PRIVACY POLICY

How we process and protect personal data relating
to website visitors, prospects, customers, business partners and applicants.

Book a Call

Last updated: 3 August 2026

This Privacy Policy explains how Alan&Eve GmbH processes personal data relating to visitors to our website, prospective and existing customers, business partners, suppliers, professional contacts and applicants.

We process personal data in accordance with the General Data Protection Regulation (“GDPR”), the German Federal Data Protection Act and other applicable data protection laws.

1. Controller

The controller responsible for the processing described in this Privacy Policy is:

Alan&Eve GmbH Grünberger Str. 54 10245 Berlin Germany
Represented by Managing Director Sebastian Schäffer
Commercial Register: Amtsgericht Charlottenburg, HRB 277589 B VAT ID: DE457545509

We have not appointed a data protection officer. Data protection matters are handled by the management of Alan&Eve GmbH.

2. Scope of this Privacy Policy

This Privacy Policy applies to personal data that we process in connection with:

  • visits to our website;
  • enquiries and other communications;
  • meeting bookings;
  • sales and business development activities;
  • prospective and existing customer relationships;
  • cooperation with business partners and suppliers;
  • contracts, invoicing and payment processes;
  • applications and recruitment;
  • the assertion, exercise or defence of legal claims.

Additional or more specific privacy information may apply to individual services, contractual relationships or employment relationships.

3. Visiting our website

3.1 Technical provision of the website

Our current website is created and hosted using Gamma, a service provided by Gamma Tech, Inc.

When you access the website, technical information may be processed automatically. This may include:

  • IP address;
  • date and time of access;
  • requested page or file;
  • browser type and version;
  • operating system;
  • device information;
  • referring website;
  • technical error and security information.

This processing is necessary to display the website, maintain its stability and security, identify technical faults and protect the website against misuse.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the reliable, secure and technically functional operation of our website.

Technical log data is retained only for as long as reasonably necessary for operational and security purposes, unless longer retention is required in connection with a security incident or legal obligation.

3.2 Cookies and similar technologies

We do not currently use our own analytics, advertising or marketing cookies on this website.

In particular, we have not activated Google Analytics, Google Tag Manager, Meta Pixel or comparable marketing technologies for this website.

The hosting platform may use technically necessary cookies or similar technologies and may process connection, device and usage information to provide and secure the service.

You can configure your browser to block or delete cookies. Blocking technically necessary cookies may affect the functionality of individual websites.

3.3 No automated decision-making

We do not use data collected through this website for automated decision-making or profiling that produces legal or similarly significant effects.

4. Contacting us

You may contact us by email or through other business communication channels.

We may process the following data:

  • name;
  • business contact details;
  • company and position;
  • content of your enquiry;
  • correspondence and attachments;
  • date, time and context of the communication.

We process this information to respond to your enquiry, initiate or manage a business relationship and document our communication.

Depending on the context, the legal basis is:

  • Article 6(1)(b) GDPR for pre-contractual measures or contractual communication;
  • Article 6(1)(f) GDPR for general business communication and relationship management;
  • Article 6(1)(c) GDPR where processing is required to comply with a legal obligation.

Our legitimate interests include responding efficiently to enquiries, maintaining professional relationships and documenting relevant business communications.

We use Google Workspace for email, calendar, file storage and related business communication.

5. Booking a meeting through Calendly

Our website contains an external link to Calendly, which can be used to book a meeting with us.

Calendly is not embedded directly into our website. Data is transferred to Calendly only when you follow the link and use the Calendly service.

Depending on the information you provide, the following data may be processed:

  • name;
  • email address;
  • company name;
  • telephone number;
  • selected appointment;
  • time zone;
  • additional participants;
  • information entered in the free-text field;
  • technical connection and device information.

We use this information to arrange, prepare and conduct the requested meeting.

The legal basis is Article 6(1)(b) GDPR where the meeting relates to pre-contractual or contractual matters. In other cases, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the efficient coordination of business appointments.

Calendly may process personal data outside the European Economic Area. Where required, such transfers must be based on an adequacy decision, appropriate safeguards such as standard contractual clauses, or another lawful transfer mechanism.

Calendly also provides its own privacy information and participant terms when a booking is made.

Calendly’s current DPA identifies Calendly as a processor for customer-provided personal data and refers to the EU-US Data Privacy Framework and other transfer safeguards.

6. Prospects, customers and business partners

We process personal data relating to prospective customers, customers, suppliers, technology partners and other business contacts.

This may include:

  • name and business contact details;
  • company, department and position;
  • areas of responsibility;
  • communication history;
  • meeting notes;
  • interests and business requirements;
  • information about opportunities, projects and contracts;
  • offers, orders and contractual documents;
  • billing and payment information;
  • support and service information;
  • information required to manage the business relationship.

We process this data to:

  • establish and maintain business relationships;
  • respond to enquiries; prepare and submit offers;
  • negotiate and perform contracts;
  • deliver professional and technical services;
  • coordinate projects;
  • provide customer support;
  • manage partnerships;
  • fulfil accounting, tax and compliance obligations;
  • assert or defend legal claims.

The legal bases are:

  • Article 6(1)(b) GDPR for contractual and pre-contractual measures;
  • Article 6(1)(c) GDPR for legal obligations;
  • Article 6(1)(f) GDPR for business relationship management, documentation, security, internal administration and the establishment or defence of legal claims.

Where the contractual partner is a company rather than the individual contact, processing of the contact person’s data is generally based on Article 6(1)(f) GDPR.

7. Customer relationship management

We use Zoho CRM to manage business contacts, prospective customers, sales opportunities and customer relationships.

Data stored in the CRM may include:

  • name;
  • business contact details;
  • company and position;
  • source of the contact;
  • communication history;
  • meeting and call notes;
  • business interests and requirements;
  • status of an opportunity;
  • proposed or agreed services;
  • relevant contractual and project information.

The legal basis is Article 6(1)(b) GDPR where the processing concerns a contract or pre-contractual measures. Otherwise, processing is based on Article 6(1)(f) GDPR.

Our legitimate interests are structured business development, consistent customer relationship management and the documentation of business communication.

8. Business contact research and direct outreach

We may obtain professional contact information from publicly available sources, professional networks, company websites, event information and specialised business contact providers such as Lusha.

This may include:

  • name;
  • employer;
  • professional role;
  • business email address;
  • business telephone number;
  • professional profile information;
  • publicly available information about areas of responsibility;
  • source of the information.

We use this information to identify potentially relevant business contacts and to communicate about services that we reasonably believe may be relevant to their professional role.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are B2B business development, professional networking and targeted communication with relevant corporate contacts.

We do not intend to use this process to collect private contact information or to contact individuals in a purely personal capacity.

Where we have not obtained the data directly from you, the information in this Privacy Policy also serves as information under Article 14 GDPR.

You may object at any time to the use of your personal data for direct marketing. Following an objection, we will no longer process your data for that purpose.

9. Offers, contracts and electronic signatures

We use PandaDoc to prepare, send, negotiate and sign offers and contractual documents.

The following data may be processed:

  • name and business contact details;
  • company and position; content of offers and contracts;
  • signature data;
  • document status;
  • comments and communications relating to a document;
  • timestamps and technical verification data.

The legal basis is Article 6(1)(b) GDPR. Where retention or processing is required by law, Article 6(1)(c) GDPR also applies. The establishment, exercise or defence of legal claims may additionally be based on Article 6(1)(f) GDPR.

PandaDoc states that content uploaded to its service may contain personal data and is processed in order to provide the contracted service.

10. Project communication and collaboration

We use business communication and collaboration tools, including Google Workspace and Slack, to communicate internally and with customers and project partners.

Depending on the project, this may include:

  • names and business contact details;
  • messages and correspondence;
  • meeting information;
  • project assignments;
  • documents and attachments;
  • technical and organisational project information;
  • decisions, tasks and status information.

The legal basis is Article 6(1)(b) GDPR where the processing is necessary for contractual performance. Otherwise, processing is based on Article 6(1)(f) GDPR.

Our legitimate interests include efficient communication, project coordination, documentation and secure collaboration.

11. Invoicing, accounting and expense management

We process customer, supplier, payment and accounting data for invoicing, bookkeeping, financial administration, expense management and compliance with tax and commercial law.

We currently use services including easybill and Pleo for these purposes.

The data processed may include:

  • name or company name;
  • address; business contact details;
  • order and contract information;
  • invoice and payment information;
  • bank and transaction information;
  • receipts and expense documentation;

The legal bases are:

  • Article 6(1)(b) GDPR for contractual billing and payment;
  • Article 6(1)(c) GDPR for statutory accounting, tax and record-keeping obligations;
  • Article 6(1)(f) GDPR for financial administration, fraud prevention and the establishment or defence of legal claims.

12. Applications and recruitment

We process personal data provided in connection with applications and recruitment processes.

This may include:

  • name and contact details;
  • application documents;
  • CV and employment history;
  • qualifications and skills;
  • salary expectations; availability;
  • interview notes;
  • correspondence;
  • information voluntarily provided by the applicant.

We use Personio to manage applications and recruitment processes.

The legal basis is Section 26 of the German Federal Data Protection Act in conjunction with Article 6(1)(b) GDPR, insofar as the processing is necessary to decide whether to enter into an employment relationship.

Where you consent to longer retention or inclusion in a talent pool, the legal basis is Article 6(1)(a) GDPR. Consent may be withdrawn at any time with effect for the future.

If an application is unsuccessful, we generally retain the application data for up to six months after the recruitment process has ended. Data may be retained for longer where required for legal proceedings, where you have consented to longer retention or where another legal basis applies.

13. Recipients of personal data

We may disclose personal data to the following categories of recipients where this is necessary and legally permitted:

  • IT, hosting and cloud service providers;
  • email and communication providers;
  • CRM and sales systems;
  • scheduling providers;
  • contract and electronic signature providers;
  • project and collaboration platforms;
  • recruitment and HR service providers;
  • accounting, invoicing, payment and expense providers;
  • technology and implementation partners;
  • professional advisers, including lawyers, tax advisers and auditors;
  • banks, insurers and payment service providers;
  • public authorities, courts and regulatory bodies;
  • prospective purchasers, investors or advisers in connection with corporate transactions.

Service providers acting on our behalf are contractually required to process data only in accordance with our instructions and applicable data protection law, where the requirements for commissioned processing apply.

14. International data transfers

Some of our service providers or their subprocessors are located outside the European Economic Area or may access personal data from countries outside the European Economic Area.

Where personal data is transferred to a country for which the European Commission has not issued an adequacy decision, we seek to rely on appropriate safeguards, such as:

the European Commission’s standard contractual clauses; participation in the EU-US Data Privacy Framework where applicable; supplementary contractual, technical or organisational safeguards; another transfer mechanism permitted under Articles 44 to 49 GDPR.

Despite these safeguards, the level of data protection in a third country may differ from that within the European Union.

You may contact us for further information about the safeguards used for a specific transfer.

15. Retention periods

We retain personal data only for as long as it is required for the relevant purpose, unless statutory obligations or legitimate interests require longer retention.

As a general framework, we apply the following periods:

Website technical data

Usually deleted or anonymised within a short period after collection, unless required for security investigations.

General enquiries

Usually retained for up to three years after the end of the calendar year in which the enquiry was completed, unless the enquiry leads to a business relationship or longer retention is required.

Prospects and CRM contacts

Usually reviewed for deletion no later than three years after the last meaningful business interaction, unless there is an ongoing business relationship, a continuing documented business interest, an objection, a legal obligation or another lawful reason for retention.

Meeting bookings

Usually retained for up to three years after the meeting or last subsequent business contact, unless the information becomes part of an ongoing customer or contractual relationship.

Customer and contractual data

Retained for the duration of the contractual relationship and thereafter for the applicable limitation and statutory retention periods.

Commercial correspondence

Generally retained for six years where statutory commercial or tax retention requirements apply.

Accounting records and booking documents

Generally retained for eight years, while certain accounting records and financial statements may have to be retained for ten years.

German commercial and tax law currently provides, depending on the document type, for retention periods of six, eight or ten years.

Applications

Usually retained for up to six months after completion of the recruitment process, unless longer retention is justified or the applicant has consented to inclusion in a talent pool.

Legal claims

Relevant data may be retained until the applicable limitation periods have expired and any related legal proceedings have been concluded.

After the applicable retention period, data is deleted or anonymised unless further processing is legally permitted or required.

16. Your rights

Subject to the applicable legal requirements, you have the right to:

  • obtain information about the personal data we process about you;
  • request correction of inaccurate or incomplete data;
  • request deletion of your personal data;
  • request restriction of processing;
  • receive personal data in a structured, commonly used and machine-readable format;
  • object to processing based on Article 6(1)(e) or Article 6(1)(f) GDPR;
  • object at any time to processing for direct marketing;
  • withdraw consent at any time with effect for the future;
  • lodge a complaint with a data protection supervisory authority.

A withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

To exercise your rights, contact:

We may request information necessary to verify your identity before responding to a request.

17. Right to object

Where we process personal data on the basis of legitimate interests under Article 6(1)(f) GDPR, you have the right to object to the processing on grounds relating to your particular situation.

We will then stop processing the personal data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.

Where personal data is processed for direct marketing, you may object at any time. Following such an objection, the data will no longer be used for direct marketing.

18. Complaints to a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority.

The supervisory authority responsible for companies based in Berlin is generally:

Berlin Commissioner for Data Protection and Freedom of Information

You are not required to contact us before lodging a complaint. However, we welcome the opportunity to address your concerns directly.

The Berlin authority provides a free complaint procedure for individuals who believe that personal data has been processed unlawfully.

19. Data security

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

These measures are reviewed and adjusted where appropriate, taking into account the nature of the data, the risks involved, the available technology and the cost of implementation.

No method of transmission or storage can guarantee absolute security.

20. Changes to this Privacy Policy

We may update this Privacy Policy where our processing activities, service providers, website technology or legal obligations change.

The version published on this page is the current version.





Alan&Eve GmbH

Made in Berlin.
Represented by the Managing Director: Sebastian Schäffer.

Registered Office: Berlin, Germany
Business Registration Number: HRB 277589 B
Registered with the Commercial Register of the Local Court (Amtsgericht) Charlottenburg
Tax ID: 30/203/52086
VAT ID (according to §27a German VAT Act): DE457545509

Email: hello@alan-eve.com