Last updated: August 2026
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection provisions is:
Deimann Com GmbH
Randstraße 75, 22525 Hamburg
Germany
Phone: upon request
Email: [email protected]
Managing Director: Janik Deimann
Register court: Amtsgericht Hamburg (Hamburg Local Court), HRB 164162
VAT identification number: DE332747716
Insofar as Deimann Com GmbH processes personal data on behalf of and under the instructions of its customers as part of the B2B lead research service (Section B), it is not Deimann Com GmbH but the respective customer who is the controller; for details, see Section B.
Our Data Protection Officer is:
Rechtsanwalt Jan Marschner
Rechtsanwaltskanzlei Jan Marschner, Markt 9, D-04109 Leipzig, Germany
Phone: +49 (0) 341 - 2618 9373
You can reach our Data Protection Officer at: [email protected]
For general questions about data protection or to exercise your data subject rights, you can also contact our internal point of contact: [email protected]
This Privacy Policy describes two separate processing contexts:
Information on the use of cookies and tracking technologies can be found in our separate Cookie Policy.
In this section, Deimann Com GmbH is the controller within the meaning of Art. 4 no. 7 GDPR.
Each time our website is accessed, technically necessary data is processed (IP address, date and time, resource accessed, browser type, referrer).
The processing takes place on the basis of Art. 6(1)(f) GDPR for the purpose of the provision, stability and security of the website.
Server log files are deleted after a maximum of 30 days, unless security-related incidents require longer storage.
Use of our platform at my.leadscraper.de requires registration.
In doing so, we process: name, business email address, password (encrypted), company data, billing data, as well as usage behavior within the platform.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract) as well as, for supplementary analysis to improve the product, Art. 6(1)(f) GDPR.
Account data is deleted up to 12 months after the end of the contract; statutory retention obligations (in particular Section 147 AO (German Fiscal Code) and Section 257 HGB (German Commercial Code): 6 or 10 years, respectively, for invoicing and business records) remain unaffected.
For payment processing, we use a specialized payment service provider based in the EU. This provider processes the payment data under its own responsibility;
we only receive confirmations of successful transactions as well as data required for invoicing.
Legal basis: Art. 6(1)(b) GDPR. For the data location and transfer basis, see the processor overview (Section C.2).
For the sending of transactional and lifecycle emails (e.g. registration and security confirmations, notifications regarding contract and account status, product-related notices), we use a specialized email delivery service provider as a processor.
In doing so, we process in particular your email address, your name, as well as the content and metadata required for the respective sending purpose.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract) or, for operationally necessary notices, Art. 6(1)(f) GDPR.
For the data location and transfer basis, see the processor overview (Section C.2).
For customer support, we use a specialized support communication service provider based in the EU as a processor.
When you use the chat, we process the content you submit as well as technical connection data in order to handle your inquiry.
The legal basis is Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR (efficient customer communication).
For the secure and stable provision of our website and platform, we use a service provider for content delivery, security and bot protection, in particular for content delivery, DNS, tunneling/provisioning and bot protection.
In doing so, technical connection data (in particular the IP address) is processed to ensure availability, integrity and protection against abusive access.
The legal basis is Art. 6(1)(f) GDPR. For the data location and transfer basis, see the processor overview (Section C.2).
We use technically necessary cookies (session management, login). These are required for the platform to function; the legal basis is Section 25(2) no. 2 TDDDG (German Digital Services Data Protection Act).
Optional analytics and marketing cookies are set exclusively on the basis of your consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG).
We integrate Google services using so-called Google Consent Mode: before your consent decision, only cookieless status signals without user identifiers are transmitted to Google. We deliver embedded explainer videos via the streaming service Mux (Mux, Inc., USA).
For details of the tools used, their providers, purposes, retention periods and any transfers to third countries, please refer to our Cookie Policy.
To provide the above services, we use carefully selected processors and recipients, in particular for hosting, database and authentication infrastructure (cloud), content delivery, security and bot protection, payment processing, sending of transactional and lifecycle emails, as well as support communication.
The complete, up-to-date list with purpose, data location and transfer basis can be found in the processor overview (Section C.2).
In this section, Deimann Com GmbH processes personal data on behalf of and under the instructions of the customer. The customer is the controller within the meaning of Art. 4 no. 7 GDPR, and Deimann Com GmbH is the processor within the meaning of Art. 28 GDPR. The basis for this is the data processing agreement (DPA), which is accepted together with the terms and conditions as an annex thereto upon registration and is available at any time.
As part of our B2B lead research service, we collect and process personal data that relates to a professional context.
We expressly point out that professional/business contact data (e.g. business email addresses, names of managing directors or sales managers) also constitutes personal data within the meaning of Art. 4 no. 1 GDPR and is fully subject to the GDPR.
In particular, the following is processed:
We do not operate a pre-built database of individuals. Rather, the data is researched from publicly accessible sources, structured and made available to the respective customer on an occasion-driven (on-demand) basis in response to a specific customer request.
All data originates exclusively from publicly accessible sources, in particular:
We do not collect data from sources whose terms of use prohibit automated data collection.
We collect, structure, verify and enrich the data described above and make it available to the respective customer as controller,
so that the customer can use the data, under its own responsibility, for B2B business development towards the relevant companies.
The processing of the lead data is carried out on behalf of the customer. The customer is the controller; the customer bears the data protection responsibility for the processing and therefore also for the legal basis.
As a rule, the customer bases the processing on its legitimate interest pursuant to Art. 6(1)(f) GDPR in the structured identification of potential business partners from publicly accessible sources and the subsequent B2B business development (cf. Recital 47 sentence 2 GDPR); however, it is the customer's responsibility to determine and document the legal basis applicable in each case.
For the core processing of the lead data, Deimann Com GmbH does not rely on a legitimate interest of its own, but acts as processor on the documented instructions of the customer. The legal basis, instructions and the obligations of both parties are governed by the DPA (annex to the terms and conditions).
Even within the scope of the processing on behalf of the customer, the processing remains limited to such data as is necessary to identify a company and its business contact person. No processing of private data, no special categories of data within the meaning of Art. 9 GDPR, and no evaluation aimed at profiling takes place; no data from the private sphere of the data subjects is collected or linked with professional data.
For the processing of the lead data, there is processing on behalf of a controller pursuant to Art. 28 GDPR:
The processing is based on the data processing agreement (DPA) concluded between the customer and Deimann Com GmbH, which is accepted together with the terms and conditions as an annex thereto upon registration and is available at any time.
The following applies to the points essential to the processing on behalf of a controller (cf. DPA Section 4):
The customer is obliged to independently verify whether, and on what legal basis, it may carry out a specific instance of contact under data protection and competition law (in particular Section 7 UWG (German Act Against Unfair Competition)).
Deimann Com GmbH assumes no responsibility and provides no warranty that any contact initiated by the customer is lawful.
The data is not collected directly from the data subjects, but from publicly accessible sources. The obligation to inform under Art. 14 GDPR is borne by the customer as controller. Deimann Com GmbH supports the customer, as processor, in fulfilling this obligation by providing the following means on behalf of the controllers:
Upon direct request by a data subject, we provide individual information, correct or delete the data within the statutory deadlines, or forward the request to the responsible customer and process it in accordance with the customer's instructions.
Lead data is deleted or anonymized as soon as it is no longer required, at the latest 12 months after delivery. Datasets that could not be updated or verified for more than 24 months are likewise deleted or anonymized.
The deletion or personal-data cleansing of lead data delivered to a customer after 12 months from delivery is based on the documented standard instruction in the DPA and takes place insofar as the customer does not instruct otherwise.
In the event of an objection by a data subject pursuant to Art. 21 GDPR, deletion takes place without undue delay, at the latest within 30 days of receipt of the objection.
There is no decision based solely on automated processing that produces legal effects concerning the data subjects or similarly significantly affects them, within the meaning of Art. 22 GDPR.
For the preparation, evaluation and prioritization of the data, we use automated procedures, including AI-supported classification; these serve exclusively for the internal quality assurance of data preparation as a technical means of carrying out the customer's instructions, and do not have any direct legal effect on the data subjects.
We take technical and organizational measures pursuant to Art. 32 GDPR to protect personal data against loss, manipulation or unauthorized access.
These include, in particular: encrypted data transmission (TLS), access restrictions with a role-based concept, storage primarily on servers within the European Union, as well as regular security reviews.
We use carefully selected processors and recipients with whom the contracts required under data protection law (in particular pursuant to Art. 28 GDPR) are in each case in place. Insofar as we process lead data on behalf of our customers (Section B), these service providers are sub-processors within the meaning of Art. 28(4) GDPR. Service providers are used in particular from the following categories:
We provide a current overview of our processors — with purpose, registered office/data location and transfer basis for each service provider — upon request. We provide our customers with a specific, current list of the processors used as part of the data processing agreement (DPA), and provide it to data subjects upon request ([email protected]).
Data processing generally takes place within the European Union. Insofar as data is transferred to recipients outside the European Economic Area — in particular to the USA in connection with individual services from the categories hosting, database and authentication infrastructure (cloud), content delivery, security and bot protection, sending of transactional and lifecycle emails, services for researching and verifying publicly accessible (business) information, as well as AI-supported preparation and evaluation of data — this is done exclusively on the basis of appropriate safeguards.
Insofar as the respective recipient is certified under the EU-US Data Privacy Framework (DPF), we base the transfer on the adequacy decision of the European Commission of 10 July 2023 (Art. 45 GDPR); otherwise on the EU Standard Contractual Clauses (Art. 46 GDPR) together with supplementary safeguards.
Which basis applies for each service provider (DPF or Standard Contractual Clauses) is set out in the processor overview available upon request.
Data subjects have the right, pursuant to Art. 15 et seq. GDPR, to:
To exercise these rights, an informal email to [email protected] is sufficient. Insofar as a request relates to lead data processed on behalf of a customer (Section B), we will assist you and, if necessary, forward the request to the responsible customer.
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for Deimann Com GmbH is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (Hamburg Commissioner for Data Protection and Freedom of Information)
Ludwig-Erhard-Straße 22, 20459 Hamburg
datenschutz-hamburg.de
We reserve the right to adapt this Privacy Policy to changed legal circumstances, technical developments or adjustments to our processing procedures.
The respective current version is available on our website at all times.
LeadScraper: AI-powered B2B leads that truly convert. GDPR compliant. Results-driven.
Still have questions? Feel free to contact us at [email protected]
