Scope and controller
This policy covers deimann.com, its preview at neu.deimann.com, Deimann Exchange and the contact and business-assessment flows embedded in this website. Other products and external websites have their own privacy policies. A tool appearing on our operating stack does not mean that it receives data from every visitor to this website.
Deimann Com GmbHRandstraße 75, 22525 Hamburg, Germany
Represented by Janik Deimann
[email protected]
Our data protection officer is Rechtsanwalt Jan Marschner, Rechtsanwaltskanzlei Jan Marschner, Markt 9, 04109 Leipzig, Germany. Telephone: +49 (0) 341 2618 9373. Email: [email protected].
Website delivery and security
This website is hosted on Cloudflare Pages, provided by Cloudflare, Inc., USA. When you visit, technical request data can include your IP address, the requested URL, date and time, browser information and referrer. Cloudflare and our application infrastructure process this data to deliver the site, protect access and investigate faults or abuse.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are a working, secure website and the prevention of abuse. Embedding a Konfigurator.io form also creates a connection to that service, which runs on Cloudflare Workers.
Contact and Exchange enquiries
If you email us or submit an enquiry, we process the information you provide to understand and answer it. The contact flow asks for your name, email, topic and message, and may ask for your organisation. Follow-up questions depend on the topic and can include your website, product, publication, role, acquisition criteria, budget or timing.
Exchange requests may include business details, earnings, revenue, costs, operating effort and your objectives as a seller or buyer. We use these details to prepare or discuss the requested assessment, review access to private materials and follow up on your enquiry. Please omit personal data about other people unless it is needed for the request and you are entitled to provide it.
Where processing is necessary to take steps at your request before entering into a contract, or to perform a contract with you, the basis is Article 6(1)(b) GDPR. For other correspondence, including enquiries made on behalf of an organisation, the basis is Article 6(1)(f) GDPR: our interest in responding to relevant business enquiries.
Providing information is voluntary. Without the required contact details and information about your request, we may be unable to answer it or provide the requested access. Submitting a form does not subscribe you to marketing.
Embedded forms and assessment results
Our contact flow and Exchange business assessment use Konfigurator.io, software operated by Deimann Com GmbH. Answers remain in the form’s browser memory until you submit the request. The embedded form sends display-height and step information to this page; it does not send your answers to the parent page through that channel.
The Exchange assessment can generate a downloadable brief in your browser before you decide whether to request a personal review. Submitting that optional request sends your contact details and assessment information to our intake. Calculations use the figures you enter. They do not determine whether we accept an enquiry or grant access to a business.
Flow-specific details are available in the contact flow privacy notice and the Exchange assessment privacy notice.
Intake, notifications and email receipts
Submitted enquiries are stored in our shared Lead Inbox on server infrastructure provided by Hetzner Online GmbH in Germany. Enquiries with the same email address can be grouped within the relevant intake source. Lead notifications are routed through our internal notification service to Slack. Notifications can contain your contact details and the contents of your enquiry, so the relevant team can respond.
Legacy Exchange forms record the submitting IP address and browser information alongside the request. Konfigurator.io uses technical request data for abuse prevention and rate limiting; it does not forward the visitor’s IP address or browser information in the enquiry payload to the inbox.
For the Deimann contact flow, we use Resend (Plus Five Five, Inc., USA) to send an email receipt. Resend receives the recipient’s email address and the receipt content, but the receipt does not include your form answers. Delivery and failure events are processed so we can check receipt delivery. Open and click tracking are disabled for these receipts. Replies go to [email protected].
If a team member uses the inbox’s optional AI follow-up suggestion for a note, the note text is sent to Anthropic, USA, to suggest a follow-up date. This assists internal organisation; it does not automatically accept, reject or value your business. The guided contact and assessment flows are excluded from the inbox’s AI provider-offer filter. The basis for enquiry routing, notifications and internal follow-up assistance is Article 6(1)(f) GDPR, where Article 6(1)(b) does not apply.
Service providers and international transfers
Cloudflare provides delivery and security; Hetzner provides server infrastructure; Slack provides team notifications; Resend provides receipt delivery. Anthropic is involved when the optional note-assistance function described above is used. Authorised team members and service providers supporting these tasks may access the data needed for their work. Data can also be disclosed where a legal obligation requires it, under Article 6(1)(c) GDPR.
Providers based in the United States may process data outside the European Economic Area. International transfers require a basis under Chapter V GDPR, such as an applicable adequacy decision or standard contractual clauses with the necessary additional safeguards. The providers’ data processing terms describe their transfer arrangements: Cloudflare, Slack, Resend and Anthropic. Contact our data protection contact for information about the safeguards applicable to your data or a copy of the relevant safeguards.
Storage and deletion
No automatic deletion period is currently configured for enquiries in the shared intake. These records remain stored until manually deleted. This describes the current technical setup; it does not justify keeping personal data indefinitely.
The appropriate storage period depends on the purpose and status of the enquiry, any ongoing business relationship, applicable statutory retention duties and the need to establish, exercise or defend legal claims. Data no longer needed for those purposes must be deleted. Provider-held technical logs and delivery records may have separate storage periods under the applicable service settings and agreements.
You can ask about the records relating to you or request their deletion at [email protected]. A legal retention duty or another applicable exception may prevent immediate deletion of some records.
Cookies and browser storage
This website does not currently embed analytics or advertising trackers. We use necessary access cookies for protected materials: the Media login cookie lasts 30 days and becomes invalid after a password change. An Exchange exposé access cookie expires with its access grant; that grant can be revoked.
These cookies provide access you explicitly request. Necessary storage or access is covered by section 25(2)(2) TDDDG; the associated personal-data processing rests on Article 6(1)(b) or (f) GDPR according to the purpose. Non-essential storage or tracking would require a separate assessment and, where required, your prior consent. Reading this policy or browsing the website is not consent.
Your rights
Subject to the conditions in the GDPR, you can request access to your personal data, correction of inaccurate data, deletion or restriction of processing. Where processing is based on consent or a contract and carried out by automated means, you can request data portability.
If processing relies on your consent, you can withdraw it at any time with effect for the future. Withdrawal does not affect the lawfulness of earlier processing. The website and enquiry processing described above do not rely on a blanket consent to this policy.
We do not use these website flows to make decisions based solely on automated processing that produce legal or similarly significant effects concerning you. An indicative calculation or an internal follow-up suggestion is not such a decision.
To exercise your rights, contact [email protected]. We may need proportionate information to verify your identity before disclosing or changing personal data.
Complaints and updates
You can complain to a data protection supervisory authority, including one in the EU member state where you live, work or where the alleged infringement took place. Our local authority is the Hamburg Commissioner for Data Protection and Freedom of Information.
We update this policy when the relevant processing changes. The date above records the latest content update; a new website deployment alone does not change it.


