Privacy policy
Last updated: 4 June 2026
Information on how we handle your personal data
1. Overview
We are obliged to inform you clearly and comprehensibly about how we handle your personal data at the time we collect it. Below you will first find a short overview; the following sections provide details on
- who we are as a company and how you can reach us or our controller (contact details are provided there),
- the purposes for which we use your personal data,
- which categories of personal data we process,
- the legal basis for this processing,
- how long we store your personal data,
- which recipients may receive your personal data,
- whether data is transferred to a country outside the EU,
- and that you have fundamental data protection rights, for example regarding:
- access,
- rectification,
- erasure,
- restriction of processing,
- data portability,
- objection, or
- further information on automated decision-making.
- In addition, we inform you about how we handle data of external and internal applicants,
- about data processing when you visit our websites and our presences on social networks,
- about how we handle your data when you use our newsletter,
- and about the use of cloud services.
Please note that personal data is indispensable for our business. Without such data, we cannot process your requests, manage you as a contractual partner or send you information about our activities, services or company. We collect only the data necessary for these purposes. Should we require further information, we will point this out and make clear that providing it is voluntary. We do not use automated decision-making.
Data protection is very important to us. We therefore want to inform you comprehensively and comprehensibly about how we process your personal data, always in compliance with the applicable legal requirements, in particular the European General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and all other applicable data protection provisions. We have set out how we handle personal data in our data protection management system and act accordingly.
We review and update our privacy policy and other data protection information regularly as part of our data protection management. The current version is published on this page.
2. Detailed information
Controller
leefs CX GmbH
Eiler Str. 3Q
51107 Köln (Cologne), Germany
Phone: +49 221 98655743
Email: hello@leefs.digital
Responsible person: Anne Görs (Managing Director)
Data protection officer
Our company has appointed a data protection officer as required by law. You can reach the data protection officer by post at the controller's address above, marked DATENSCHUTZ, or by email at datenschutz@leefs.digital.
You can also contact us directly or the competent data protection supervisory authority at any time and lodge a complaint there: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Postfach 20 04 44, 40102 Düsseldorf, Germany, phone: +49 211 384 24-0, fax: +49 211 384 24-999, email: poststelle@ldi.nrw.de, https://www.ldi.nrw.de.
3. Purpose
Which data we process and for what purpose depends on the services you use. Details of the processing purposes can be found in the respective contract documents, forms, declarations of consent and other information provided to you in this context. This data protection information forms part of our contract texts, our website and other documents that we provide or have provided to you. As a rule, we process personal data for the following purposes:
- customer and supplier management,
- applicant management,
- employee management,
- order management,
- operation of the websites https://leefs.digital and https://rygg.ai,
- publications on our websites and on social media portals,
- management of training and event participants.
In addition, we process your data in the following cases for the purpose of
- sending company information (by post, email, etc.), provided you have given us your consent,
- communication (analogue and digital),
- obtaining information from credit agencies,
- using your email address for marketing purposes, newsletters, etc.,
- complying with legal requirements such as tax laws, compulsory insurance, etc.,
- complying with legal security, control and reporting obligations,
- archiving data for backup purposes and to fulfil documentation obligations,
- disclosure in the context of official or judicial measures,
- conducting video conferences.
4. Categories
Depending on how you use our services or what contractual relationship exists with you, we may process the following categories of personal data:
- master data (e.g. name, telephone number, email address, postal address) of customers (including prospective customers), suppliers and service providers (including prospective ones), employees in the context of the employment relationship, participants in market research studies, applicants, training and event participants, other interested parties and further persons connected with the persons mentioned who may be involved in the context of their respective affiliation (e.g. family members, employees of service providers and/or suppliers),
- contact data of the aforementioned categories of persons (addresses, telephone numbers, email addresses, etc.),
- transaction data of the aforementioned categories of persons (interests, orders, participation in training courses and events of all kinds, etc.),
- bank details and data on payments and, where applicable, creditworthiness,
- usage data on the websites and customer portals we offer (IP address, time of access, pages visited, etc.),
- consent data documenting consents given or withdrawn.
5. Legal basis
If you are employed by us, we process your personal data to establish, perform and terminate this contractual relationship on the basis of Art. 6 (1) (b) in conjunction with Art. 88 GDPR and Section 26 BDSG.
If there is another contractual relationship or if we communicate in the context of pre-contractual measures, we process personal data to perform the contracts concerned and the associated measures and activities. This processing is based on Art. 6 (1) (b) GDPR.
In addition, we process your data for the following purposes on the legal bases stated:
- customer management (Art. 6 (1) (b) GDPR),
- supplier management (Art. 6 (1) (b) GDPR),
- employee management (Art. 6 (1) (c) GDPR),
- applicant management (Art. 6 (1) (a) and (b) GDPR in conjunction with Art. 88 GDPR, Section 26 BDSG),
- administration (Art. 6 (1) (c) GDPR),
- operation and hosting of the company websites, in particular to provide you with the content requested and to ensure secure operation (Art. 6 (1) (f) GDPR),
- publication of photos on the websites and on social media portals (Art. 6 (1) (a) GDPR), provided you have given us your consent,
- market and opinion research (Art. 6 (1) (a) GDPR), provided you have given us your consent,
- use of your email address for marketing purposes and newsletters (Art. 6 (1) (a) GDPR), provided you have given us your consent,
- compliance with legal requirements such as tax laws etc. (Art. 6 (1) (c) GDPR),
- compliance with legal control and reporting obligations (Art. 6 (1) (e) GDPR),
- archiving of data for backup purposes (Art. 6 (1) (c) and, where applicable, (f) GDPR),
- fulfilment of documentation obligations (Art. 6 (1) (c) GDPR),
- disclosure in the context of official or judicial measures (Art. 6 (1) (e) GDPR).
Should we process further personal data about you on the basis of Art. 6 (1) (f) GDPR, i.e. on the basis of a balancing of interests, we will inform you of this separately in advance.
6. Retention
We process and store your data only for as long as is necessary for our activities and the purposes stated, or as required by statutory retention obligations (e.g. under the German Commercial Code (HGB) and Fiscal Code (AO)). In individual cases, this may mean that personal data is stored for several years.
7. Recipients
As a matter of principle, we pass on your personal data only to internal or external recipients who need it to fulfil contractual or legal obligations or to perform their tasks. Data is therefore passed on or disclosed
- to bodies that process data as processors or as joint controllers with us (e.g. in the areas of HR, legal, data centres, accounting, data disposal, customer management, marketing, sales, information and communication technology, website administration and hosting, applicant management),
- where there is a legitimate interest, to authorities, lawyers, associations, courts, experts, credit agencies, debt collection agencies, etc.,
- where there is a legal obligation, to authorities, public bodies, social insurance institutions, etc.,
- to other third parties, provided you have given us your express consent.
Your data is not passed on beyond this.
Service providers that we have commissioned as processors or as joint controllers may use the data exclusively for the purposes for which we transferred it to them. This is generally governed by contract with these service providers; data processing there is subject to the same conditions as with us.
8. Data transfer outside the EU
As a rule, your data is not transferred to bodies in countries outside the European Union (EU) or the European Economic Area (EEA), so-called third countries. Only in connection with data collected when you visit our websites, use our newsletter, use cloud services, and use or visit our social media presences can a transfer to third countries, including unsafe third countries, not be ruled out. Please refer to the respective notes in the relevant sections of this privacy policy.
9. Your rights
Under certain conditions, you can assert your data protection rights against us:
- Under Art. 15 GDPR, you have the right to obtain information about the data we store about you, subject to restrictions where applicable.
- If the data we store about you is incorrect or inaccurate, you can request its rectification under Art. 16 GDPR.
- Under Art. 17 GDPR, you can request the erasure of the personal data stored about you, provided no other legal provision prevents this.
- If the conditions of Art. 18 GDPR are met, you can request the restriction of the processing of your data.
- Under the conditions of Art. 20 GDPR, you have the right in certain circumstances to have us provide you with your personal data.
- You can withdraw any consent you have given at any time with effect for the future in accordance with Art. 7 (3) GDPR. From the time of withdrawal, we will no longer process your personal data for the purposes to which you have objected. Withdrawal can be made informally.
If, for example, you have expressly consented under Art. 6 (1) (a) GDPR, we use your email address to send you our newsletter regularly. You can unsubscribe at any time, for example via the link at the end of each newsletter. Alternatively, you can send your request to unsubscribe at any time by email to datenschutz@leefs.digital.
Within existing contractual relationships with our customers, we send contract- and/or service-related information by email to the contact email addresses we hold, in particular in the service area. This includes, for example, notices of upcoming maintenance and service intervals or current technical information on the products purchased from us. If you do not wish to receive this information, you can let us know at any time by email to datenschutz@leefs.digital or via the unsubscribe link contained in each customer information. If you would like to name a different or additional contact person in your company to receive this information, please send us an email to datenschutz@leefs.digital.
- Under Art. 77 GDPR, you have the right to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence, your place of work or our registered office.
- If your personal data is processed on the basis of legitimate interests pursuant to Art. 6 (1) sentence 1 (f) GDPR, you have the right under Art. 21 GDPR to object to the processing, insofar as there are grounds arising from your particular situation or the objection is directed against direct marketing. In the latter case, you have a general right to object, which we will implement without you having to state a particular situation.
If you wish to exercise any of these rights, please contact us, preferably in writing at the controller's address given above (see contact details) or directly by email to datenschutz@leefs.digital.
10. Additional information on data of external and internal applicants
We generally collect personal data directly from you, for example in the course of the application process, on the basis of Art. 88 GDPR and Section 26 (1) BDSG.
We may also have received data from third parties (e.g. from job portals such as Indeed, Stepstone or comparable recruitment services).
In addition, we may process personal data that we have lawfully obtained from publicly accessible sources (e.g. professional social networks).
The categories of applicants' personal data processed include in particular your master data (such as first name, surname, name affixes, nationality, personnel number), contact data (such as private address, (mobile) telephone number, email address) and all data from the application process (cover letter, CV, employment or other references, proof of qualifications).
If you voluntarily disclose special categories of personal data in your application or during the application process (e.g. health data, degree of disability, religious affiliation), we will process this data only if you have expressly consented to this (Art. 9 (2) (a) GDPR).
We process personal employee and applicant data on the basis of and in compliance with the European General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and all other provisions relevant under German labour law (e.g. AGG, BetrVG, SGB).
The processing of your personal data in the application process serves primarily to carry out the application procedure, in particular to determine to what extent you are suitable for the advertised position. The processing of your applicant data is necessary for the decision on establishing an employment relationship. The primary legal basis for this is Art. 88 GDPR in conjunction with Section 26 (1) BDSG.
10.1 Disclosure of data of internal and external applicants
Within our company, only those persons and departments receive your personal data who need it to decide on your employment and to fulfil our legal and contractual obligations. Outside our company, we disclose your data only to bodies that process it as processors (applicant management) and to companies of our group, provided you have given us your consent.
Notwithstanding this, we only transfer your personal data, for example to investigating authorities, if we are legally obliged to do so.
10.2 Storage period for data of internal and external applicants
We delete applicant data transmitted to us as soon as it is no longer required for the purposes stated above, but no later than six months. This does not apply if you have expressly agreed to a longer storage period, if storage is necessary for evidentiary purposes or if legal regulations prevent deletion. For example, we retain your applicant data for as long as you may assert legal claims against us, for example due to a violation of the provisions of the German General Equal Treatment Act (AGG).
If, on the other hand, your application leads to an employment contract, we store your data for the purposes of the usual administrative and organisational processes and to carry out the employment relationship until it ends.
11. Additional information on the collection and storage of personal data when you visit our websites
When you visit our websites, the browser on your device automatically sends information to the server of our website and our customer portal. This information is temporarily stored in a so-called log file. The following information is collected without any action on your part and stored until it is automatically deleted:
- IP address of the requesting computer,
- host name of the requesting computer,
- date and time of access,
- website from which access is made (referrer URL),
- browser used, including browser version, and the operating system of your computer.
We process this data for the following purposes:
- ensuring a smooth connection to the website,
- ensuring convenient use of our website,
- evaluating system security and stability, and
- other administrative purposes.
The legal basis for the data processing is Art. 6 (1) (f) GDPR. Our legitimate interest lies in operating our website and the associated presentation of our company. We never use the data collected to draw conclusions about you personally.
We delete your data as soon as it is no longer required for the purposes stated, but no later than six months.
11.1 Information on the website rygg.ai
The website https://rygg.ai is a service of leefs CX GmbH. For this website, the following applies:
- Hosting: The website is hosted by Netlify, Inc. (USA). When you visit the website, the log file data listed in section 11 is processed by Netlify. For transfers to the USA, see section 8. Netlify's privacy policy: https://www.netlify.com/privacy/.
- Audience measurement: We use Netlify Analytics. The analysis is carried out on the server from the log file data; no scripts are run in your browser and no cookies are set. We receive only aggregated statistics (e.g. page views, referring pages). The legal basis is Art. 6 (1) (f) GDPR, our legitimate interest in analysing the use of our website.
- Cookies and consent: The website does not set cookies and does not store any information on your device. A consent banner is therefore not required.
- Fonts: The fonts (Schibsted Grotesk, JetBrains Mono) are stored locally on our server. No connection to third-party servers is made.
- Contact form: If you use the contact form, we process the data you enter (name, email address, optionally company and role, your area of interest and your message) in order to answer your request. The data is transmitted to our email inbox via a form service that we operate on Netlify (api.leefs.digital). To prevent misuse, your IP address is processed briefly to limit the number of requests. The legal basis is your consent (Art. 6 (1) (a) GDPR) and the performance of pre-contractual measures (Art. 6 (1) (b) GDPR). You can withdraw your consent at any time with effect for the future, for example by email to datenschutz@leefs.digital.
12. Presences on social networks
We maintain online presences within social networks and platforms such as Xing, LinkedIn, Facebook and YouTube in order to communicate with the customers, prospective customers and users active there and to inform them about our services and our company. When operating these online presences, we are joint controllers together with the respective providers.
Please note that, in particular with LinkedIn, Facebook, Instagram and YouTube, user data may be processed outside the European Union. This may result in risks for users, for example because it may be more difficult to enforce their rights.
Furthermore, the platforms usually process user data for market research and advertising purposes. For example, usage profiles can be created from user behaviour and the interests derived from it. These profiles can in turn be used, for example, to display advertisements inside and outside the platforms that presumably correspond to the users' interests. For these purposes, cookies are usually stored on users' computers, in which usage behaviour and interests are recorded. In addition, data can also be stored in the usage profiles independently of the devices used, in particular if users are members of the respective platform and are logged in there. We ourselves do not have any access to the actual usage data, but only use general usage statistics to check the effectiveness of our presences.
The processing of users' personal data is based on our legitimate interests in informing and communicating with users effectively in accordance with Art. 6 (1) (f) GDPR.
For a detailed description of the respective processing operations and the options to object (opt-out), please refer to the providers' information linked below.
With regard to requests for information and the assertion of user rights, we point out that these can be asserted most effectively directly with the providers. Only the providers have access to the users' data and can take appropriate measures and provide information directly. Should you nevertheless require assistance, you can contact us.
- LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland), privacy policy: https://de.linkedin.com/legal/privacy-policy
- Instagram (Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA), privacy policy: https://privacycenter.instagram.com/policy
13. Cloud services
We use software services that are accessible via the internet and run on the providers' servers (so-called "cloud services", also known as "software as a service"), such as "Microsoft Teams" or "Microsoft Exchange", for the following purposes: exchanging documents, content and information with specific recipients, authenticated user login secured with two-factor authentication, as well as chats and participation in audio and video conferences.
In this context, personal data may be processed and stored on the providers' servers insofar as it forms part of communication processes with us or is otherwise processed by us as set out in this privacy policy. This data may include in particular master and contact data of users as well as data on transactions, contracts, other processes and their content. The cloud service providers also process usage data and metadata, which they use for security purposes and to optimise their services. In this context, personal data may be transferred to the cloud service providers in unsafe third countries such as the USA. For this reason, we have concluded the EU standard contractual clauses with the providers to ensure an adequate level of data protection.
If we use the cloud services to provide forms or other documents and content for other users or on publicly accessible websites, the providers may store cookies on users' devices, for example for web analysis purposes or to remember user settings (e.g. for media controls).
Notes on legal bases: If we ask for consent to the use of the cloud services, the legal basis for processing is consent pursuant to Art. 6 (1) (a) GDPR. Furthermore, their use may be part of our (pre-)contractual services pursuant to Art. 6 (1) (b) GDPR, provided that the use of the cloud services has been agreed in this context. Otherwise, we process users' data on the basis of our legitimate interests pursuant to Art. 6 (1) (f) GDPR (interest in efficient and secure administrative and collaboration processes).
Types of data processed: inventory data (e.g. names, addresses), contact data (e.g. email addresses, telephone numbers), content data (e.g. text entries, photographs, videos), usage data (e.g. websites visited, interest in content, access times), meta and communication data (e.g. device information, IP addresses).
Data subjects: customers, employees (e.g. staff, applicants, former employees), prospective customers, communication partners.
Purposes of processing: office and organisational procedures.
Legal bases: consent (Art. 6 (1) sentence 1 (a) GDPR), performance of a contract and pre-contractual requests (Art. 6 (1) sentence 1 (b) GDPR), legitimate interests (Art. 6 (1) sentence 1 (f) GDPR), consent pursuant to Art. 6 (1) (a) GDPR for transfers to servers in the USA.
Services and service providers used:
Microsoft cloud services: cloud storage services; service provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; website: https://www.microsoft.com/de-de/; security information: www.microsoft.com/de-de/trustcenter.
14. Rights of use of legal notice data
We expressly object to the use by third parties of the contact data published in our legal notice and in this privacy policy for sending unsolicited advertising and information material.
We expressly reserve the right to take legal action in the event of unsolicited advertising information, for example by spam emails.