Privacy Policy

1. Controller

Gosign GmbH
Hallerstraße 8
20146 Hamburg, Germany

Email: web26 [at] gosign.de

Data Protection Officer

A data protection officer is currently not appointed. Fewer than 20 employees are regularly involved in the automated processing of personal data (§ 38(1) of the German Federal Data Protection Act, BDSG). For questions regarding data protection, please contact the address stated above.

2. Overview

This website does not set any cookies. Neither first-party nor third-party. No client-side third-party trackers are loaded - no Google Analytics, no Matomo, no Facebook Pixel, no LinkedIn Insight Tag, and no Google Tag Manager. For reach and conversion measurement we operate our own cookieless, server-side system (see section 4).

No cookie banner is required, as no cookies or comparable technologies are stored on or read from your device (§ 25 TDDDG).

3. Hosting and Content Delivery

This website is served via Cloudflare Pages. Cloudflare acts as a data processor under Art. 28 GDPR. A Data Processing Addendum (DPA) with Standard Contractual Clauses (SCCs) is in place.

When delivering web pages, Cloudflare technically processes the IP address of the requesting device. Depending on the service, this processing may also take place outside the EU and is secured via the EU-US Data Privacy Framework as well as DPA/SCCs.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and performant website delivery).

4. Reach and Conversion Measurement

To analyse website usage and the effectiveness of our advertising, we operate our own cookieless measurement system (internally "Lyftyfy"), run by Gosign GmbH. No cookies are set and no client-side third-party trackers are loaded (no Google Analytics, no Google Tag Manager, no Facebook Pixel, no LinkedIn Insight Tag). Measurement is performed server-side and without persistent recognition of your device:

  • No persistent identifier is stored on your device. To group the page views of a single day, a daily-rotating session hash is derived from IP address, browser signature, and date; the IP address itself is not stored.
  • We collect page views, scroll depth, dwell time, clicks, and form/conversion events - in aggregated, pseudonymous form.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in analysing website usage and the effectiveness of our advertising).

Conversion measurement for advertising campaigns (Google Ads)

If you reach our website via a Google Ads ad, the requested URL contains a click parameter (gclid). If you subsequently complete an action (e.g. a form enquiry), we transmit a conversion event to Google server-side in order to measure the effectiveness of our campaigns. The click parameter, a cryptographically hashed (not human-readable) value of your email address or phone number, and the conversion value are transmitted. No cookie and no advertising tag is set in your browser. The recipient is Google Ireland Ltd. or Google LLC (USA); the transfer is secured via the data processing agreement (Art. 28 GDPR), the EU-US Data Privacy Framework, and Standard Contractual Clauses (see the section on data processing agreements).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in measuring and optimising our advertising).

You may object to this measurement at any time with effect for the future (Art. 21 GDPR). An informal message to the address stated under "Controller" is sufficient; we will then cease processing.

5. Contact Form and Email Contact

When you contact us via the contact form or by email, your details (e.g. name, email address, message text) are processed for the purpose of handling your inquiry and for any follow-up questions. This data is processed on the basis of Art. 6(1)(b) GDPR if your inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6(1)(f) GDPR).

Technical Processing via Cloudflare (Without Intermediate Storage)

To ensure secure and fast transmission of your form data, we use Cloudflare Workers technology from Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA for routing. Cloudflare acts exclusively as a technical intermediary. Your form data is not stored in a database by Cloudflare but is processed in memory and forwarded in real time via an encrypted connection (TCP socket) to our email server. Once the data has been transmitted, it does not remain on Cloudflare's servers.

Email Hosting via Google Workspace (EU Hosting)

For receiving, storing, and sending our emails, we use Google Workspace from Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland. We have configured Google Workspace so that our email data is physically stored on servers within the European Union (EU).

Data Processing Agreements and Third-Country Transfers

We have entered into data processing agreements (DPAs) pursuant to Art. 28 GDPR with both Cloudflare and Google. As both providers are part of US corporations, a theoretical data transfer to the USA during maintenance, routing (Cloudflare), or support cases cannot be 100 % excluded. For such cases, the providers rely on the adequacy decision of the EU Commission (EU-US Data Privacy Framework) as well as Standard Contractual Clauses to ensure an adequate level of data protection.

Retention Period

The data you enter in the contact form remains in our email inbox until you request deletion, revoke your consent to storage, or the purpose for data storage no longer applies (e.g. after your inquiry has been fully processed). Mandatory statutory provisions, in particular commercial and tax retention periods (up to 10 years under § 257 HGB and § 147 AO), remain unaffected.

6. Newsletter

When you subscribe to our newsletter, we process your email address for the purpose of regularly sending information about our services, articles and events.

Double Opt-In

Registration uses a double opt-in procedure: after entering your email address, you will receive a confirmation email with a unique link. Your address is only added to the mailing list after you click this link. The confirmation link is valid for 7 days.

Services Used

The newsletter is sent via a Cloudflare Worker (provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). Your email address is stored in Cloudflare KV (key-value store). We have concluded a Data Processing Agreement (DPA) with Cloudflare pursuant to Art. 28 GDPR. Emails are sent via SMTP (currently through a third-party mail server).

Legal Basis

Art. 6(1)(a) GDPR (consent). You may revoke your consent at any time by unsubscribing via the link in every newsletter email or by contacting us at datenschutz@gosign.de.

Retention Period

Your email address is stored until you unsubscribe from the newsletter. After unsubscribing, the address is deleted without undue delay, unless statutory retention obligations apply.

7. 203-Readiness-Check

On our German-language pages we offer the 203-Readiness-Check, a voluntary self-assessment on the use of AI for professionals bound by professional secrecy under § 203 of the German Criminal Code (StGB). Your answers in the self-check are neither stored nor transmitted - the assessment runs entirely in your browser, and the result appears directly on the page without any email entry.

Results Report by Email (Optional)

Only if you voluntarily request the detailed results report by email do we process your email address, your professional group, and the level recommended for you - not your answers. The request is confirmed via the same double opt-in procedure as the newsletter (section 6): you receive a confirmation email with a unique link, and the report is only delivered after you click this link. Delivery is handled by our email service provider Brevo, with which a data processing agreement pursuant to Art. 28 GDPR has been concluded.

Legal Basis

Art. 6(1)(a) GDPR (consent). You may withdraw your consent at any time with effect for the future, for example by email to datenschutz@gosign.de.

Retention Period

Confirmed report requests are deleted after 6 months. Unconfirmed double opt-in requests expire automatically after 7 days.

8. Appointment Booking

For appointment booking, we use Google Calendar Appointment Scheduling (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). When you click the booking link, you are redirected to calendar.google.com. No script is loaded and no cookie is set on our website by the booking link.

When using the booking service, your data (name, email address, selected appointment) is processed by Google. Google's Privacy Policy applies.

Legal basis: Art. 6(1)(b) GDPR (implementation of pre-contractual measures at your request). Booking a consultation appointment serves to initiate a business relationship.

9. Fonts

All fonts used on this website are locally embedded (self-hosted). No external font services (e.g. Google Fonts) are loaded. No connection to third parties is established when loading fonts.

10. Maps and Videos

This website does not embed external map services (e.g. Google Maps) or external video services (e.g. YouTube). Where maps or videos are displayed, this is done via static images or self-hosted content.

11. No Additional Third Parties

This website does not load resources from third parties not mentioned in this privacy policy. In particular, the following are not used:

  • Google Tag Manager
  • Facebook Pixel
  • LinkedIn Insight Tag
  • HubSpot, Salesforce, or other CRM trackers
  • Hotjar, Mouseflow, or other session recording tools
  • Matomo or other self-hosted analytics tools

12. SSL/TLS Encryption

This website uses SSL/TLS encryption for security purposes. An encrypted connection is indicated by "https://" in your browser's address bar.

13. Server Log Files

The hosting provider (Cloudflare) collects access data in server log files for technical reasons. These may include: page accessed, time, data volume, referrer URL, IP address, browser, and operating system. Log files are stored by Cloudflare for a maximum of 72 hours and are not merged with other data.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in ensuring technical operations and detecting attacks).

14. Artificial Intelligence and Automated Decision-Making

No automated decision-making including profiling within the meaning of Art. 22 GDPR takes place. No AI systems are used on this website for the automated processing of personal data of website visitors.

AI-Assisted Content Creation

Gosign uses AI-assisted tools (large language models, image generation) for the creation and editing of website content, graphics, and diagrams. These tools do not process personal data of website visitors. All outputs are editorially reviewed and approved.

AI in Client Projects

Gosign develops and operates AI infrastructure for enterprise clients (AI Agents, Document Intelligence, workflow automation). The processing of personal data in client projects is governed by separate data processing agreements (DPAs) pursuant to Art. 28 GDPR and is not covered by this privacy policy.

15. Security Vulnerability Reporting

At gosign.de/en/security/report/ we accept reports about security vulnerabilities. For this reporting channel Gosign GmbH is the controller under the GDPR - including where the reported flaw concerns a site we operate for a client. Use is voluntary; the following applies only if you submit a report.

Purpose and legal basis

We process your details in order to assess and remediate the reported vulnerability and - where it concerns a client site - to pass it to the responsible operator. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the security of our systems and those of our clients. If you wish to be credited by name after remediation, we process your name or pseudonym on the basis of your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time and informally.

What we store

We store the details from the form (affected URL or system, impact, reproduction steps, date of the finding, a statement on AI tools used, and optional evidence), your contact address if you provide one, a hash of your IP address salted with a secret value, and an equally salted hash of your network range (the network prefix that IP address belongs to). We do not store the IP address itself; both hashes serve solely to detect abusive repeat submissions. Without a contact address your report is anonymous - we then store nothing that identifies you, and equally cannot reply to you.

The free-text fields may contain personal data if you reproduce such data in your evidence. Please limit yourself to what is necessary to evidence the flaw.

Recipients

The form page and the endpoint that accepts your report run on Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA); the endpoint itself is a Cloudflare Worker at the network edge. Cloudflare terminates the encrypted connection and processes your IP address and the content of your report transiently in memory, without storing it; processing takes place at the Cloudflare location closest to your internet access and may therefore also occur outside the EU/EEA. The legal grounds are the data processing agreement concluded with Cloudflare under Art. 28 GDPR, the European Commission's adequacy decision on the EU-US Data Privacy Framework - Cloudflare, Inc. is certified under it - and, in addition, standard contractual clauses under Art. 46(2)(c) GDPR. You can obtain a copy of the standard contractual clauses from datenschutz@gosign.de.

To protect against automated mass submissions we use our own mechanism, which runs entirely on our own servers. When the form is opened we issue a signed proof of origin, which we verify on submission. Nothing is stored on or read from your device, no third-party service is embedded, and no additional recipient of your data arises. We process only a salted hash of your IP address; we do not store the IP address itself for this purpose. If the proof cannot be issued or verified, we still accept your report and mark it internally as unverified - a published reporting channel must not fail because of a check.

The report is stored in a database we operate (Supabase, self-hosted on a server within the EU) and additionally delivered to an internal Gosign GmbH mailbox; mail delivery runs via Google Workspace (Google Ireland Limited) as processor. Where the report concerns a client site we operate, we pass it to the responsible operator - that is the purpose of the processing and at the same time our obligation under Art. 33(2) GDPR. Beyond the recipients named here we do not pass your report on.

Retention

We delete the report text, the evidence and any contact address you provided 90 days after the case is closed, and at the latest 365 days after we received the report. The salted hashes of your IP address and of its network range are deleted after 7 days. A pseudonymised entry containing the case number and the date of receipt is retained for up to three years after the case is closed so that we can evidence compliance with the deadlines we commit to; after that we delete it as well.

Your rights

The data subject rights set out under "Your Rights" apply. Please address requests to datenschutz@gosign.de, quoting your case number. For an anonymous report we cannot link the data to you (Art. 11(2) GDPR).

16. International Data Protection Standards

Gosign serves clients worldwide and recognises data protection rights under the respectively applicable local laws. The GDPR remains the primary data protection law as Gosign GmbH is headquartered in Germany and data processing takes place in the EU. Below are supplementary notes for users in specific jurisdictions.

United Kingdom

For users in the United Kingdom, the UK GDPR in conjunction with the Data Protection Act 2018 applies. The rights largely correspond to those under the EU GDPR. Competent supervisory authority: Information Commissioner's Office (ICO), Wilmslow, Cheshire, UK.

United States

For users residing in California, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) apply additionally. This includes the right to know the categories of data collected, the right to deletion, and the right to opt out of the sale of personal data. Gosign does not sell personal data and does not share it with third parties for advertising purposes. For users in other US states with their own privacy laws (Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and others), comparable rights are recognised.

Switzerland

For users in Switzerland, the revised Federal Act on Data Protection (revDSG/nDSG), in effect since 1 September 2023, applies. It grants rights comparable to the GDPR. Competent supervisory authority: Federal Data Protection and Information Commissioner (FDPIC/EDÖB), Bern.

Canada

For users in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) applies. Gosign recognises the PIPEDA principles, in particular consent, purpose limitation, access, and rectification. Competent supervisory authority: Office of the Privacy Commissioner of Canada (OPC), Gatineau, QC.

Brazil

For users in Brazil, the Lei Geral de Proteção de Dados (LGPD, Lei n.º 13.709/2018) applies additionally. The LGPD grants Brazilian users comprehensive rights, including access, rectification, anonymisation, erasure, data portability, and objection. These rights are fully recognised by us. Competent supervisory authority: Autoridade Nacional de Proteção de Dados (ANPD), Brasília, DF.

India

For users in India, the Digital Personal Data Protection Act (DPDP Act, 2023) applies. Gosign recognises the rights of Indian users, in particular access, rectification, erasure, and the right to lodge a complaint. Competent supervisory authority: Data Protection Board of India (DPBI), New Delhi.

Japan

For users in Japan, the Act on the Protection of Personal Information (APPI) applies. The EU Commission has granted Japan an adequate level of data protection. Gosign recognises the APPI rights, in particular access, rectification, erasure, and cessation of use. Competent supervisory authority: Personal Information Protection Commission (PPC), Tokyo.

South Africa

For users in South Africa, the Protection of Personal Information Act (POPIA) applies. Gosign recognises the POPIA rights, in particular access, rectification, erasure, and objection to direct marketing. Competent supervisory authority: Information Regulator, Johannesburg.

All other jurisdictions

For users in countries with their own data protection laws not explicitly mentioned here, Gosign recognises the respectively applicable local data protection rights insofar as they relate to processing via this website. Your rights to access, rectification, and erasure are guaranteed in every case.

17. Your Rights

You have the following rights regarding your personal data:

  • Access (Art. 15 GDPR): You may request information about the data we process.
  • Rectification (Art. 16 GDPR): You may request correction of inaccurate data.
  • Erasure (Art. 17 GDPR): You may request deletion of your data, provided no statutory retention obligations apply.
  • Restriction (Art. 18 GDPR): You may request restriction of processing.
  • Data Portability (Art. 20 GDPR): You may request your data in a machine-readable format.
  • Objection (Art. 21 GDPR): You may object to processing based on Art. 6(1)(f) GDPR at any time.
  • Withdrawal of Consent (Art. 7(3) GDPR): Where processing is based on your consent, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out prior to the withdrawal remains unaffected.

To exercise your rights, an informal message to the address stated above is sufficient.

18. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the supervisory authority of the federal state in which you reside, or the authority responsible for the controller:

The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Str. 22
20459 Hamburg, Germany

19. Currency

This privacy policy is currently valid. Last updated: February 2026.

We reserve the right to amend this privacy policy to adapt it to changed legal requirements or changes to the service.