Privacy Policy
Version 1.6.1 · effective July 16, 2026
This English translation is provided for convenience only. The legally binding version is the German one.
1. Who we are
Here you can learn how we process personal data in connection with the use of this website. The following information applies to all persons who visit our website and use our offerings.
This privacy policy does not apply to our recruiting, nor to the processing of personal data within the Kultify platform. For the processing of data that our customers record in the Kultify platform, we conclude a separate data processing agreement (DPA) with the respective customer; this privacy policy does not apply to that processing.
Data protection, and in particular the General Data Protection Regulation (GDPR) applicable in the EU, is known to all Kultify employees and is part of their daily work.
Controller
Kultify GmbH, Lorenzer Platz 5A, 90402 Nuremberg, Germany
Phone: +49 911 477 116 001 · Email: info@kultify.de
We are responsible for this website, its content and the processing of personal data taking place on it. You can reach our data protection team at our postal address as well as by email at datenschutz@kultify.com.
Our data protection principles
- We lay our cards on the table.
- We process only the data we need for our work and our business.
- We process data only where we have a purpose and a legal basis for doing so.
- We secure our systems in line with the state of the art.
- We work with reliable service providers and review them regularly.
- We process and use data only for as long as necessary.
- We do not process sensitive data such as ethnic origin, political opinions, religious or philosophical beliefs and the like.
- We do not process data of children, as the use of our website and our offerings is not intended for persons under 16 years of age.
- We do not create a profile of you and do not make decisions based solely on automated processing.
Providing your personal data is neither legally nor contractually required. Without your data, however, we cannot send you information, offer you services or conclude a contract for the provision of Kultify.
2. When do we process your personal data?
You contact us or visit our website, whether out of curiosity about us and our work, because you are looking for something specific, or because our paths cross on the internet. To provide and use certain offerings, we need your data. So that you can better understand how we process your data, we have provided all the necessary information below.
You visit our website
When you visit our website, we process data about your browser, your operating system, your approximate location, your IP address and some others, in order to ensure the functionality of the website, the security of the connection and a good browsing experience. In addition, we process data for statistical and marketing purposes, in part with the support of service providers. For this processing we ask for your consent. A precise list of all cookies can be found via the cookie settings.
- Which data: IP address, browser type and version, time zone setting, browser plug-in types, approximate geolocation, operating system and version, click behaviour, returning visits, use of third-party services
- Purposes: statistics, optimisation, security, marketing
- Legal basis: legitimate interests (Art. 6(1)(f) GDPR) where the processing is technically necessary; for data that is not technically necessary, solely your consent (Art. 6(1)(a) GDPR, Sec. 25(1) TDDDG)
- Storage period: varies depending on the cookie and service, from the session duration up to 12 months; the specific storage periods of the individual services can be found in the respective sections below and in the cookie settings
You use our contact form, call us or send us an email
We are pleased that you are getting in touch, whether by web form, email or telephone. In doing so we process some of your data, such as your first and last name and your email address, in order to handle your request and to be able to contact you. We pass your data on to third parties only where this is necessary to handle your request.
- Which data: first and last name, company information, telephone number, email address, your request
- Purposes: handling your contact request, answering questions, feedback
- Legal basis: performance of pre-contractual measures or legitimate interest in answering your request (Art. 6(1)(b) and (f) GDPR)
- Storage period: until the purpose has been fulfilled
Provision of free information or events
When we make free information and knowledge content available to you, whether online or as part of our events, we need your data in order to be able to provide our offering to you.
If you subscribe to our newsletter, we need your consent. We first send you an email asking for confirmation. This two-step process is known as double opt-in and helps us ensure that we are actually communicating with you.
- Which data: depending on the request, first and last name, company information, telephone number, email address
- Purposes: provision of information, participation in and running of events (online or offline), relationship building, marketing or newsletter dispatch
- Legal basis: contract for the provision of free content in conjunction with your consent to marketing activities; for the newsletter, solely your consent (Art. 6(1)(a) and (b) GDPR)
- Storage period: three years since the contact's last activity or until you withdraw your consent
Interest in Kultify
If you are interested in learning more about our products and services, we offer you an expert consultation or a web demo. For this purpose we need your contact details (e.g. email address, first and last name).
- Which data: first and last name, company information, telephone number, email address
- Purposes: provision of consultation appointments and web demos, marketing, initiating a customer relationship
- Legal basis: performance of pre-contractual measures or contract (Art. 6(1)(b) GDPR)
- Storage period: three years since the contact's last activity for prospects; for customers, for the duration of the customer relationship plus statutory retention periods
You exercise your data subject rights
If you would like to exercise your data protection rights, please contact us. To ensure that you can exercise your rights, we must process some of your data, for instance to verify your identity and to answer your request.
- Which data: first and last name, address where applicable, email address, content of the request
- Purposes: handling data subject requests
- Legal basis: legal obligation (Art. 6(1)(c) GDPR)
- Storage period: 2 years
3. Trusted third parties that process your data
In the course of our business activities and to provide certain services, we use processors. This takes place in marketing and customer support, for online surveys, the display of videos, the operation of the website (hosting, cookie banner, security and provision) and more. We have concluded data processing agreements (DPAs) with these service providers and, when transferring your data to third countries, we ensure an adequate level of protection. This is achieved either through countries recognised as safe by the EU (adequacy decision), through specific approved contracts (standard contractual clauses), or, where necessary, by obtaining your explicit consent.
Detailed information on the services used can be found in the settings options of the cookie banner, via the “Cookie settings” link at the bottom of every page of the website.
4. Analytics tools and third-party services
Consent management
We manage your consent to the use of cookies and comparable technologies via a self-hosted consent tool integrated directly into our website. No external consent-management provider (such as Cybot/Cookiebot) is used. The consent banner itself loads no third-party content; your browser does not connect to any service provider.
We store your selection in two places. First, locally on your device, namely in a first-party cookie (technical name cc_cookie) together with the time of your decision; the cc_cookie cookie is stored on your device for about 6 months (182 days). It serves to avoid asking you again on every visit.
Second, we record every consent decision on our server, both a grant and a refusal. We are legally required to be able to demonstrate a consent that has been given (Art. 7(1) GDPR); without such a record we would also be unable to show that we did not track you after a refusal. We record: a randomly generated identifier for your decision, the time, the categories you accepted and rejected, the version of the consent banner and of this privacy notice, and your browser identifier (user agent). We do not store your IP address. The legal basis is our legal obligation (Art. 6(1)(c) in conjunction with Art. 7(1) GDPR). Consent is neither required nor possible for this, because the record is precisely the evidence of your decision.
The record is stored in a database of the Bunny Database service (provider: BunnyWay d.o.o., see the section on Bunny.net below), which we operate in the Frankfurt (Germany) region. The data does not leave the EU. We have concluded a data processing agreement with BunnyWay. The data is transmitted solely from our server; your browser does not connect to this database. We delete the log entries after three years.
Operating the consent tool itself is technically necessary and serves our legitimate interest in legally compliant consent management (Art. 6(1)(f) GDPR). The non-essential cookies and services that the tool gates are set solely with your consent (Art. 6(1)(a) GDPR, Sec. 25(1) TDDDG).
Plausible Analytics
We use Plausible Analytics to statistically evaluate the use of our website and to improve our offering. The provider is Plausible Insights OÜ, Estonia. Plausible works in a privacy-friendly manner, sets no cookies and does not create cross-device profiles. No information is stored on or read from your device, so no consent under Sec. 25 TDDDG is required for this; only aggregated data that cannot be traced back to you is processed. The data is processed within the EU; reach measurement runs first-party via our own domain (kultify.de), so that your browser does not connect directly to Plausible.
The legal basis is our legitimate interest in privacy-friendly reach measurement (Art. 6(1)(f) GDPR); no consent is required for this. You have the right to object to this processing. Further information at plausible.io/data-policy.
PostHog
We use the analytics tool PostHog to analyse user behaviour on our website and to improve our online offering. The provider is PostHog, Inc., USA. Processing and storage take place on servers within the European Union (EU hosting). No sensitive data such as health data is collected. The cookies set by PostHog (ph_*) are stored on your device for up to 12 months.
The legal basis is your consent (Art. 6(1)(a) GDPR, Sec. 25(1) TDDDG). Your data is stored only for as long as is necessary for the stated purposes or required by law. You can withdraw your consent at any time. Further information can be found in PostHog’s privacy policy at posthog.com/privacy. Objection requests can be directed to privacy@posthog.com.
HubSpot
For our customer relationship management (CRM), the processing of form requests, appointment booking and for marketing purposes, we use HubSpot. The provider is HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland (parent company: HubSpot, Inc., USA). Data processing takes place via servers within the EU. HubSpot may set cookies to recognise your interaction with our website. The cookies set by HubSpot are stored for varying periods: __hstc and hubspotutk for up to 6 months, __hssc for 30 minutes and __hssrc for the duration of the session.
The legal basis for processing form and booking requests is the performance of (pre-)contractual measures or our legitimate interest (Art. 6(1)(b) and (f) GDPR). For setting non-essential cookies, we rely on your consent (Art. 6(1)(a) GDPR, Sec. 25(1) TDDDG).
Where personal data is thereby transferred to HubSpot, Inc. in the USA, this transfer is safeguarded by the EU-U.S. Data Privacy Framework. With its adequacy decision of 10 July 2023 (Decision (EU) 2023/1795), the European Commission determined that an adequate level of data protection exists for US companies certified under this framework; HubSpot, Inc. is certified under the EU-U.S. Data Privacy Framework. Further information at legal.hubspot.com/de/privacy-policy.
Advertising attribution (ktfy_ad)
In order to attribute enquiries to the correct advertising campaigns, we set our own first-party marketing cookie with the technical name ktfy_ad. In it we store advertising click identifiers (e.g. Google gclid, Meta fbclid and the corresponding identifiers from Microsoft, LinkedIn, TikTok and X) and UTM parameters that are passed when our website is opened via an advertisement. If you later submit an enquiry, we can attribute it to the original advertising campaign (campaign attribution).
The ktfy_ad cookie is stored on your device for 90 days and is set solely after your consent to marketing. Where the stored click identifiers are transmitted to the respective advertising platform (e.g. Google Ads) for success measurement, this takes place for the purpose of conversion measurement; details on the transmission to Google Ads can be found in the "Google Ads" section below.
The legal basis is your consent (Art. 6(1)(a) GDPR, Sec. 25(1) TDDDG). Consent can be withdrawn at any time.
Google Ads (conversion measurement)
To measure the success of our advertising, upon a completed enquiry we transmit to Google, server-side, your SHA-256-hashed email address and the Google click identifier (gclid/gbraid/wbraid) from the ktfy_ad cookie. No cookie is set in the process and your browser does not connect to Google. The provider is Google Ireland Limited, Dublin, Ireland (parent company: Google LLC, USA). The transmission only takes place if you have previously consented to the marketing category.
The legal basis is your consent (Art. 6(1)(a) GDPR, Sec. 25(1) TDDDG). You can withdraw it at any time with effect for the future via the cookie settings (Art. 7(3) GDPR); the lawfulness of the transmission carried out before the withdrawal remains unaffected. Where data is thereby transferred to Google LLC in the USA, this is safeguarded by the adequacy decision for the EU-U.S. Data Privacy Framework, under which Google LLC is certified. Further information at policies.google.com/privacy.
Crisp (help chat)
For our help chat on the website we use Crisp. The provider is Crisp IM SAS, 2 boulevard de Launay, 44100 Nantes, France. The chat is loaded only after you have consented to the “Help chat” category; before that, nothing is loaded from Crisp and nothing is stored on your device.
After your consent, Crisp stores a cookie (crisp-client/session/…) on your device with a default storage period of 6 months, together with entries in local storage under crisp-client/* which we delete at the latest when you withdraw your consent. These serve to recognise your chat session so that a conversation is retained across a page navigation. When you use the chat, we process the messages you enter and, if you provide them, your name and email address, timestamps and technical metadata of your visit.
The chat data is stored within the EU (messaging data in the Netherlands, plugin data in Germany). In addition, Crisp operates relay servers in the USA, the United Kingdom and Singapore, which store no chat content but log connection data (IP address, time of the connection, user agent and referring website). Insofar as this constitutes a transfer to a third country without an adequacy decision (USA, Singapore), it is safeguarded by standard contractual clauses pursuant to Art. 46(2)(c) GDPR; for the United Kingdom, an adequacy decision of the European Commission exists.
Empty chat sessions in which no message was sent expire about 30 minutes after your last visit. Sessions containing messages are stored by us until the purpose ceases and are then deleted.
The legal basis is your consent (Art. 6(1)(a) GDPR, Sec. 25(1) TDDDG); consent can be withdrawn at any time. We have concluded a data processing agreement with Crisp. Further information at crisp.chat/privacy.
Screening of form submissions for bots (Mistral AI)
When you submit one of our web forms, the submitted data is checked by an AI model to determine whether the submission originates from a bot or spammer. The provider is Mistral AI SAS, 15 rue des Halles, 75001 Paris, France; the model mistral-small-latest is used via Mistral's API. Transmitted in the process are the data you entered in the form (name, company, email address, telephone number, number of employees, interests and your message) and the time you took to fill in the form. No cookie is set and nothing is read from your device, so Sec. 25 TDDDG does not apply.
A submission is never discarded solely on the basis of the AI's assessment; a case classified as suspicious is merely flagged for manual review by a person. Mistral stores inputs and outputs for 30 days for abuse monitoring and does not use them to train its models (paid API). Processing takes place on servers in the EU; where Mistral transfers data to a third country, it relies on adequacy decisions or standard contractual clauses. We have concluded a data processing agreement with Mistral.
The legal basis is our legitimate interest in preventing spam and automated submissions and thus in the security of our network and information systems (Art. 6(1)(f) GDPR, cf. Recital 49). Further information at legal.mistral.ai/terms/privacy-policy.
Bunny.net (video delivery and consent record)
The provider is BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia. We use two services from this provider. We have concluded a data processing agreement with BunnyWay. Further information at bunny.net/privacy.
Video delivery. To deliver videos, for instance customer testimonials, we use the content delivery service Bunny.net. When you play a video, your IP address is transmitted to Bunny.net so that the video content can be delivered to your browser. The legal basis is your consent or our legitimate interest in fast and reliable delivery of the content (Art. 6(1)(a) and (f) GDPR).
Consent record (Bunny Database). In a database of the Bunny Database service, which we operate in the Frankfurt (Germany) region, we store the record of your consent decisions (see the "Consent management" section above). Your browser does not connect to Bunny.net for this; the data is transmitted solely from our server and does not leave the EU. No IP address is stored. The legal basis is our legal obligation to be able to demonstrate a consent (Art. 6(1)(c) in conjunction with Art. 7(1) GDPR). The retention period is three years.
Hosting (OVH)
This website is hosted by OVH. The provider is OVH GmbH, Dürerstraße 24, 50668 Cologne, Germany. The servers are located in Germany. When the website is accessed, OVH processes server log data including your IP address in order to ensure the delivery and security of the website. These server log data are stored for 90 days for security purposes and then deleted.
The legal basis is our legitimate interest in the secure and reliable operation of the website (Art. 6(1)(f) GDPR). We have concluded a data processing agreement with OVH. Processing takes place exclusively within the EU.
Error monitoring (GlitchTip, self-hosted)
In order to detect and fix software errors on this website, we operate the open-source tool GlitchTip on our own infrastructure at errors.kultify.com. The servers are located at Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; processing takes place exclusively in Germany. No external error-monitoring provider is involved, and the error data does not leave the EU. We have concluded a data processing agreement with Hetzner.
We record the error message and the associated program flow (stack trace), the address accessed (URL), your browser and operating system, and the time of the error. No account or form data is transmitted; IP addresses are anonymised before storage. GlitchTip sets no cookie and stores no information on your device. Error data is deleted after 90 days.
- Errors in your browser: The error report is only transmitted if you have consented to the “Analytics” category. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can withdraw it at any time, with effect for the future, via the cookie settings.
- Errors on our server and reports of Content Security Policy (CSP) violations: These arise on our side, or are reported by the browser on the basis of a security directive in the response header; they are necessary for the secure and stable operation of the website. The legal basis is our legitimate interest in the security of our network and information systems (Art. 6(1)(f) GDPR, cf. recital 49). No consent is required for this.
Right to object (Art. 21(4) GDPR): You have the right to object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR. Please address your objection to datenschutz@kultify.com.
5. International data transfers
In specific cases, the data collected in connection with this website may be passed on to third parties located in countries outside the European Economic Area (EEA), for instance in the USA. Some of these countries may not have the same data protection laws as the EEA. In particular, these countries may not offer the same level of protection for your personal data, may not grant you the same rights, and may not have a data protection supervisory authority that can assist you with concerns.
When transferring your personal data outside the EEA, we ensure, where the applicable data protection laws require it, that at least one of the following safeguards is implemented: (1) we transfer your data only to countries or organisations that, in the opinion of the European Commission, provide an adequate level of protection (adequacy decision, e.g. the EU-U.S. Data Privacy Framework); or (2) we use contracts approved by the European Commission, commonly known as “standard contractual clauses”. For the transfer to our US service provider HubSpot, Inc., we rely on the adequacy decision for the EU-U.S. Data Privacy Framework (Decision (EU) 2023/1795), under which HubSpot, Inc. is certified (see the HubSpot section above). For the transfer to Google LLC (USA) in the context of conversion measurement, we likewise rely on the adequacy decision for the EU-U.S. Data Privacy Framework, under which Google LLC is certified (see the Google Ads section above). For the connection data logged by the relay servers of our chat provider Crisp IM SAS in the USA and Singapore, we rely on standard contractual clauses pursuant to Art. 46(2)(c) GDPR (see the Crisp section above). Please contact us if you would like further information on the specific mechanisms.
6. How we use cookies
Cookies are text information stored on your device via the internet browser. Cookies have various functions.
Technically necessary cookies are required to ensure the website functions. Without them the website would not work. We do not need consent for these (Sec. 25(2) TDDDG). For all other cookies, that is functional cookies, marketing cookies, help-chat cookies and those for displaying videos, we ask for your consent (Sec. 25(1) TDDDG).
We manage your consent via a self-hosted consent tool. You can change or withdraw your selection at any time by reopening the cookie settings via the “Cookie settings” link at the bottom of every page.
7. Data security
For security reasons and to protect the transmission of personal data and other confidential content, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that the browser's address bar changes from “http://” to “https://” and by the padlock symbol in your browser bar. When SSL/TLS encryption is active, the data you transmit to us cannot be read by third parties.
8. Your data protection rights
You have the right to be informed about the processing of your personal data. We provide this information with this privacy policy. In addition, you have the right of access, the right to rectification, the right to erasure and the right to restriction of processing. You have the right to a copy of the data we process and may withdraw any consent given at any time with effect for the future. Where we process data on the basis of legitimate interest, you have the right to object. Where we process your personal data by automated means on the basis of your consent or for the performance of a contract, you also have the right to data portability (Art. 20 GDPR); on request, we will provide the data you have given us in a structured, commonly used and machine-readable format.
To do so, please use our contact form or contact our data protection officer directly at datenschutz@kultify.com.
We would prefer that, in the event of a complaint, you first contact us. However, you have the right to lodge a complaint directly with the supervisory authority responsible for Kultify GmbH. Our competent authority is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht), Promenade 18, 91522 Ansbach, Germany, telephone: +49 981 180093-0, email: poststelle@lda.bayern.de.
A list of supervisory authorities in the EEA and their contact details can be found at edpb.europa.eu/about-edpb/about-edpb/members.
9. Data protection officer
Kultify GmbH has appointed Jan Kühnlein as internal data protection officer. You can reach him at:
Kultify GmbH – Data Protection Officer, Lorenzer Platz 5A, 90402 Nuremberg, Germany
Email: datenschutz@kultify.com
10. General terms and conditions
All information on our general terms and conditions and our data processing agreement can be found under Terms and Conditions.
Last updated: July 2026
Change history
- v1.0.0 (2024-04-01): First version based on the privacy notice published on the website, extended with data security (SSL/TLS), server log retention (90 days) and the right to data portability (Art. 20 GDPR).
- v1.1.0 (2026-07-08): Consent management moved from Cookiebot to a self-hosted tool; consent is stored locally in the first-party cookie
cc_cookie. Legal basis for operating it: legitimate interest (Art. 6(1)(f) GDPR). - v1.2.0 (2026-07-08): Per-service retention periods added (
cc_cookie, PostHog, HubSpot). Marketing cookiektfy_adadded. Legal basis for Plausible restated (legitimate interest, cookieless). Transfer to HubSpot identified as covered by the EU-U.S. Data Privacy Framework. - v1.3.0 (2026-07-10): Crisp help chat added, including its relay servers in the USA, the United Kingdom and Singapore and the standard contractual clauses (Art. 46(2)(c) GDPR). AI-supported bot screening of form submissions via Mistral AI added.
- v1.3.1 (2026-07-10): Help-chat details clarified: cookie name
crisp-client/session/…, retention 6 months, local storage until consent is withdrawn. - v1.3.2 (2026-07-10): Address of BunnyWay d.o.o. updated (Dunajska cesta 165, 1000 Ljubljana, Slovenia).
- v1.3.3 (2026-07-12): Retention for lead and customer contact data updated to three years since the contact's last activity, matching the retention policy held in the CRM.
- v1.4.0 (2026-07-13): Error monitoring via self-hosted GlitchTip added (Hetzner, Germany). Browser errors after consent to "Analytics", server-side errors on legitimate interest; IP anonymised, no cookie, 90 days.
- v1.5.0 (2026-07-14): Server-side consent record added (Art. 7(1) GDPR). Stored are an identifier, timestamp, categories, banner and notice version and user agent, without IP address; Bunny Database, Frankfurt region, deleted after three years.
- v1.6.0 (2026-07-16): Conversion measurement via Google Ads added (hashed email address and click identifier, consent under Art. 6(1)(a) GDPR; transfer covered by the EU-U.S. Data Privacy Framework). Plausible section clarified (first-party via our own domain).
- v1.6.1 (2026-07-17): Change history shortened and restated.