Data Security

Privacy Policy of PromptingBirds GmbH

1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

PromptingBirds GmbH
Werinherstr. 3
81541 Munich, Germany
Represented by the Managing Directors: Daniel Frystacki, Sascha Frystacki
Phone: +49 89 20174032
Email: info@promptingbirds.com

2. General Information on Data Processing

As a matter of principle, we process our users’ personal data only to the extent necessary to provide a functional website as well as our content and services, or where consent has been given. Depending on the processing activity, the legal bases are Art. 6(1)(a) GDPR (consent), (b) (contract or pre-contractual measures), (c) (legal obligation) or (f) (legitimate interest). For each processing activity below, we state the relevant legal basis, the storage period and any recipients.

Where we use service providers that process personal data on our behalf, this is done on the basis of data processing agreements pursuant to Art. 28 GDPR.

3. Hosting and Server Log Files

This website is hosted by Host Europe GmbH (Hansestraße 111, 51149 Cologne, Germany; a brand of the GoDaddy group); the server location is in Germany. When the website is accessed, the host automatically collects data on our behalf in so-called server log files: the page visited, the date and time of access, the volume of data transferred, the source/referrer, the browser type and version, the operating system and the IP address.

This processing is carried out on the basis of our legitimate interest in the secure and stable operation of the website (Art. 6(1)(f) GDPR). Log files are deleted as soon as they are no longer required for the purpose for which they were collected, generally after no more than 14 days. A data processing agreement pursuant to Art. 28 GDPR is in place with the host.

This website uses TLS/SSL encryption. As a result, data you transmit to us cannot be read by third parties.

4. Cookies and Consent Management (CookieYes)

This website uses cookies and comparable technologies. We use technically necessary cookies on the basis of Section 25(2) TDDDG (German Telecommunications Digital Services Data Protection Act) and Art. 6(1)(f) GDPR. All non-essential cookies (e.g. statistics/analytics) are only set after you have given your consent via our consent banner (Section 25(1) TDDDG, Art. 6(1)(a) GDPR).

To manage your consent, we use the consent manager CookieYes (CookieYes Limited, 3 Warren Yard, Warren Park, Stratford Road, Wolverton Mill, Milton Keynes, MK12 5NW, United Kingdom). CookieYes stores your consent decision in a cookie on your device (storage period: up to 12 months). The legal basis is Art. 6(1)(c) GDPR (obligation to demonstrate consent) as well as (f) GDPR.

You can withdraw or adjust your consent at any time with effect for the future by reopening the cookie settings via the corresponding icon or the link in the website footer.

5. Contacting Us: Contact Form, Email and CRM System

If you contact us via the contact form, by email or by telephone, we process the data you provide (in particular your name, email address, and where applicable your telephone number and company, as well as the content of your message) in order to handle and respond to your enquiry.

This processing is carried out to perform pre-contractual measures or to fulfil a contract (Art. 6(1)(b) GDPR) and on the basis of our legitimate interest in efficiently handling enquiries (Art. 6(1)(f) GDPR).

CRM system: To handle and organise enquiries, we use a self-hosted CRM/ERP system (ERPNext). It runs on infrastructure rented by us from Microsoft Ireland Operations Limited (One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland; “Microsoft Azure”). The server location is exclusively in Germany (Frankfurt am Main region). The information you submit via the contact form is stored directly in this system; the form is technically embedded from our own system (erp.promptingbirds.com). A data processing agreement pursuant to Art. 28 GDPR (Microsoft Products and Services Data Protection Addendum) including EU Standard Contractual Clauses is in place with Microsoft.

Email communication: For our email communication we use Microsoft 365 (Microsoft Ireland Operations Limited). Email correspondence relating to your enquiry may be linked to your enquiry in our CRM system so that the responsible team can follow up on and answer it.

Storage period: We delete enquiry data as soon as it is no longer required for processing, at the latest 12 months after the enquiry has been concluded — unless a business relationship arises, in which case the retention periods under commercial and tax law apply (Section 257 HGB / German Commercial Code, Section 147 AO / German Fiscal Code). As part of our daily backups, data is additionally retained for 30 days in encrypted backups (Microsoft Azure, Germany).

6. Spam Protection (hCaptcha)

To protect our forms against abusive automated use, we use the hCaptcha service (Intuition Machines, Inc., 2211 Selig Drive, Los Angeles, CA 90026, USA). hCaptcha checks whether an entry is made by a human and may process hardware and software information (e.g. device and application data) for this purpose. The legal basis is our legitimate interest in protecting the website against misuse and spam (Art. 6(1)(f) GDPR). Insofar as data is transferred to the USA, the transfer is based on the EU Standard Contractual Clauses or a certification under the EU-U.S. Data Privacy Framework.

7. Web Analytics: Google Analytics 4 (via Google Site Kit)

On the basis of your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you can give via our cookie banner, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). It is integrated via the WordPress plugin “Site Kit by Google”.

Google Analytics uses cookies and similar technologies to analyse your use of the website (e.g. pages viewed, time spent, approximate location, device used). IP addresses are not stored in Google Analytics 4; transmitted IP data is truncated before processing or used only for rough geolocation. Data may be transferred to servers of Google LLC in the USA; Google LLC is certified under the EU-U.S. Data Privacy Framework, and the EU Standard Contractual Clauses apply in addition.

The analytics data we collect is deleted after 14 months. You can withdraw your consent at any time via the cookie settings (footer) with effect for the future.

8. Appointment Booking

Using the “Book an appointment” or “Book a consultation” buttons, you can arrange an appointment with us online. For this we use Microsoft Bookings (Microsoft Ireland Operations Limited). We process the data you provide when booking (name, email address, selected appointment, and where applicable your request) in order to arrange and hold the appointment (Art. 6(1)(b) GDPR). Microsoft’s privacy notices additionally apply.

9. Online Shop (WooCommerce)

If you place an order through our online shop, we process the data required to perform the contract: name, address, email address, where applicable telephone number, as well as order and payment data (Art. 6(1)(b) GDPR).

Payment is made by invoice (bank transfer); we do not use external payment service providers and do not pass on your data to third parties for payment purposes. We retain invoice and accounting data in accordance with our commercial and tax law obligations (Section 257 HGB, Section 147 AO); thereafter it is deleted.

10. Job Applications

If you apply to us — whether via an application form provided on our website or by email — we process the applicant data you submit in order to decide on the establishment of an employment relationship and to carry out the application process.

In particular, we process your contact and master data (name, address, email address, telephone number), the information contained in your cover letter, CV and references, as well as any further information you provide to us as part of your application.

The legal basis is Section 26(1) BDSG (German Federal Data Protection Act) in conjunction with Art. 6(1)(b) GDPR (processing to decide on the establishment of an employment relationship). Insofar as we process applicant data beyond this — for example to safeguard legitimate interests or to comply with legal obligations — we base this on Art. 6(1)(f) or (c) GDPR. Providing the data is voluntary; however, without the information required for assessment we cannot consider your application.

Your applicant data is accessed exclusively by the persons involved in the application process (in particular HR staff and the decision-makers responsible for the advertised position). For processing and storage we use our self-operated infrastructure hosted in Germany (Microsoft Azure, Frankfurt am Main region) as well as Microsoft 365 for email communication; a data processing agreement pursuant to Art. 28 GDPR is in place in each case.

If an employment relationship is established, we store your data in your personnel file for the purpose of carrying out the employment relationship. Otherwise, we delete your applicant data at the latest six months after the application process has been concluded, unless statutory retention obligations apply or you have expressly consented to longer storage — for example for inclusion in a talent pool. The six-month period takes into account possible claims under the German General Equal Treatment Act (AGG).

11. Social Media and External Links

On our website we link to our profiles on LinkedIn, YouTube, Instagram, Spotify and Apple Podcasts. These are plain links — simply visiting our website does not transfer any data to these providers. The respective provider’s privacy terms only apply once you follow a link.

12. Your Rights as a Data Subject

You have the following rights with regard to the personal data concerning you:

the right of access (Art. 15 GDPR), the right to rectification (Art. 16 GDPR), the right to erasure (Art. 17 GDPR), the right to restriction of processing (Art. 18 GDPR) and the right to data portability (Art. 20 GDPR). You can withdraw any consent you have given at any time with effect for the future (Art. 7(3) GDPR).

Right to object (Art. 21 GDPR): Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation, to the processing.

To exercise your rights, an informal message to info@promptingbirds.com is sufficient.

You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.

13. Changes to This Privacy Policy

We reserve the right to amend this privacy policy so that it always complies with current legal requirements or in order to reflect changes to our services. The version published on this page at the relevant time applies.

Last updated: July 2026