Skip to main content

Privacy Policy

Last updated: 1 June 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and other data protection provisions is:

Sophera Consulting
Max Fey
Elsdorfer Straße 29
50126 Bergheim
Germany

Telephone: +49 322 21802200
Email: fey@sopheraconsulting.de

VAT ID: DE357873793

1.1 Data protection officer

As a sole proprietorship, Sophera Consulting has currently not appointed a data protection officer (DPO), because the statutory conditions for a mandatory appointment are not met:

  • At least 20 persons are not permanently engaged in the automated processing of personal data (§ 38(1) BDSG, German Federal Data Protection Act).
  • The core activity does not consist of the regular and systematic monitoring of data subjects on a large scale (Art. 37(1)(b) GDPR).
  • The core activity does not consist of the large-scale processing of special categories of personal data (Art. 37(1)(c) GDPR, Art. 9 GDPR).
  • No commercial processing for the purpose of transfer or market/opinion research takes place, and none of our processing operations is subject to the obligation to carry out a data protection impact assessment under Art. 35(3) GDPR or the mandatory list of the German Data Protection Conference (§ 38(1) sentence 2 BDSG).

Voluntary risk assessment: For the processing operations with the highest risk, namely session recording by Microsoft Clarity (section 6.2), the AI-supported initial assessment in the Automation Check (section 7) and the consolidation of prospect data (section 8.14), we have voluntarily carried out and documented a risk assessment based on the standards of Art. 35 GDPR. It is reviewed annually as well as upon any material change to the processing; we submit it to the competent supervisory authority on request. Outcome: the processing operations are permissible and the residual risk is low.

Customer projects involving health data: As soon as we process special categories of personal data (Art. 9 GDPR) on a large scale as a processor, we will appoint a data protection officer before processing begins (Art. 37(1)(c) GDPR) and announce this here.

Contact for data protection enquiries: For questions about data protection, the exercise of your data subject rights (Art. 15–22 GDPR) or the withdrawal of consent you have given, please contact directly:

Max Fey (owner and controller)
Email: fey@sopheraconsulting.de

Should the circumstances of our company change (e.g. the hiring of additional staff or the commencement of high-risk processing activities), we will appoint a data protection officer without undue delay and disclose this transparently at this point.

2. Scope

This Privacy Policy applies to the online offering of Sophera Consulting under the domains sopheraconsulting.de and sopheraconsulting.com as well as to all associated subpages (hereinafter the “Website”). Sophera Consulting provides consulting and implementation services in the areas of AI workflow automation, process optimisation, digitalisation consulting, AI training as well as support & maintenance. The following information explains which personal data we collect within the scope of this offering, on what legal basis this takes place and for what purpose the processing is carried out.

3. General information and mandatory disclosures

3.1 SSL and TLS encryption

For security reasons and to protect the transmission of confidential content, this Website uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address bar of your browser changes from “http://” to “https://” and a padlock symbol appears in your browser bar. When SSL or TLS encryption is active, the data you transmit to us cannot be read by third parties.

3.2 Retention period for personal data

Unless a more specific retention period is stated within this Privacy Policy, your personal data will remain with us until the purpose of the data processing ceases to apply. If you assert a justified request for erasure or withdraw your consent to data processing, your data will be deleted unless we have other legally permissible grounds for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, erasure will take place once those grounds cease to apply.

Overview of retention periods by data type:

  • Server log files: 14 days, followed by automatic erasure (Art. 6(1)(f) GDPR)
  • IP addresses used for rate limiting: max. 120 seconds in memory, no persistent storage
  • Contact form enquiries: until the enquiry has been dealt with, max. 3 years (limitation period under § 195 BGB, German Civil Code)
  • Appointment bookings and meetings: 12 months after the appointment, provided no business relationship has been established
  • Automation Check (AI configurator): 12 months (cf. section 7.3)
  • Customer data (Supabase, Pipedrive): for the duration of the business relationship plus statutory retention periods
  • Invoicing and accounting data (Lexoffice, Stripe): 10 years pursuant to § 147 AO (German Fiscal Code), § 257 HGB (German Commercial Code)
  • Business letters and email correspondence: 6 years pursuant to § 257 HGB
  • Cookie consent (consent record): 12 months, after which consent is requested again
  • Microsoft Clarity (cookies, session recordings): max. 12 months
  • Portal user data after deactivation: 90 days grace period, followed by technical erasure, provided no statutory retention obligations conflict
  • Confirmation link for the Automation Check: 24 hours for the confirmation, result link 30 days from confirmation

3.3 Legal bases for data processing

Where we obtain the consent of the data subject for processing operations involving personal data, Art. 6(1)(a) GDPR serves as the legal basis.

Where the processing of personal data is necessary for the performance of a contract to which the data subject is party, or in order to take steps prior to entering into a contract, the processing is based on Art. 6(1)(b) GDPR.

Where processing of personal data is necessary for compliance with a legal obligation to which our company is subject, Art. 6(1)(c) GDPR serves as the legal basis.

Where processing is necessary to safeguard a legitimate interest of our company or of a third party, and where the interests, fundamental rights and freedoms of the data subject do not override that first-mentioned interest, Art. 6(1)(f) GDPR serves as the legal basis for the processing.

4. Rights of the data subject

As a data subject, you have the following rights under the GDPR:

4.1 Right of access (Art. 15 GDPR)

You have the right to request confirmation as to whether we process personal data concerning you. If this is the case, you are entitled to access that data as well as to the information listed in detail in Art. 15(1) GDPR.

4.2 Right to rectification (Art. 16 GDPR)

You have the right to obtain the rectification of inaccurate personal data without undue delay. Taking into account the purposes of the processing, you also have the right to request that incomplete personal data be completed.

4.3 Right to erasure (Art. 17 GDPR)

You have the right to request that personal data concerning you be erased without undue delay, provided one of the grounds set out in Art. 17(1) GDPR applies and the processing is not necessary under Art. 17(3) GDPR.

4.4 Right to restriction of processing (Art. 18 GDPR)

You have the right to request the restriction of the processing of your personal data where one of the conditions set out in Art. 18(1) GDPR applies, in particular where you contest the accuracy of the data, the processing is unlawful, we no longer need the data or you have objected to the processing.

4.5 Right to data portability (Art. 20 GDPR)

You have the right to receive the personal data concerning you which you have provided to us in a structured, commonly used and machine-readable format. You also have the right to transmit that data to another controller, provided the processing is based on consent or on a contract and is carried out by automated means.

4.6 Right to object (Art. 21 GDPR)

Where we process your personal data on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right under Art. 21 GDPR to object to the processing at any time. This requires grounds relating to your particular situation. This also applies to profiling based on that provision.

Where we process your personal data for the purposes of direct marketing, you have the right to object at any time and without giving reasons. This also applies to profiling to the extent that it is related to direct marketing.

4.7 Right to withdraw consent given (Art. 7(3) GDPR)

You have the right to withdraw consent to data processing once given at any time with effect for the future. The withdrawal does not affect the lawfulness of the processing carried out on the basis of the consent up to the point of withdrawal.

4.8 Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement.

The supervisory authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestr. 2–4
40213 Düsseldorf
Telephone: +49 211 38424-0
Email: poststelle@ldi.nrw.de

4.9 Automated decision-making and profiling (Art. 22 GDPR)

An automated individual decision producing legal effects concerning you or similarly significantly affecting you (Art. 22(1) GDPR) does not take place. So that you can nevertheless fully understand our processing, we disclose the automated procedures we use:

a) Initial assessment in the Automation Check. Your process description is evaluated by an AI system (Anthropic Claude, see section 7.2). The system estimates an automation potential as a percentage and a possible monthly saving in euros. These figures are a non-binding orientation, not a commitment and not a decision about a contractual relationship.

b) Pre-sorting in the CRM. After you submit the Automation Check, we automatically create a record in our CRM system. The saving estimated by the AI system is adopted as the provisional value of the case and the record is assigned to an internal processing stage. This serves solely the internal prioritisation of our follow-up. Whether an offer is made, and on what terms, is in every case decided by a human.

c) Reach measurement. Microsoft Clarity (section 6.2) evaluates usage behaviour in aggregated form. This data is not combined with your contact details to form a personality profile.

You may at any time request information about the assessment stored about you at fey@sopheraconsulting.de, request its rectification or erasure and object to the pre-sorting described above.

5. Hosting

5.1 Vercel

Our Website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA (“Vercel”). Vercel is a platform-as-a-service solution for hosting web applications.

When you visit our Website, the host automatically collects technical access data (known as server log files). These include in particular:

  • IP address of the requesting device
  • date and time of the request
  • URL accessed and referrer URL
  • browser type and version as well as operating system
  • volume of data transferred

The collection of this data is technically necessary in order to display our Website to you and to ensure stability and security.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure and efficient web presence).

Transfer of data to the USA: Vercel is certified under the EU-US Data Privacy Framework. The transfer of personal data to the USA takes place on the basis of the adequacy decision of the European Commission pursuant to Art. 45 GDPR. Further information on data protection at Vercel can be found at: https://vercel.com/legal/privacy-policy

Data processing: We have concluded a data processing agreement (DPA) with Vercel that meets the requirements of Art. 28 GDPR.

6. Data collection on this Website

6.1 Technically necessary cookies

Our Website uses technically necessary cookies that are required to ensure the basic functions of the Website – in particular the language selection (German/English) via the internationalisation function (next-intl) and the storage of your cookie consent.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the technically error-free provision and optimisation of the Website. For technically necessary cookies, consent under § 25(2) TDDDG (German Digital Services Data Protection Act) is not required.

6.2 Analytics cookies (Microsoft Clarity)

Provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.

Purpose: We use Microsoft Clarity to analyse usage behaviour on our Website. Clarity creates heatmaps and session recordings (session replay) that help us to improve usability.

Note on profiling (Art. 4(4) GDPR): The session replays recorded by Clarity (mouse movements, click behaviour, scroll depth) may be classified as profiling in the data protection sense, as they enable a systematic evaluation of user behaviour. An automated individual decision with legal effect for you within the meaning of Art. 22 GDPR does, however, not take place (see section 4.9). In the standard configuration we use, Clarity masks entries in form fields so that your input is not recorded in plain text. You can object to this processing at any time via the cookie banner; you will find the link to it in the page footer.

Data processed: click behaviour, scroll depth, mouse movements, page views, device and browser information, IP address (anonymised).

Data sharing: Microsoft Clarity may link the collected data with other Microsoft services (including Microsoft Advertising/Bing) and pass it on to third parties in order to provide aggregated analytics and advertising services. Details can be found in the Microsoft privacy statement.

Retention period: The cookies set by Clarity have a storage period of up to 1 year.

Legal basis: Art. 6(1)(a) GDPR (consent) as well as § 25(1) TDDDG. Clarity is only activated after your express consent via the cookie banner. You can withdraw your consent at any time.

Note: Microsoft Clarity is not a technically necessary cookie. The service serves exclusively to analyse user behaviour and is not required for the operation of the Website. It is activated exclusively with your active consent; a legitimate interest under Art. 6(1)(f) GDPR expressly does not exist.

Microsoft is certified under the EU-US Data Privacy Framework.

6.2a Google Tag Manager

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).

Purpose: We use Google Tag Manager (GTM-MVSDH957) to manage marketing and analytics tags on our Website. The Tag Manager itself does not set cookies; however, when the script is loaded, your IP address is transmitted to Google. It serves as a management tool that triggers other tags (e.g. conversion tracking).

Legal basis: Art. 6(1)(a) GDPR (consent). Google Tag Manager is only activated after your express consent via the cookie banner (category “Marketing”). Without your consent, no tags are loaded.

Data sharing: Google is certified under the EU-US Data Privacy Framework. Further information on data protection at Google can be found at https://policies.google.com/privacy.

6.3 Note on data sharing by third-party providers

The analytics and marketing services used on this Website (Microsoft Clarity, Google Ads, Meta, LinkedIn) may share the collected data with their respective partner networks and process it for their own purposes. This includes in particular:

  • Microsoft: sharing with Microsoft Advertising, Bing and affiliated services
  • Google: sharing with Google Ads, the Google Analytics network and affiliated services
  • Meta: sharing with the Meta advertising network (Facebook, Instagram)
  • LinkedIn: sharing with the LinkedIn Marketing Solutions network

These transfers take place exclusively on the basis of your prior consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR).

Some of the providers named are subsidiaries of US corporations. In the course of data processing, data may be passed on to the respective parent companies in the USA:

  • Meta Platforms Ireland Limited → Meta Platforms, Inc. (USA)
  • LinkedIn Ireland Unlimited Company → LinkedIn Corporation (USA)
  • Google Ireland Limited → Google LLC (USA)
  • Microsoft Ireland Operations Limited → Microsoft Corporation (USA)

These transfers take place on the basis of the EU-US Data Privacy Framework (DPF) pursuant to Art. 45 GDPR. All the US parent companies named are certified under the DPF. Details on third country transfers can be found in section 11.

6.4 AI crawlers and LLM access

At /llms.txt we provide a machine-readable file that makes structured information about our Website and services available to AI systems (e.g. ChatGPT, Perplexity, Claude, Google AI Overviews). This file contains exclusively publicly available company information and no personal data.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in visibility in AI-supported search systems).

6.5 Server log files

The hosting provider automatically collects and stores information in what are known as server log files, which your browser transmits automatically when you visit the Website (cf. section 5.1). We do not merge this data with other data sources.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security and error-free operation of the Website).

6.6 Contact form

If you send us an enquiry via the contact form provided on the Website, the following personal data is collected:

  • Name
  • Email address
  • Company (optional)
  • Content of your message

Purpose: The collection serves to process and answer your enquiry, including any follow-up questions.

Legal basis: Where your enquiry serves to take steps prior to entering into a contract, Art. 6(1)(b) GDPR is the legal basis. Otherwise, we process your data on the basis of our legitimate interest in the effective handling of enquiries addressed to us pursuant to Art. 6(1)(f) GDPR.

Retention period: The data collected in the contact form will be deleted as soon as your enquiry has been conclusively dealt with and no statutory retention obligations conflict.

Protective measures: To protect against automated spam enquiries we use a server-side honeypot technique as well as IP-based rate limiting. The IP address is held in memory exclusively for the duration of the rate limiting (max. 120 seconds) and is discarded afterwards.

6.7 Enquiry by email or telephone

If you contact us by email or telephone, your enquiry together with all personal data arising from it (name, enquiry, telephone number, email address) will be stored and processed by us for the purpose of handling your request. This data will not be passed on to third parties without your express consent.

Legal basis: Art. 6(1)(b) GDPR (initiation and performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in the efficient handling of enquiries).

Retention period: The data will be deleted as soon as the enquiry has been conclusively dealt with and no statutory retention obligations conflict.

7. Automation Check (AI configurator)

On our Website we provide an interactive AI-supported configurator (“Automation Check”) with which you can obtain a non-binding initial assessment of the automation potential of your business processes.

7.1 Data collected

When you use the Automation Check, the following data is collected:

  • Name (optional)
  • Email address (mandatory)
  • Telephone number (mandatory)
  • Description of the business process to be automated (free text)
  • Preferred solution type (SaaS, custom development or open source)
  • Systems currently in use (optional)
  • Estimated monthly cost of the process (optional)

7.2 Processing by Anthropic (Claude API)

The process description you enter is transmitted to the API of Anthropic Ireland, Limited, Dublin, Ireland (processing by Anthropic, PBC, San Francisco, USA; hereinafter “Anthropic”) in order to produce the automation analysis. Anthropic processes the data exclusively to generate the analysis and, in accordance with the terms of use of the API, does not store the transmitted input for its own training purposes.

Data transmitted: process description, solution type, where applicable current systems and monthly costs. Your email address, telephone number and your name are not transmitted to Anthropic.

Transfer of data to the USA: The transfer of data to Anthropic in the USA takes place on the basis of EU Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR, which form part of Anthropic’s Data Processing Addendum.

Further information on data protection at Anthropic can be found at: https://www.anthropic.com/privacy

7.3 Delivery of the analysis by email

The result of the AI-supported analysis is sent to you by email to the email address you have provided. We use an SMTP service to send the email. The email contains the data you entered as well as the generated initial assessment.

Legal basis: Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract: preparation and delivery of the initial assessment you requested). Before submitting, you confirm by checkbox that you are acting as an entrepreneur and that the GTC apply; this confirmation is not consent under data protection law. You can object to follow-up by email or telephone at any time (section 4.6).

Storage and disclosure: The data collected in the course of the Automation Check is stored in our database (Supabase, Frankfurt region — see section 11a) in order to process your enquiry and deliver the analysis. In addition, we create a record of your contact details and your process description in our CRM system Pipedrive (see section 8.13) in order to document the initiation of business. A contact in our accounting software (section 8.12) is only created when an order is placed.

Retention period: We store this data for the duration of the initiation of business. If no business relationship arises within 12 months, we delete it. Statutory retention obligations (§ 147 AO, § 257 HGB) remain unaffected. You can request erasure at any time at fey@sopheraconsulting.de. The IP-based rate limiting (max. 120 seconds) serves exclusively to protect against misuse.

7.4 Note on the content of the analysis

The initial assessment generated by the AI system constitutes an automated, non-binding orientation aid and does not replace individual advice. No legal claims can be derived from the analysis.

7.5 Funding consultancy (partner service)

Description of the service: Within the framework of the partner service “funding consultancy”, Sophera Consulting refers clients to external, certified funding consultants (hereinafter “funding partners”). In this respect, Sophera Consulting is not the provider of the funding consultancy but an intermediary.

Data processed: In the course of the referral, the following personal data is transmitted to the funding partner:

  • First and last name
  • Email address
  • Telephone number
  • Details of the planned digitalisation project (insofar as communicated in the initial consultation)
  • Company data (industry, size, location — insofar as relevant for the funding assessment)

Legal basis: Art. 6(1)(a) GDPR (consent). The transfer of your data to the funding partner takes place exclusively after your express consent, which you give in the course of booking an appointment. You can withdraw your consent at any time with effect for the future.

Recipients: The funding partners are independent controllers within the meaning of Art. 4(7) GDPR. The respective partner is itself responsible for the processing after the transfer and informs you pursuant to Art. 13 GDPR. We tell you the name of the partner before the transfer.

Retention period: The referral data is stored by Sophera Consulting for the duration of the business relationship. After completion or discontinuation of the funding process and expiry of statutory retention periods, the data is deleted.

Right to object: You can object to the transfer of data to the funding partner at any time (fey@sopheraconsulting.de). In that case, the funding consultancy cannot be continued.

7.6 Customer portal, onboarding and digital offers

Purpose: Sophera Consulting offers its customers an access-restricted customer portal, digital acceptance of offers as well as automated onboarding after a contract is concluded. These functions facilitate project delivery and provide a transparent overview of ongoing projects, milestones and payments.

Data processed:

  • Contact data (name, email, telephone, company, address)
  • Project data (project name, description, milestones, payment status)
  • Onboarding questionnaires (company data, current systems, project goals, schedule)
  • Offer data (services, amounts, date of acceptance)
  • Generated PDF documents (invoices, offers)
  • Evidence of acceptance of the GTC and acknowledgement of this policy: timestamp, version, IP address and browser identifier (user agent) of each user (Art. 6(1)(f) GDPR, legitimate interest in verifiability)
  • Invited team members of the customer: name and email address (Art. 6(1)(b) and (f) GDPR)

Access control: Access takes place via cryptographically secure tokens (UUID v4) that are sent by email to the respective customer. The tokens are assigned exclusively to the respective customer and do not allow access to the data of other customers.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract).

Retention period: Project data is stored for the duration of the business relationship as well as the statutory retention periods (10 years pursuant to § 147 AO, § 257 HGB). Onboarding data is deleted after project completion, provided no further legal obligations exist.

8. Use of third-party services

In the course of our business activities we use various third-party services in order to provide our services efficiently and professionally. Below we inform you about the services used, the respective purposes of the processing and the relevant legal bases.

8.1 Google Workspace (Gmail, Google Drive, Google Calendar, Google Meet)

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Purpose: We use Google Workspace for business email communication (Gmail), the storage and exchange of documents (Google Drive), scheduling (Google Calendar) as well as for holding video conferences (Google Meet).

Data processed: name, email address, communication content, appointment details, shared documents, IP address, device and browser information.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in efficient business communication).

Google is certified under the EU-US Data Privacy Framework (DPF). We have concluded a data processing agreement (Data Processing Amendment) with Google pursuant to Art. 28 GDPR.

8.1a AI-supported meeting notes (Gemini in Google Meet)

Purpose: In video conferences via Google Meet, the “AI-supported meeting notes” function (Google Gemini) can be activated on request and with the express consent of all participants. It automatically creates a written transcript and a summary of the conversation.

Data processed: audio content of the conversation, transcripts and summaries generated from it, participant names, timestamps, spoken content of all those involved.

Legal basis: Art. 6(1)(a) GDPR (consent). The function is only activated if all participants expressly agree to the recording and processing. In addition, § 201 StGB (German Criminal Code, confidentiality of the spoken word) applies: recording takes place exclusively with the consent of all those involved.

Information provided before every recording:

  • Before the start of every meeting, all participants are actively informed about the planned recording
  • Consent is obtained orally or in writing and documented
  • Participants can withdraw their consent at any time, in which case the recording is stopped
  • Notes and transcripts are used exclusively for documentation purposes within the scope of the respective consultancy
  • They are not passed on to third parties without renewed consent

Note on the EU AI Act: Since 2 August 2026, the transparency obligations of Art. 50 of Regulation (EU) 2024/1689 have applied. We label AI transcripts and summaries accordingly as AI-generated. An overview of where we use AI and how we make this apparent can be found in section 14.

Data processing by Google: Google processes the audio data in accordance with the Google Workspace privacy terms. Under the data processing agreement (DPA, see 8.1), the data is used exclusively to provide the agreed service and not to train the AI models.

Activation and opt-out: The AI-supported meeting notes are NOT activated automatically for every meeting. Before each meeting, all participants are actively asked and must expressly agree. Any participant can have the recording stopped at any time during the meeting. Refusing consent does not lead to the meeting being cancelled.

Storage location: Transcripts and summaries are stored in Google Drive within the Sophera Consulting Workspace (EU servers) and are accessible exclusively to authorised staff.

Retention period: Transcripts are deleted after completion of the respective consultancy or the respective project. At the request of a participant, transcripts are deleted without undue delay.

8.1b Apple iCloud (calendar and contacts)

Provider: Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland (parent company: Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA).

Purpose: Synchronisation of our business calendar and address book between our devices. Appointments from Google Calendar (section 8.1) and contacts from business communication are mirrored in iCloud.

Data processed: appointment details (title, time, participants, location, notes), contact data (name, company, email address, telephone number).

Legal basis: Art. 6(1)(b) GDPR (performance of a contract and steps taken prior to entering into a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in scheduling that is available across devices).

Third country transfer: Apple Inc. is certified under the EU-US Data Privacy Framework (Art. 45 GDPR). Data in iCloud is stored in encrypted form; calendar and contacts are not end-to-end encrypted for reasons of interoperability. Patient data or other data from our customers’ systems is not processed in iCloud.

Retention period: appointments 12 months after the appointment, provided no business relationship has been established; contacts for the duration of the business relationship (section 3.2).

8.2 Google AI (Gemini, Vertex AI)

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Purpose: AI-supported analysis and automation within the scope of customer projects. The services are used to optimise processes, generate texts and analyse data.

Data processed: process descriptions, business data of the customer (only within the scope of the respective project assignment), where applicable anonymised or pseudonymised data sets.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) where we use the service for our own purposes. In customer projects we process personal data as a processor; the legal basis is determined by the customer as controller (section 8.17).

Important note: When certain Google AI services are used, data entered may be used to train AI models unless this has been excluded via the API configuration with data governance settings. For customer-related projects we primarily use the API variant with model training deactivated.

8.3 Anthropic (Claude API)

Provider: Anthropic Ireland, Limited, Dublin, Ireland (processing by Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA).

Purpose: In addition to the use described in section 7.2 within the scope of the Automation Check, we also use the Claude API for further customer projects, in particular for AI-supported text generation, analysis and process automation.

Data processed: process descriptions, business data of the customer (only within the scope of the respective project assignment).

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in the efficient provision of services).

No training: When the API is used, no input data is used to train AI models in accordance with the Anthropic API Terms of Service. The transfer to the USA is safeguarded by EU Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR.

Data processing: We have concluded a data processing agreement (DPA) with Anthropic pursuant to Art. 28 GDPR (Anthropic Data Processing Addendum, as of 2026). Further information on data protection at Anthropic can be found at: https://www.anthropic.com/privacy

8.4 OpenAI (GPT API)

Provider: OpenAI Ireland Ltd, Dublin, Ireland (processing by OpenAI, L.L.C., 3180 18th Street, San Francisco, CA 94110, USA). We do not use the consumer product ChatGPT for personal data.

Purpose: AI-supported text generation, analysis, code generation and process automation within the scope of customer projects.

Data processed: process descriptions, text input, business data of the customer (only within the scope of the respective project assignment).

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in the efficient provision of services).

No training when using the API: In accordance with the OpenAI API Terms of Use, no input data is used to train AI models when the API is used. The transfer to the USA is safeguarded by EU Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR in OpenAI’s Data Processing Addendum.

8.5 Clay

Provider: Clay Inc., USA.

Purpose: Data enrichment and lead research in the B2B sector. Clay is used to research and enrich publicly available business contact data.

Data processed: business contact data such as name, position, company, business email address.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in customer acquisition in the B2B sector). The legitimate interest arises from the necessity of identifying and approaching potential business customers. Contact is made by telephone, by post or via professional networks; we send email advertising only with prior consent (§ 7(2) no. 2 UWG, German Act against Unfair Competition).

Notice pursuant to Art. 14 GDPR: Insofar as we collect personal data not directly from the data subject but from publicly accessible sources or via Clay, we inform the data subject about the data processing pursuant to Art. 14 GDPR upon first contact.

8.6 Workflow automation (Dieserver AI / n8n, Make, Zapier, Microsoft Power Automate)

(1) The purpose of the processing is the automation of workflows and the orchestration of processes within customer projects, in particular the linking of services and systems. Which of the platforms named below is used in the individual case is determined by the offer or the data processing agreement.

(2) Recipients, place of processing and legal basis for transfer:

  • n8n – Recipient: n8n GmbH, Novalisstraße 10, 10115 Berlin, Germany. Where self-hosted on the customer’s servers or in a region within the European Union (section 8.16), no transfer to n8n GmbH takes place; the telemetry function is deactivated. The cloud variant is operated within the European Union (Frankfurt am Main).
  • Make – Recipient: Celonis, Inc., One World Trade Center, 87th Floor, New York, NY 10007, USA (parent company: Celonis SE, Munich). Place of processing: EU zone; a transfer to the United States of America cannot be ruled out. Legal basis for transfer: Art. 45 GDPR in conjunction with the adequacy decision on the EU-US Data Privacy Framework, additionally standard contractual clauses pursuant to Art. 46(2)(c) GDPR.
  • Zapier – Recipient: Zapier, Inc., 548 Market St. #62411, San Francisco, CA 94104-5401, USA. Place of processing: United States of America. Legal basis for transfer: Art. 45 GDPR in conjunction with the adequacy decision on the EU-US Data Privacy Framework, additionally standard contractual clauses pursuant to Art. 46(2)(c) GDPR. Special categories of personal data (Art. 9(1) GDPR) are not processed via Zapier.
  • Microsoft Power Automate – Recipient: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Place of processing: within the EU Data Boundary. For transfers to Microsoft Corporation, USA, see section 11.

(3) Categories of personal data: depending on the respective workflow, in particular master and contact data (name, email address) and business data.

(4) Legal basis: where we use these platforms for our own purposes, Art. 6(1)(b) GDPR. In customer projects we process personal data as a processor; the legal basis is determined by the customer as controller (section 8.17).

8.7 Microsoft Outlook and Microsoft Teams

Provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.

Purpose: Email communication (Microsoft Outlook), video conferencing, chat and collaboration (Microsoft Teams).

Data processed: name, email address, communication content, appointment details, IP address, device and browser information.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in efficient business communication).

Microsoft is certified under the EU-US Data Privacy Framework. We have concluded a data processing agreement with Microsoft pursuant to Art. 28 GDPR (Microsoft Products and Services Data Protection Addendum).

8.8 Zoom

Provider: Zoom Video Communications, Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA.

Purpose: Holding video conferences and online meetings with customers and business partners.

Data processed: name, email address, IP address, device and browser information, where applicable audio/video data during the conference.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract).

Zoom is certified under the EU-US Data Privacy Framework. Further information on data protection at Zoom can be found at: https://explore.zoom.us/de/privacy/

8.9 Appointment booking (initial consultation)

Purpose: Via the booking form on our Website you can choose an appointment for an initial consultation. The booking is operated by us; no external booking service is used.

Data processed: name, email address, telephone number, company (optional), chosen appointment, request (free text), confirmation of entrepreneur status, time of booking.

Recipients: The appointment is entered in Google Calendar (section 8.1), the booking is stored in our database (Supabase, section 11a) and created as a contact in Pipedrive (section 8.13). You receive confirmation and reminder by email (section 8.10).

Legal basis: Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract).

Retention period: 12 months after the appointment, provided no business relationship has been established (section 3.2). To protect against misuse, the IP address is held in memory for a maximum of 120 seconds.

8.10 Email and SMS communication

Email: For business email communication we use Google Workspace (Gmail) and Microsoft Outlook (cf. sections 8.1 and 8.7).

System emails: Automatic emails (confirmations, reminders, result of the Automation Check, portal invitations) are sent via an SMTP delivery service within the EU.

SMS: No SMS messages are currently sent.

Purpose: Business communication, appointment confirmations, project-related correspondence.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract).

8.11 Payment processing (Stripe)

Provider: Stripe Technology Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland.

Purpose: We use Stripe for the secure processing of online payments. If you make a payment via our Website, your payment data is processed directly by Stripe.

Data processed: payment data (credit card number, IBAN), name, email address, IP address, transaction amount and details.

Data sharing: Your payment data is transmitted directly to Stripe and processed by Stripe in accordance with their privacy policy. Sophera Consulting does not store complete credit card or account details.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract). The processing is necessary in order to carry out the payment.

Retention period: Transaction data is stored for the duration of the statutory retention periods (10 years pursuant to HGB/AO).

Stripe is certified under the EU-US Data Privacy Framework. Details: stripe.com/de/privacy

8.12 Accounting (Lexoffice / Lexware)

Provider: Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg, Germany (address as of 2026).

Purpose: We use Lexoffice for accounting, invoicing and customer management. If you place an order or make a payment, your data is automatically created in Lexoffice as a contact and, where applicable, as an invoice.

Data processed: first and last name, email address, telephone number, customer number (assigned automatically), invoice amounts, project designation, payment status, invoice date.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) as well as Art. 6(1)(c) GDPR (compliance with statutory accounting obligations pursuant to HGB/AO).

Retention period: Invoice data is stored for the duration of the statutory retention periods (10 years pursuant to § 147 AO, § 257 HGB).

Lexware is a German company based in Freiburg. Data processing takes place exclusively in Germany or the EU.

8.13 Customer relationship management / CRM (Pipedrive)

Provider: Pipedrive OÜ, Mustamäe tee 3a, 10615 Tallinn, Estonia (EU company, address as of 2026).

Purpose: We use Pipedrive as a CRM system to manage customer relationships and sales processes. If you get in touch with us — e.g. via the Automation Check, an appointment booking or a payment — your data is automatically recorded in Pipedrive as a contact and, where applicable, as a deal.

Data processed: first and last name, email address, telephone number, type of enquiry (booking, Automation Check, payment), project designation, where applicable automation potential and estimated saving, deal status and value.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract and steps taken prior to entering into a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in efficient customer relationship management).

Retention period: Contact and deal data is stored for the duration of the business relationship and deleted after it ends in accordance with the statutory retention periods.

Pipedrive is an EU company based in Estonia. The data is processed on servers within the EU. Pipedrive is certified to SOC 2 Type II.

8.14 Data linkage between systems

In order to handle our business processes efficiently, the systems named above are linked with one another. Below we provide transparent information about the data flow:

  • Website → Supabase: Your contact and booking data is stored in our database (Supabase, EU servers).
  • Supabase → Lexoffice: When an order is placed or a payment is made, contact data and invoicing information is transmitted automatically to Lexoffice in order to create invoices and comply with accounting obligations.
  • Supabase → Pipedrive: Contact data and project information is recorded automatically in Pipedrive as a customer relationship in order to ensure efficient support.
  • Stripe → Supabase / Lexoffice: Payment confirmations are transmitted by Stripe to our systems in order to finalise invoices and update the payment status.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(c) GDPR (statutory accounting obligations) as well as Art. 6(1)(f) GDPR (legitimate interest in efficient business processes).

Synchronisation frequency: Data synchronisation between the systems takes place in real time (event-based via webhooks). When a record is created or changed in one system, the information is automatically passed on to the linked systems.

Bidirectionality: The data flows are partly bidirectional:

  • Pipedrive ↔ Supabase: lead data and deal status are synchronised in both directions
  • Stripe → Supabase: payment status is transmitted one-way from Stripe to Supabase (webhook)
  • Lexoffice ↔ Supabase: customer numbers and invoice IDs are synchronised

Erasure: If a record is erased at the request of the data subject, the erasure is carried out in all linked systems. The request can be addressed to fey@sopheraconsulting.de.

All data transfers are encrypted (TLS/HTTPS). We have concluded data processing agreements (DPAs) pursuant to Art. 28 GDPR with all service providers, insofar as required. All services used process data within the EU or are certified under the EU-US Data Privacy Framework.

8.15 Telephony (Placetel)

Provider: Placetel GmbH, Brüsseler Straße 1, 50674 Köln, Germany (a company of NFON AG).

Purpose: Cloud telephone system for business voice communication (incoming and outgoing calls, voicemail, call distribution).

Data processed: telephone numbers (our own and those of the calling person), time of the call, call duration, connection data, where applicable voicemail recordings.

Server location: Germany. No transfer of data to third countries.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract and steps taken prior to entering into a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in efficient business communication).

Retention period: Connection data for a maximum of 7 days (§ 9 TDDDG), unless required for longer for billing purposes. We create call recordings only with the express prior consent of all participants (§ 201 StGB) and delete them without undue delay on request.

Data processing: A data processing agreement pursuant to Art. 28 GDPR has been concluded with Placetel. Further information: placetel.de/datenschutz

8.16 Cloud infrastructure for customer projects

(1) To provide our services to customers, we use cloud infrastructure from one or more of the providers named below. This processing does not concern the operation of this Website. Sections 8.16 to 8.19 are advance information about the services that may be used in customer projects. Which of them are actually used in a project is conclusively determined by the data processing agreement with the respective customer; a service not named there is not used for that customer’s personal data.

(2) Providers whose parent company has its registered office in the United States of America:

  • Amazon Web Services (AWS) – Recipient: Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg. Parent company: Amazon.com, Inc., USA (participant in the EU-US Data Privacy Framework). Place of processing: including region eu-central-1 (Frankfurt am Main) and AWS European Sovereign Cloud (Brandenburg). Certifications: BSI C5 attestation.
  • Microsoft Azure – Recipient: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Parent company: Microsoft Corporation, USA (participant in the EU-US Data Privacy Framework). Place of processing: regions Germany West Central (Frankfurt am Main) and Germany North (Berlin), EU Data Boundary. Certifications: BSI C5 attestation.
  • Google Cloud – Recipient: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland. Parent company: Google LLC, USA (participant in the EU-US Data Privacy Framework). Place of processing: regions europe-west3 (Frankfurt am Main) and europe-west10 (Berlin). Certifications: BSI C5 attestation.
  • Oracle Cloud Infrastructure – Recipient: ORACLE Deutschland B.V. & Co. KG, Riesstraße 25, 80992 Munich, Germany. Parent company: Oracle America, Inc., USA (participant in the EU-US Data Privacy Framework). Place of processing: region eu-frankfurt-1 and Oracle EU Sovereign Cloud (Frankfurt am Main). Certifications: BSI C5 attestation.
  • IBM Cloud – Recipient: International Business Machines Corporation, USA, represented in Germany by IBM Deutschland GmbH, Ehningen. Parent company: International Business Machines Corporation, USA (participant in the EU-US Data Privacy Framework). Place of processing: region eu-de (Frankfurt am Main). Certifications: BSI C5 attestation, ISO/IEC 27001.

(3) Providers established in the European Union; no transfer to third countries takes place by the provider itself:

  • STACKIT – Recipient: Schwarz Digits Cloud GmbH & Co. KG, Am Campus 1, 74177 Bad Friedrichshall, Germany. Place of processing: data centres in the Federal Republic of Germany and the Republic of Austria. Certifications: BSI C5 attestation (Type 2), ISO/IEC 27001.
  • T Cloud Public (formerly Open Telekom Cloud) – Recipient: T-Systems International GmbH (Deutsche Telekom). Place of processing: data centres in Magdeburg/Biere and Amsterdam. Certifications: BSI C5 attestation (Type 2), ISO/IEC 27001.
  • IONOS Cloud – Recipient: IONOS Cloud GmbH, Elgendorfer Straße 57, 56410 Montabaur, Germany. Place of processing: data centres including Frankfurt am Main, Berlin and Karlsruhe. Certifications: BSI C5 attestation (Type 1), ISO/IEC 27001 based on IT-Grundschutz.
  • OVHcloud – Recipient: OVH GmbH, St. Johanner Straße 41–43, 66111 Saarbrücken, Germany (parent company: OVH SAS, Roubaix, France). Place of processing: Frankfurt am Main region, Limburg data centre. Certifications: BSI C5 attestation.
  • Hetzner – Recipient: Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. Place of processing: data centres in Nuremberg, Falkenstein and Helsinki. Certifications: ISO/IEC 27001, BSI C5 attestation (Type 2).

(4) We choose regions within the European Union only, preferably in the Federal Republic of Germany. Should a technical requirement exceptionally not permit a region within the European Union, we inform the customers concerned separately prior to use. For providers whose parent company has its registered office in the United States of America, access by public authorities under the law of the United States cannot be entirely ruled out even where processing takes place in a region within the European Union. To that extent, the transfer is based on Art. 45 GDPR in conjunction with the adequacy decision on the EU-US Data Privacy Framework and additionally on standard contractual clauses pursuant to Art. 46(2)(c) GDPR; see section 11. Where this is material to the customer, we use providers established in the European Union.

(5) Legal basis: where we use the infrastructure for our own purposes, Art. 6(1)(b) and (f) GDPR; our legitimate interest lies in operating a secure and scalable infrastructure. In customer projects we process personal data as a processor; the legal basis is determined by the customer as controller (section 8.17).

(6) Data processing agreements pursuant to Art. 28(3) GDPR are in place with the providers used, including the AWS Data Processing Addendum, the Microsoft Products and Services Data Protection Addendum, the Google Cloud Data Processing Addendum and the data processing agreements of IONOS, STACKIT and Hetzner. The information on places of processing and certifications is based on the providers’ documentation (as of 2026); section 8.20(3) applies.

8.17 Processing on behalf of our customers and blueprints

Processing on behalf: In customer projects, the respective customer is the controller of the personal data from its systems. We process this data as a processor exclusively on the customer’s instructions and on the basis of the data processing agreement concluded with the customer (Art. 28 GDPR; for church customers correspondingly Section 29 KDG or Section 30 DSG-EKD). The customer fulfils the information obligations towards the data subjects; this privacy policy does not govern such processing.

Blueprints: From the AI systems and automations we create, we derive reusable templates (e.g. architectures, process models, templates for prompts and rule sets, code modules). These blueprints contain no personal data. We do not use personal data from customer projects for blueprints or for any other purposes of our own.

Healthcare clients: for hospitals, care facilities and other healthcare institutions, we process health data (Art. 9 GDPR) only on the basis of the data processing agreement, only as far as necessary for the agreed purpose and only through the sub-processors named there. Processing takes place in the EU; we operate AI models via EU regions, e.g. Amazon Bedrock with an EU profile. According to AWS, the model developer receives no data, and the data is not used for training. We and the persons we engage are bound to secrecy under § 203 German Criminal Code (StGB). After the end of the contract we return or delete the data and confirm deletion with a log. Details are set out in § 20 of our GTC.

8.18 AI models via application programming interfaces (API) in customer projects

(1) Within customer projects we use AI models via the application programming interfaces of the providers named below. Which providers are used in the individual case is determined by the offer or the data processing agreement. Access primarily takes place via Amazon Bedrock using the EU profile.

(2) Recipients, legal basis for transfer, place of processing and use for training purposes:

  • Amazon Bedrock (including Claude, Amazon Nova, Llama, Mistral) – Recipient: Amazon Web Services EMEA SARL, Luxembourg; parent company Amazon.com, Inc., USA. Legal basis for transfer: Art. 45 GDPR in conjunction with the adequacy decision on the EU-US Data Privacy Framework, additionally standard contractual clauses pursuant to Art. 46(2)(c) GDPR. Place of processing: regions within the European Union, when using the EU profile exclusively between them. Inputs and outputs are neither used for training purposes nor shared with the model developers; the retention period is configurable down to no storage at all.
  • Anthropic (Claude) – Recipient: Anthropic Ireland, Limited, Dublin, Ireland; processing by Anthropic, PBC, USA. Legal basis for transfer: standard contractual clauses pursuant to Art. 46(2)(c) GDPR; there is no participation in the EU-US Data Privacy Framework. Place of processing: United States of America; the direct interface offers no processing within the European Union, which is why in customer projects we primarily use Claude via Amazon Bedrock or Google Vertex AI in regions within the European Union. No use for training purposes; retention up to 30 days, on request without storage (zero data retention).
  • OpenAI (GPT) – Recipient: OpenAI Ireland Ltd, Dublin, Ireland; processing by OpenAI, USA. Legal basis for transfer: standard contractual clauses pursuant to Art. 46(2)(c) GDPR; there is no participation in the EU-US Data Privacy Framework. Place of processing: European Economic Area when using EU data residency, which we use primarily. No use for training purposes without consent; abuse monitoring logs up to 30 days, on request without storage.
  • Google (Gemini API, Vertex AI) – Recipient: Google Cloud EMEA Limited, Dublin, Ireland; parent company Google LLC, USA. Legal basis for transfer: Art. 45 GDPR in conjunction with the adequacy decision on the EU-US Data Privacy Framework. Place of processing: regional endpoints within the European Union. In paid use there is no use for training purposes; a configuration without storage is possible.
  • Microsoft (Azure OpenAI, Azure AI Foundry) – Recipient: Microsoft Ireland Operations Limited, Dublin, Ireland; parent company Microsoft Corporation, USA. Legal basis for transfer: Art. 45 GDPR in conjunction with the adequacy decision on the EU-US Data Privacy Framework, additionally standard contractual clauses pursuant to Art. 46(2)(c) GDPR. Place of processing: EU data zone with processing exclusively in member states of the European Union. No use for training purposes.
  • Mistral AI – Recipient: Mistral AI SAS, 15 rue des Halles, 75001 Paris, France. Legal basis for transfer: not required (established in the European Union). Place of processing: within the European Union by default. In paid use there is no use for training purposes; on request without storage.
  • Aleph Alpha (PhariaAI) – Recipient: Aleph Alpha GmbH, Speyerer Straße 14, 69115 Heidelberg, Germany. Legal basis for transfer: not required (established in the European Union). Place of processing: operated on STACKIT within the European Union.
  • Cohere – Recipient: Cohere Inc., 171 John St, Suite 200, Toronto, Canada. Legal basis for transfer: Art. 45 GDPR in conjunction with the European Commission’s adequacy decision for Canada, additionally standard contractual clauses pursuant to Art. 46(2)(c) GDPR. Place of processing: Canada. Use for training purposes is enabled by default at the provider; we use Cohere exclusively with training use deactivated.
  • Perplexity (Sonar) – Recipient: Perplexity AI, Inc., San Francisco, USA. Legal basis for transfer: Art. 45 GDPR in conjunction with the adequacy decision on the EU-US Data Privacy Framework, additionally standard contractual clauses pursuant to Art. 46(2)(c) GDPR. Place of processing: United States of America. Use for training purposes is contractually excluded. The service is used primarily for research purposes.
  • xAI (Grok) – Recipient: SpaceXAI LLC, USA. Legal basis for transfer: standard contractual clauses pursuant to Art. 46(2)(c) GDPR; there is no participation in the EU-US Data Privacy Framework. Place of processing: United States of America; processing within the European Union is not offered. The service is used exclusively on the basis of a separate agreement and not for personal data from our customers’ systems.
  • DeepL (translation) – Recipient: DeepL SE, Maarweg 165, 50825 Cologne, Germany. Legal basis for transfer: for the sub-processor AWS: Art. 45 GDPR in conjunction with the adequacy decision on the EU-US Data Privacy Framework, additionally standard contractual clauses pursuant to Art. 46(2)(c) GDPR. Place of processing: according to DeepL, depending on the plan also outside the European Union; where the plan permits, we choose the region within the European Union. In paid use texts are neither stored nor used for training purposes.
  • ElevenLabs (speech synthesis) – Recipient: Eleven Labs Inc., 169 Madison Ave #2484, New York, NY 10016, USA. Legal basis for transfer: Art. 45 GDPR in conjunction with the adequacy decision on the EU-US Data Privacy Framework, additionally standard contractual clauses pursuant to Art. 46(2)(c) GDPR. Place of processing: United States of America; EU data residency exclusively in the Enterprise plan. Use for training purposes is enabled by default below the Enterprise plan; we deactivate it and, where available, use the zero retention mode.
  • Black Forest Labs (FLUX, image generation) – Recipient: BFL GmbH, Ingeborg-Krummer-Schroth-Straße 18, 79106 Freiburg im Breisgau, Germany. Legal basis for transfer: not required (established in the European Union). Place of processing: EU endpoint with processing in regions within the European Union. The provider’s terms provide for use for training purposes; we use the service exclusively for content without personal reference.
  • AssemblyAI (speech recognition) – Recipient: AssemblyAI, Inc., USA. Legal basis for transfer: Art. 45 GDPR in conjunction with the adequacy decision on the EU-US Data Privacy Framework. Place of processing: EU endpoint. When processing on EU servers there is no use for training purposes; according to the provider, audio data is deleted after 24 to 48 hours and transcripts after 30 days.

(3) The above information is based on the documentation and contractual commitments of the respective providers (as of 2026); section 8.20(3) applies.

(4) Legal basis: where we use the interfaces for our own purposes, Art. 6(1)(b) GDPR. In customer projects we process personal data as a processor; the legal basis is determined by the customer as controller (section 8.17). For transfers to third countries, see section 11.

8.19 Self-operated AI models (locally, at the customer or in a region within the European Union)

(1) Where processing is to take place exclusively on the customer’s premises or within the European Union, we use AI models with freely available model weights (open-weight models) which we operate ourselves, namely on our own hardware, on the customer’s servers or in a region within the European Union of one of the providers named in section 8.16. Inputs and outputs are processed exclusively in that environment. According to our state of knowledge and the developers’ information, there is neither a transfer of personal data to the developer of the model nor a transfer to third countries caused by the model.

(2) Depending on the project, the following model families in particular are used:

  • Meta Llama (United States of America) – Llama Community License
  • Mistral AI, including Mistral Small and Mistral Large 3 (France) – Apache License 2.0
  • Google Gemma 4 (United States of America) – Apache License 2.0
  • OpenAI gpt-oss (United States of America) – Apache License 2.0
  • Microsoft Phi (United States of America) – MIT License
  • IBM Granite (United States of America) – Apache License 2.0
  • Alibaba Qwen (People’s Republic of China) – Apache License 2.0 or the developer’s licence, depending on the model
  • DeepSeek (People’s Republic of China) – MIT License
  • Moonshot AI Kimi (People’s Republic of China) – the developer’s licence

(3) We use models from developers established in the People’s Republic of China exclusively in the form of downloaded model weights in a closed environment; we do not use these developers’ applications or application programming interfaces. According to our state of knowledge, no personal data is transferred to the People’s Republic of China in this context.

(4) We use Ollama, vLLM, llama.cpp or LM Studio as runtime environments. Functions for collecting usage statistics and telemetry data are deactivated. We obtain model weights exclusively from the developers’ official sources and verify their integrity.

(5) Legal basis: where we use the models for our own purposes, Art. 6(1)(b) GDPR. In customer projects we process personal data as a processor; the legal basis is determined by the customer as controller (section 8.17).

8.20 Principles for the use of artificial intelligence in customer projects

(1) The following principles apply to all AI systems which we build and operate for customers:

  • Data minimisation and purpose limitation (Art. 5(1)(b) and (c) GDPR): Only the personal data required for the agreed purpose is processed; where the purpose allows, it is pseudonymised (Art. 4(5) GDPR) or anonymised.
  • Priority of processing within the European Union: We choose the providers’ regions and processing options within the European Union. Where processing exclusively at the customer is required, we use self-operated models (section 8.19).
  • Exclusion of use for training purposes: We only use application programming interfaces and enterprise variants for which, according to the providers’ commitments, inputs and outputs are not used to train AI models. We do not use freely available consumer products for our customers’ personal data.
  • Storage limitation (Art. 5(1)(e) GDPR): Where available, we use variants without storage at the provider (zero data retention); otherwise the retention period provided by the provider for abuse detection applies.
  • Access restriction: Access to the customer’s systems is read-only unless the engagement provides otherwise. Credentials are managed separately per customer and kept in the cloud providers’ key management services; for the separation of processing environments according to the level of protection required, see section 12.
  • No automated individual decision-making (Art. 22 GDPR): Our systems do not make decisions which produce legal effects concerning data subjects or similarly significantly affect them. The systems’ outputs are notices; the decision is made by a human.
  • Knowledge bases (Retrieval Augmented Generation): Vector databases and document stores are operated at the customer or within the European Union. Access rights are inherited from the source systems; deletions in the source systems are replicated.
  • Logging: Logs contain personal data only to the extent necessary and are retained only as long as required for operation, error analysis and evidence purposes; the period is determined by the data processing agreement.
  • Transparency: The sub-processors used are named in the offer or the data processing agreement; intended changes are notified in advance (Art. 28(2) sentence 2 GDPR).
  • Data protection impact assessment and AI Act: We support our customers in carrying out a data protection impact assessment (Art. 35 GDPR) and in the classification under Regulation (EU) 2024/1689 (AI Act).

(2) We follow the guidance of the Conference of the Independent Data Protection Supervisory Authorities of the Federation and the Federal States (DSK) on “Artificial Intelligence and Data Protection” (May 2024), on technical and organisational measures for AI systems (June 2025) and on Retrieval Augmented Generation (October 2025), as well as Opinion 28/2024 of the European Data Protection Board on AI models.

(3) Information on data flows, places of processing, retention periods and use for training purposes is based on the documentation and contractual commitments of the respective providers and developers and on our state of knowledge at the time of publication. Details are set out in our terms and conditions (§ 6(8)).

9. Online marketing and advertising

Sophera Consulting uses various online marketing tools in order to increase the visibility of its own services and to approach potential customers. Below we provide information about the services used.

9.1 Google Search Console

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Purpose: Analysis of the visibility of our Website in Google Search and technical SEO optimisation.

Data processed: search queries (exclusively aggregated), click data, impressions. No personal data of Website visitors is transmitted to us. The data is fully anonymised and serves exclusively technical optimisation.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in optimising our web presence).

9.2 Google Ads

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Purpose: Placement of paid search ads and conversion tracking to measure advertising effectiveness.

Data processed: IP address (truncated), cookie ID, conversion data (e.g. whether an enquiry was made via an ad).

Consent: The use of Google Ads conversion tracking requires your prior consent pursuant to § 25(1) TDDDG. Conversion tracking is only activated after your express consent via the cookie banner.

Legal basis: Art. 6(1)(a) GDPR (consent).

Opt-out: You can deactivate personalised advertising in the Google Ads settings: https://adssettings.google.com

9.3 Meta Ads (Facebook, Instagram) and Meta apps

Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

Purpose: Placement of advertisements on Facebook, Instagram, Messenger and WhatsApp. Where applicable, use of Custom Audiences to address relevant target groups.

Data processed: usage data, interaction data, where applicable data from Custom Audience lists.

Consent: The use of Meta tracking technologies (e.g. Meta Pixel) requires your prior consent. Tracking is only activated after consent has been given via the cookie banner.

Legal basis: Art. 6(1)(a) GDPR (consent).

Joint controllership: Insofar as we operate a Facebook company page (fan page), joint controllership pursuant to Art. 26 GDPR exists between us and Meta Platforms Ireland Limited. For this purpose Meta provides what are known as Page Insights addenda, in which the respective responsibilities are set out. This is based on the case law of the CJEU (judgment of 05.06.2018 – C-210/16).

Further information on data protection at Meta can be found at: https://www.facebook.com/privacy/policy

9.4 LinkedIn and LinkedIn Ads

Provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.

Purpose: B2B marketing, placement of advertisements and lead generation on the LinkedIn platform.

Data processed: profile visits, interaction data, where applicable data from lead gen forms (name, email address, position, company).

Consent: The use of LinkedIn tracking technologies (e.g. LinkedIn Insight Tag) requires your prior consent. Tracking is only activated after consent has been given via the cookie banner.

Legal basis: Art. 6(1)(a) GDPR (consent).

Joint controllership: For our LinkedIn company page, joint controllership pursuant to Art. 26 GDPR exists between us and LinkedIn Ireland Unlimited Company.

Contact via LinkedIn: We also use LinkedIn to send connection requests and messages to decision-makers in companies. In doing so, we process the professional data provided in your public profile (name, position, company). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in approaching potential business customers). You can object to this processing at any time (section 4.6).

9.5 General note on advertising tracking

All marketing cookies and tracking pixels (e.g. Google Ads conversion tracking, Meta Pixel, LinkedIn Insight Tag) are activated on this Website only after your express consent via the cookie banner. Without your consent, no advertising tracking takes place.

You can adjust your cookie settings or withdraw your consent at any time via the cookie banner. In addition, the following opt-out options are available to you:

9.6 IndexNow (Bing/Google indexing)

Provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA (for Bing).

Purpose: IndexNow is an open protocol with which we automatically inform search engines about new or updated content on our Website. This accelerates indexing at Bing, Yandex, DuckDuckGo and other IndexNow-capable search engines.

Data processed: exclusively URLs of our public Website content. No personal data is transmitted.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in efficient indexing of our content in search engines).

10. Disclosure of data to third parties

Your personal data is disclosed to third parties exclusively in the following cases:

  • Vercel Inc. (hosting, cf. section 5.1) – data processing pursuant to Art. 28 GDPR
  • Anthropic Ireland, Limited (AI analysis, cf. sections 7.2 and 8.3) – exclusively process descriptions within the scope of the Automation Check; for customer projects only within the scope of the project assignment
  • OpenAI Ireland Ltd (AI services, cf. section 8.4) – processing within the scope of customer projects
  • Google Ireland Limited (Google Workspace, Google AI, Google Ads, Google Search Console, cf. sections 8.1, 8.2, 9.1 and 9.2)
  • Microsoft Ireland Operations Limited (Outlook, Teams, cf. section 8.7)
  • Apple Distribution International Limited (iCloud, calendar and contacts, cf. section 8.1b)
  • Zoom Video Communications, Inc. (video conferencing, cf. section 8.8)
  • Clay Inc. (lead research, cf. section 8.5)
  • Meta Platforms Ireland Limited (advertisements, cf. section 9.3)
  • LinkedIn Ireland Unlimited Company (advertisements, cf. section 9.4)
  • SMTP service provider (email delivery)
  • Supabase Inc. (database, server location: Frankfurt/Germany) — data processing pursuant to Art. 28 GDPR
  • Vercel Speed Insights (anonymised performance measurement, no persistent storage of personal data)
  • Stripe Technology Europe Limited (payment processing, cf. section 8.11)
  • Haufe-Lexware GmbH & Co. KG (accounting, cf. section 8.12) – data processing pursuant to Art. 28 GDPR
  • Pipedrive OÜ (CRM, cf. section 8.13) – data processing pursuant to Art. 28 GDPR
  • Placetel GmbH (telephony, cf. section 8.15) – data processing pursuant to Art. 28 GDPR
  • Funding partners (cf. section 7.5) – only with your consent
  • Cloud and AI providers in customer projects (cf. sections 8.16 to 8.19) – only the sub-processors named in the respective data processing agreement

Beyond this, no data is disclosed to third parties unless we are legally obliged to do so (e.g. disclosure to law enforcement authorities under § 24 BDSG) or you have expressly consented.

11. Transfer of data to third countries

Within the scope of the processing operations described in this Privacy Policy, personal data is transferred to companies in the United States of America. This concerns in particular the following service providers:

  • Vercel Inc. (hosting) – DPF-certified
  • Anthropic, PBC (AI services, contracting entity Anthropic Ireland, Limited) – safeguarded by EU Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR
  • OpenAI, L.L.C. (AI services, contracting entity OpenAI Ireland Ltd) – safeguarded by EU Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR
  • Supabase Inc. (database, server location Frankfurt; possible support access from the USA, cf. section 11a) – safeguarded by EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR as part of the Supabase Data Processing Addendum
  • Google Ireland Limited (Google group, data transfer to Google LLC, USA) – DPF-certified
  • Microsoft Ireland Operations Limited (data transfer to Microsoft Corp., USA) – DPF-certified, additionally EU Standard Contractual Clauses
  • Zoom Video Communications, Inc. (video conferencing) – DPF-certified
  • Apple Inc. (iCloud, data transfer from Apple Distribution International Limited to the parent company, cf. section 8.1b) – DPF-certified
  • Clay Inc. (lead research) – safeguarded by EU standard contractual clauses pursuant to Art. 46(2)(c) GDPR
  • Meta Platforms, Inc. (parent company, USA) – DPF-certified
  • LinkedIn Corporation (parent company, USA) – DPF-certified
  • Amazon Web Services EMEA SARL, Luxembourg (cloud infrastructure for customer projects, cf. section 8.16 — data transfer to Amazon Web Services Inc., USA) – DPF-certified, additionally safeguarded by EU standard contractual clauses pursuant to Art. 46(2)(c) GDPR
  • Oracle America, Inc. (cloud infrastructure, see section 8.16) – DPF certified
  • International Business Machines Corporation (cloud infrastructure, see section 8.16) – DPF certified
  • Celonis, Inc. (Make, see section 8.6) – DPF certified, additionally EU Standard Contractual Clauses
  • Zapier, Inc. (workflow automation, see section 8.6) – DPF certified, additionally EU Standard Contractual Clauses
  • Perplexity AI, Inc. (AI services, see section 8.18) – DPF certified, additionally EU Standard Contractual Clauses
  • Eleven Labs Inc. (speech synthesis, see section 8.18) – DPF certified, additionally EU Standard Contractual Clauses
  • AssemblyAI, Inc. (speech recognition, see section 8.18) – DPF certified
  • SpaceXAI LLC (xAI, see section 8.18) – safeguarded by EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR
  • Cohere Inc., Canada (AI services, see section 8.18) – European Commission adequacy decision for Canada, additionally EU Standard Contractual Clauses

On 10 July 2023, the European Commission adopted the adequacy decision for the EU-US Data Privacy Framework (DPF) pursuant to Art. 45 GDPR. On this basis, an adequate level of data protection is ensured for data transfers to the DPF-certified companies.

Should the adequacy decision for the DPF cease to be valid, we will without undue delay ensure appropriate safeguards pursuant to Art. 46 GDPR (in particular EU standard contractual clauses) or discontinue the data transfer.

11a. Data storage (Supabase)

For the storage of contact data, appointment bookings and configurator enquiries we use the database service Supabase (Supabase Inc., USA). The database is operated in the Frankfurt, Germany (eu-central-1) region; the stored data is therefore located within the EU. Access by Supabase Inc. from the USA (for example in the course of support or maintenance) cannot be completely ruled out; the safeguards described in section 11 apply in this respect.

Data stored: name, email address, telephone number, company (optional), appointment booking data, process descriptions and analysis results from the Automation Check.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract) and Art. 6(1)(f) GDPR (legitimate interest in the efficient management of customer enquiries).

Retention period: Contact data is stored for as long as a business relationship exists or statutory retention periods apply. You can request the erasure of your data at any time.

Data processing: We have concluded a data processing agreement (DPA) with Supabase pursuant to Art. 28 GDPR. The DPA is available at: https://supabase.com/dpa. Although Supabase is a US company, the data is processed and stored exclusively on servers in Frankfurt/Germany.

11b. Vercel Analytics (website analysis)

We use Vercel Analytics, a privacy-friendly analytics service provided by Vercel Inc. (USA), to evaluate Website usage. Vercel Analytics works without cookies and without fingerprinting. The IP address is processed technically when the page is called up but is not stored; the evaluation takes place exclusively on the basis of aggregated, anonymised data.

Data collected: page views, referrer (where visitors come from), device type, country (estimated, without storing IP addresses) — fully anonymised.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in analysing Website usage for optimisation purposes). As no information is stored on or read from your terminal device, consent under § 25 TDDDG is not required.

11c. Vercel Speed Insights (performance measurement)

We use Vercel Speed Insights, a service provided by Vercel Inc. (USA), for the anonymised measurement of Website performance (Core Web Vitals). Only technical performance data is collected — no cookies, no tracking, no persistent storage of personal data.

Data collected: loading times (LCP, FID, CLS), device type (desktop/mobile), connection speed — fully anonymised, without IP addresses or user identification.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the technical optimisation of the Website). As no information is stored on or read from your terminal device, consent under § 25 TDDDG is not required.

12. Data security

We use appropriate technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or against unauthorised access by third parties. Our security measures include in particular:

  • End-to-end TLS encryption of all data traffic
  • Server-side honeypot techniques and IP-based rate limiting to protect against misuse
  • Validation and filtering of all user input at server level
  • No persistent storage of IP addresses beyond the duration of the rate limiting
  • Use of up-to-date frameworks and regular updates of software components
  • Encryption of stored data in the cloud services used
  • Multi-factor authentication for administrative access
  • Role-based access rights following the principle of least privilege
  • Separation of processing environments according to the level of protection required for the data: development and testing generally take place in our own working environment (locally or in our cloud account) using synthetic, anonymised or pseudonymised data. Personal data requiring an increased level of protection, in particular special categories of personal data (Art. 9(1) GDPR), is processed by us exclusively in the respective customer’s environment or in an environment set up separately for that customer; the system is transferred there upon completion of development. Deviations, such as calling AI models via our cloud account until acceptance, take place only insofar as agreed in the data processing agreement. Credentials are managed separately per customer.
  • Management of keys and credentials in dedicated services (e.g. AWS KMS, AWS Secrets Manager), not in program code
  • Process for personal data breaches: prompt notification of our customers as controllers; our own notifications to the supervisory authority within 72 hours (Art. 33 GDPR)
  • Regular review of the effectiveness of the measures (Art. 32(1)(d) GDPR)

13. Validity and amendment of this Privacy Policy

This Privacy Policy reflects the status as of 1 June 2026. Due to the further development of our Website and our services, or due to changed statutory or regulatory requirements, it may become necessary to amend this Privacy Policy. The current version can be accessed at any time at sopheraconsulting.de/datenschutz.

14. AI transparency (Art. 50 EU AI Act)

Since 2 August 2026, the transparency obligations of Art. 50 of Regulation (EU) 2024/1689 (the “EU AI Act”) have applied. We use AI at the following points and make this apparent in each case:

a) Automation Check (AI configurator). The Automation Check on our home page is carried out by an AI system (Anthropic Claude). You are not interacting with a human there. We point this out to you immediately at the beginning of the interaction. The assessment produced is AI-generated and labelled as such. Details on the data processing can be found in section 7 and on the automated evaluation in section 4.9.

b) Blog articles. The specialist articles in our blog are created with AI support. Every article concerned carries a visible notice as well as a machine-readable marking in the source code.

c) Meeting notes. Notes and summaries from video conferences are generated by Google Gemini (see section 8.1a) and labelled as AI-generated.

No emotion recognition, no biometric categorisation. We use systems within the meaning of Art. 50(3) EU AI Act neither on this Website nor in our customer communication. Likewise, we do not create deepfakes within the meaning of Art. 50(4) EU AI Act.

We answer questions about our use of AI at fey@sopheraconsulting.de.

If you have any questions about data protection, you can contact us at any time: fey@sopheraconsulting.de