). Here, Deimann Com GmbH is the controller.
  • Section B: The processing of business-related data of third parties that we research from publicly accessible sources on behalf of our customers as part of our B2B lead research service and make available to the respective customer. Here, the customer is the controller and Deimann Com GmbH is the processor (Art. 28 GDPR).

Information on the use of cookies and tracking technologies can be found in our separate Cookie Policy.

A. Processing in connection with the operation of the platform and website

In this section, Deimann Com GmbH is the controller within the meaning of Art. 4 no. 7 GDPR.

A.1 Accessing the website and server log files

Each time our website is accessed, technically necessary data is processed (IP address, date and time, resource accessed, browser type, referrer).
The processing takes place on the basis of Art. 6(1)(f) GDPR for the purpose of the provision, stability and security of the website.
Server log files are deleted after a maximum of 30 days, unless security-related incidents require longer storage.

A.2 Registration and use of the platform

Use of our platform at my.leadscraper.de requires registration.
In doing so, we process: name, business email address, password (encrypted), company data, billing data, as well as usage behavior within the platform.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract) as well as, for supplementary analysis to improve the product, Art. 6(1)(f) GDPR.
Account data is deleted up to 12 months after the end of the contract; statutory retention obligations (in particular Section 147 AO (German Fiscal Code) and Section 257 HGB (German Commercial Code): 6 or 10 years, respectively, for invoicing and business records) remain unaffected.

A.3 Payment processing

For payment processing, we use a specialized payment service provider based in the EU. This provider processes the payment data under its own responsibility;
we only receive confirmations of successful transactions as well as data required for invoicing.
Legal basis: Art. 6(1)(b) GDPR. For the data location and transfer basis, see the processor overview (Section C.2).

A.4 Transactional and lifecycle emails

For the sending of transactional and lifecycle emails (e.g. registration and security confirmations, notifications regarding contract and account status, product-related notices), we use a specialized email delivery service provider as a processor.
In doing so, we process in particular your email address, your name, as well as the content and metadata required for the respective sending purpose.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract) or, for operationally necessary notices, Art. 6(1)(f) GDPR.
For the data location and transfer basis, see the processor overview (Section C.2).

A.5 Support chat

For customer support, we use a specialized support communication service provider based in the EU as a processor.
When you use the chat, we process the content you submit as well as technical connection data in order to handle your inquiry.
The legal basis is Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR (efficient customer communication).

A.6 Provision and security (content delivery / bot protection)

For the secure and stable provision of our website and platform, we use a service provider for content delivery, security and bot protection, in particular for content delivery, DNS, tunneling/provisioning and bot protection.
In doing so, technical connection data (in particular the IP address) is processed to ensure availability, integrity and protection against abusive access.
The legal basis is Art. 6(1)(f) GDPR. For the data location and transfer basis, see the processor overview (Section C.2).

A.7 Cookies and tracking

We use technically necessary cookies (session management, login). These are required for the platform to function; the legal basis is Section 25(2) no. 2 TDDDG (German Digital Services Data Protection Act).
Optional analytics and marketing cookies are set exclusively on the basis of your consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG).
We integrate Google services using so-called Google Consent Mode: before your consent decision, only cookieless status signals without user identifiers are transmitted to Google. We deliver embedded explainer videos via the streaming service Mux (Mux, Inc., USA).
For details of the tools used, their providers, purposes, retention periods and any transfers to third countries, please refer to our Cookie Policy.

A.8 Recipients / processors in platform operations

To provide the above services, we use carefully selected processors and recipients, in particular for hosting, database and authentication infrastructure (cloud), content delivery, security and bot protection, payment processing, sending of transactional and lifecycle emails, as well as support communication.
The complete, up-to-date list with purpose, data location and transfer basis can be found in the processor overview (Section C.2).

B. Processing of business-related data of third parties (lead research) — on behalf of the customer

In this section, Deimann Com GmbH processes personal data on behalf of and under the instructions of the customer. The customer is the controller within the meaning of Art. 4 no. 7 GDPR, and Deimann Com GmbH is the processor within the meaning of Art. 28 GDPR. The basis for this is the data processing agreement (DPA), which is accepted together with the terms and conditions as an annex thereto upon registration and is available at any time.

B.1 Subject matter of the processing

As part of our B2B lead research service, we collect and process personal data that relates to a professional context.
We expressly point out that professional/business contact data (e.g. business email addresses, names of managing directors or sales managers) also constitutes personal data within the meaning of Art. 4 no. 1 GDPR and is fully subject to the GDPR.

In particular, the following is processed:

  • Company name, address, website, industry and size classification
  • First and last name of persons in a business function (e.g. management, sales, marketing)
  • Business contact details (business email address, business phone number)
  • Professional position

We do not operate a pre-built database of individuals. Rather, the data is researched from publicly accessible sources, structured and made available to the respective customer on an occasion-driven (on-demand) basis in response to a specific customer request.

B.2 Source of the data

All data originates exclusively from publicly accessible sources, in particular:

  • Company websites and legal notices (Impressum)
  • Public industry and company directories
  • Public registers (e.g. commercial register)
  • Map services with publicly available business information

We do not collect data from sources whose terms of use prohibit automated data collection.

B.3 Purposes of the processing

We collect, structure, verify and enrich the data described above and make it available to the respective customer as controller,
so that the customer can use the data, under its own responsibility, for B2B business development towards the relevant companies.

B.4 Legal basis

The processing of the lead data is carried out on behalf of the customer. The customer is the controller; the customer bears the data protection responsibility for the processing and therefore also for the legal basis.
As a rule, the customer bases the processing on its legitimate interest pursuant to Art. 6(1)(f) GDPR in the structured identification of potential business partners from publicly accessible sources and the subsequent B2B business development (cf. Recital 47 sentence 2 GDPR); however, it is the customer's responsibility to determine and document the legal basis applicable in each case.

For the core processing of the lead data, Deimann Com GmbH does not rely on a legitimate interest of its own, but acts as processor on the documented instructions of the customer. The legal basis, instructions and the obligations of both parties are governed by the DPA (annex to the terms and conditions).

Even within the scope of the processing on behalf of the customer, the processing remains limited to such data as is necessary to identify a company and its business contact person. No processing of private data, no special categories of data within the meaning of Art. 9 GDPR, and no evaluation aimed at profiling takes place; no data from the private sphere of the data subjects is collected or linked with professional data.

B.5 Responsibility and data flow (processing on behalf of a controller, Art. 28 GDPR)

For the processing of the lead data, there is processing on behalf of a controller pursuant to Art. 28 GDPR:

  • The customer is the controller within the meaning of Art. 4 no. 7 GDPR. Through its search requests as well as its target-group, industry, region and role parameters, the customer determines the purpose and means of the processing and is, in particular, the controller responsible for any contact made with the data subjects.
  • Deimann Com GmbH is the processor within the meaning of Art. 28 GDPR. It researches, prepares and provides the data exclusively on behalf of and under the documented instructions of the customer.

The processing is based on the data processing agreement (DPA) concluded between the customer and Deimann Com GmbH, which is accepted together with the terms and conditions as an annex thereto upon registration and is available at any time.

The following applies to the points essential to the processing on behalf of a controller (cf. DPA Section 4):

  • The research sources, search and evaluation procedures, as well as the AI-supported classification used are technical means for carrying out the instructions of the controller.
  • The service-wide global suppression list (upholding objection and erasure requests from data subjects) and the centralized retention period of 12 months are documented standard instructions from the controller, issued upon conclusion of the contract, insofar as the controller does not instruct otherwise.

The customer is obliged to independently verify whether, and on what legal basis, it may carry out a specific instance of contact under data protection and competition law (in particular Section 7 UWG (German Act Against Unfair Competition)).
Deimann Com GmbH assumes no responsibility and provides no warranty that any contact initiated by the customer is lawful.

B.6 Information for data subjects (Art. 14 GDPR)

The data is not collected directly from the data subjects, but from publicly accessible sources. The obligation to inform under Art. 14 GDPR is borne by the customer as controller. Deimann Com GmbH supports the customer, as processor, in fulfilling this obligation by providing the following means on behalf of the controllers:

  • At https://www.leadscraper.de/lead-information, we permanently provide publicly accessible, lead-specific privacy information containing all mandatory information pursuant to Art. 14(1) and (2) GDPR.
  • We provide a simple and directly effective means for data subjects to object and to request information.
  • We contractually oblige our customers to indicate the source of the data upon first making business contact with a data subject, unless this is already apparent from the communication itself.
  • Insofar as individually informing the data subjects would require disproportionate effort (Art. 14(5)(b) GDPR), the obligation to inform can be fulfilled through the public provision described above.

Upon direct request by a data subject, we provide individual information, correct or delete the data within the statutory deadlines, or forward the request to the responsible customer and process it in accordance with the customer's instructions.

B.7 Retention period

Lead data is deleted or anonymized as soon as it is no longer required, at the latest 12 months after delivery. Datasets that could not be updated or verified for more than 24 months are likewise deleted or anonymized.
The deletion or personal-data cleansing of lead data delivered to a customer after 12 months from delivery is based on the documented standard instruction in the DPA and takes place insofar as the customer does not instruct otherwise.
In the event of an objection by a data subject pursuant to Art. 21 GDPR, deletion takes place without undue delay, at the latest within 30 days of receipt of the objection.

B.8 No decision based solely on automated processing in individual cases (Art. 22 GDPR)

There is no decision based solely on automated processing that produces legal effects concerning the data subjects or similarly significantly affects them, within the meaning of Art. 22 GDPR.
For the preparation, evaluation and prioritization of the data, we use automated procedures, including AI-supported classification; these serve exclusively for the internal quality assurance of data preparation as a technical means of carrying out the customer's instructions, and do not have any direct legal effect on the data subjects.

C. General provisions

C.1 Data security

We take technical and organizational measures pursuant to Art. 32 GDPR to protect personal data against loss, manipulation or unauthorized access.
These include, in particular: encrypted data transmission (TLS), access restrictions with a role-based concept, storage primarily on servers within the European Union, as well as regular security reviews.

C.2 Processors

We use carefully selected processors and recipients with whom the contracts required under data protection law (in particular pursuant to Art. 28 GDPR) are in each case in place. Insofar as we process lead data on behalf of our customers (Section B), these service providers are sub-processors within the meaning of Art. 28(4) GDPR. Service providers are used in particular from the following categories:

  • Hosting, database and authentication infrastructure (cloud) — provision of the underlying server, database, authentication and storage infrastructure.
  • Content delivery, security and bot protection — content delivery, DNS, secure provisioning and protection against abusive access.
  • Payment processing — processing of payments and management of subscriptions.
  • Sending of transactional and lifecycle emails — delivery of system-related and contract-related emails.
  • Services for researching and verifying publicly accessible (business) information — research, retrieval and verification of information from publicly accessible sources, including the verification of business email addresses.
  • AI-supported preparation and evaluation of data — automated structuring, enrichment and evaluation of data.
  • Support communication — handling of support and customer inquiries.

We provide a current overview of our processors — with purpose, registered office/data location and transfer basis for each service provider — upon request. We provide our customers with a specific, current list of the processors used as part of the data processing agreement (DPA), and provide it to data subjects upon request ([email protected]).

C.3 Transfer to third countries

Data processing generally takes place within the European Union. Insofar as data is transferred to recipients outside the European Economic Area — in particular to the USA in connection with individual services from the categories hosting, database and authentication infrastructure (cloud), content delivery, security and bot protection, sending of transactional and lifecycle emails, services for researching and verifying publicly accessible (business) information, as well as AI-supported preparation and evaluation of data — this is done exclusively on the basis of appropriate safeguards.
Insofar as the respective recipient is certified under the EU-US Data Privacy Framework (DPF), we base the transfer on the adequacy decision of the European Commission of 10 July 2023 (Art. 45 GDPR); otherwise on the EU Standard Contractual Clauses (Art. 46 GDPR) together with supplementary safeguards.
Which basis applies for each service provider (DPF or Standard Contractual Clauses) is set out in the processor overview available upon request.

C.4 Rights of data subjects

Data subjects have the right, pursuant to Art. 15 et seq. GDPR, to:

  • access to stored personal data (Art. 15 GDPR)
  • rectification of inaccurate or incomplete data (Art. 16 GDPR)
  • erasure ("right to be forgotten", Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • objection to processing based on legitimate interest (Art. 21 GDPR)
  • withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)

To exercise these rights, an informal email to [email protected] is sufficient. Insofar as a request relates to lead data processed on behalf of a customer (Section B), we will assist you and, if necessary, forward the request to the responsible customer.

C.5 Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for Deimann Com GmbH is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (Hamburg Commissioner for Data Protection and Freedom of Information)
Ludwig-Erhard-Straße 22, 20459 Hamburg
datenschutz-hamburg.de

C.6 Changes to this Privacy Policy

We reserve the right to adapt this Privacy Policy to changed legal circumstances, technical developments or adjustments to our processing procedures.
The respective current version is available on our website at all times.