Palancart
ImprintPrivacyGerman version

Legal

Privacy Policy

Last updated: July 2026

With this Privacy Policy, we inform visitors to our website as well as prospects, customers, partners and other contact persons about how we process personal data.

Personal data means any information relating to an identified or identifiable natural person. This includes, for example, name, email address, telephone number, company affiliation, IP address, communication content or technical usage data.

We process personal data only where this is necessary, where a legal basis exists or where consent has been given.

1. Controller

The controller responsible for data processing within the meaning of the General Data Protection Regulation is:

Palancart UG (haftungsbeschränkt)
Boschstr. 15
69214 Eppelheim
Germany

Represented by

Hotniel Henriques Mateque, Managing Director

Email: contact@palancart.de
Phone: +49 304 3979 2922
Website: www.palancart.com

2. Privacy contact

If you have any questions about privacy, wish to exercise your rights or have questions about this Privacy Policy, you may contact us at any time:

Email: contact@palancart.de

If a data protection officer is appointed in the future, the corresponding contact details will be added here.

3. Hosting and technical provision of the website

Our website is technically provided through a hosting and infrastructure service provider. As of now, we use Vercel for this purpose.

Provider

Vercel Inc.
340 S Lemon Ave #4133
Walnut, CA 91789
USA

When our website is accessed, technically necessary data is processed so that the website can be delivered, operated securely and optimized. This may include, in particular, the following data:

  • IP address
  • Date and time of access
  • Pages and files accessed
  • Referrer URL
  • Browser type and browser version
  • Operating system
  • Device type
  • Technical request information
  • Error messages and performance data

The processing is carried out for the technical provision, security, stability and optimization of our website. The legal basis is Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the secure, fast and reliable operation of our online presence.

Where processing is connected with pre-contractual or contractual inquiries, Art. 6 para. 1 lit. b GDPR also applies.

Where required, we conclude data processing agreements pursuant to Art. 28 GDPR with the service providers we use.

4. Server log files

When you visit our website, information transmitted automatically by your browser or device to the server is processed. This information is technically required to display the website and ensure operational security.

Server log files may include:

  • IP address
  • Date and time of the request
  • Time zone difference
  • Content of the request
  • HTTP status code
  • Amount of data transferred
  • Website from which the request originates
  • Browser
  • Operating system
  • Language and version of the browser software
  • Device type

The data is not used to personally identify individual visitors. It is not combined with other data sources unless this is necessary to investigate security-related incidents or to enforce legal rights.

The legal basis is Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the technical functionality, security and error analysis of our website.

5. SSL and TLS encryption

Our website uses SSL or TLS encryption for security reasons. You can recognize an encrypted connection by the fact that the browser address line begins with https:// and a lock symbol is displayed.

When SSL or TLS encryption is activated, data that you transmit to us cannot readily be read by third parties according to the current state of the art.

6. Contact by email, telephone or contact form

If you contact us, we process the data you provide in order to handle your inquiry. This may include:

  • Name
  • Email address
  • Telephone number
  • Company
  • Position or role
  • Content of the inquiry
  • Communication history
  • Technical metadata of the communication
  • Documents or information voluntarily provided by you, if any

Processing is carried out to handle your inquiry. If your contact is aimed at entering into or performing a contract, processing is based on Art. 6 para. 1 lit. b GDPR.

In all other cases, we process the data on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in efficiently handling inquiries and communicating with prospects, customers and partners.

If you give us consent, processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR.

We store contact inquiries only for as long as this is necessary to handle them or as long as statutory retention obligations apply. Business and tax-relevant communication may be stored for longer in accordance with statutory requirements.

7. Downloads of guides, whitepapers and materials

We may provide content such as guides, whitepapers, checklists or other materials on our website. If a download is possible without entering personal data, we process only technically required access data for this purpose.

If we connect the download with a form, scorecard or registration, we process the data you provide. This may include:

  • Name
  • Email address
  • Company
  • Role or position
  • Country or target market
  • Information about product, company, compliance maturity or security needs
  • Answers to qualification questions
  • Time of the request
  • Consent and proof data

Processing is carried out to provide the requested content, handle your inquiry and, where applicable, prepare a consultation.

The legal basis is Art. 6 para. 1 lit. b GDPR where processing is necessary to provide the requested content or to carry out pre-contractual measures. In addition, processing may be based on Art. 6 para. 1 lit. f GDPR if we have a legitimate interest in qualifying business inquiries and improving our offerings.

If we send you promotional information or further content only on the basis of your consent, processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR.

8. Lead qualification, scorecards and embedded forms

We may use interactive forms, scorecards or qualification flows on our website to better understand the requirements, risks or open questions of prospects. Heyflow may be used for this purpose.

Provider

Heyflow GmbH
Jungfernstieg 49
20354 Hamburg
Germany

When such forms are used, the following data in particular may be processed:

  • Contact details
  • Company data
  • Answers to questions within the scorecard
  • Selected options
  • Calculated score values or categories
  • Time of use
  • Technical usage data
  • Consent and proof data

Processing serves to provide the form, evaluate your information, qualify your inquiry and prepare possible next steps, for example a consultation.

The legal basis is Art. 6 para. 1 lit. b GDPR where processing is necessary to carry out pre-contractual measures. Otherwise, processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the structured, efficient and traceable handling of business inquiries.

Where consent is obtained for certain processing operations, processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR.

9. CRM, contact management and sales processes

We may use a CRM system to manage inquiries, contacts, conversation notes, pipeline information and customer relationships. As of now, we use HubSpot for this purpose.

Provider

HubSpot Ireland Limited
1 Sir John Rogersons Quay
Dublin 2
Ireland

Parent company

HubSpot, Inc.
25 First Street
Cambridge, MA 02141
USA

In HubSpot, the following data in particular may be processed:

  • Name
  • Email address
  • Telephone number
  • Company
  • Position or role
  • Country or market
  • Communication history
  • Form responses
  • Appointment bookings
  • Interests and requested services
  • Status in the sales process
  • Consent and opt-out information
  • Technical interaction data, where tracking is enabled

Processing serves the structured handling of inquiries, maintaining customer and prospect relationships, documenting communication, and preparing and conducting business relationships.

The legal basis is Art. 6 para. 1 lit. b GDPR where processing is necessary to carry out pre-contractual or contractual measures. In addition, processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in efficient, traceable and professional management of our business relationships.

If we send marketing emails or comparable promotional communication only on the basis of your consent, processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR.

10. Appointment booking and online meetings

If you book an appointment with us or participate in an online meeting, we process the data required for this purpose. This may include:

  • Name
  • Email address
  • Company
  • Telephone number
  • Requested appointment
  • Calendar data
  • Meeting link
  • Subject and description of the appointment
  • Communication content
  • Technical connection data
  • Audio and video data if you activate camera or microphone

For appointment bookings, we may use HubSpot Meeting Scheduler or comparable calendar functions. For online meetings, services such as Google Meet, Microsoft Teams, Zoom or comparable providers may be used. The specific provider is indicated in the relevant invitation.

Processing is carried out to plan, conduct and follow up on conversations. The legal basis is Art. 6 para. 1 lit. b GDPR where the meeting serves the initiation or performance of a contract. Otherwise, processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the efficient conduct of online meetings.

We do not record meetings without prior information and, where required, your consent. If a recording is made, the purpose, scope and storage period will be communicated separately.

11. Email communication and Google Workspace

We may use Google Workspace for our business email communication, calendar management and collaboration.

Provider

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

In connection with the use of Google Workspace, email content, communication data, calendar data, contact data, documents and metadata may be processed in particular where you communicate with us or where we need your data to carry out our business processes.

Processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR where it is necessary for pre-contractual or contractual measures. In addition, processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in secure and efficient business organization and communication.

12. Consent management and cookies

Our website may use cookies and comparable technologies. Cookies are small text files stored on your device. Similar technologies may include local storage, session storage, pixels or scripts.

We distinguish between:

  • Technically necessary cookies and technologies
  • Functional cookies and technologies
  • Statistics and analytics technologies
  • Marketing and tracking technologies

Technically necessary cookies and technologies are required to provide the website, enable security functions, store language settings or perform requested services. Processing is carried out on the basis of Section 25 para. 2 TDDDG and Art. 6 para. 1 lit. f GDPR.

We use non-essential cookies and comparable technologies only if you have given prior consent. The storage of or access to information on your device is then based on Section 25 para. 1 TDDDG. The subsequent processing of personal data is based on Art. 6 para. 1 lit. a GDPR.

To manage consent, we may use a consent management tool such as Cookiebot by Usercentrics or a comparable solution. Your consent, refusal or later change is documented so that we can technically respect your choice and legally demonstrate it.

You may change or withdraw your consent at any time with effect for the future. The corresponding setting option should be available via the cookie banner or a link in the website footer.

13. Web analytics, performance and error analysis

We may use analytics and performance tools to understand how our website is used, which content is relevant and where technical problems occur.

Depending on the tool used, the following data may be processed:

  • Page views
  • Clicks
  • Time spent
  • Referring page
  • Approximate region
  • Device type
  • Browser
  • Operating system
  • Loading times
  • Technical errors
  • Interactions with forms or content

Where analytics or tracking technologies are not technically necessary, we use them only on the basis of your consent. The legal basis is then Section 25 para. 1 TDDDG and Art. 6 para. 1 lit. a GDPR.

Where purely technical, data-minimizing and consent-free performance or error analysis is carried out, processing may be based on Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in optimizing the stability and security of our website.

14. LinkedIn and LinkedIn Ads

We may operate company pages on LinkedIn, publish content and run advertising campaigns. If you interact with our LinkedIn page, view, comment on, share or like posts, or contact us via LinkedIn, LinkedIn processes personal data in accordance with its own privacy terms.

The provider for users in the European Economic Area is generally:

LinkedIn Ireland Unlimited Company
Wilton Place
Dublin 2
Ireland

In connection with company pages, LinkedIn provides us with aggregated statistics and so-called Page Insights. For certain analyses, we may be jointly responsible with LinkedIn.

If we use LinkedIn Lead Gen Forms, conversion tracking, retargeting or the LinkedIn Insight Tag, further data may be processed depending on your consent and the settings of the relevant campaign. This may include, in particular, professional profile data, interactions with ads, form entries and technical identifiers.

Where tracking technologies are used on our website, this happens only with your consent. The legal basis is Section 25 para. 1 TDDDG and Art. 6 para. 1 lit. a GDPR.

Processing in connection with our LinkedIn presence and campaigns is otherwise based on Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the visibility of our company, communication with prospects and partners, and evaluating and improving our B2B communication.

15. Recipients of personal data

We disclose personal data only where this is necessary, where a legal basis exists or where you have given consent.

Recipients may include, in particular:

  • Hosting and infrastructure service providers
  • CRM and form providers
  • Email and calendar providers
  • Online meeting providers
  • IT and security service providers
  • Tax advisors, legal advisors or business advisors
  • Authorities, where legally required
  • Affiliated project or implementation partners, where this is necessary to handle your inquiry or perform a project

Where service providers process personal data on our behalf, we conclude data processing agreements pursuant to Art. 28 GDPR where required.

16. International data transfers

We prefer to process personal data within the European Union or the European Economic Area.

When using certain service providers, however, personal data may be transferred to third countries, in particular the USA. Such a transfer takes place only if the requirements of Art. 44 et seq. GDPR are met.

Suitable safeguards may include, in particular:

  • Adequacy decisions of the European Commission
  • Certifications under the EU-US Data Privacy Framework
  • EU Standard Contractual Clauses
  • Additional technical and organizational safeguards

If you would like more information about the safeguards used, you may contact us at any time.

17. Storage period

We store personal data only for as long as this is necessary for the respective purposes.

Contact and inquiry data is generally stored until the inquiry has been fully handled, unless further statutory, contractual or legitimate reasons require longer storage.

Data connected with contractual relationships, offers, invoices, accounting or business correspondence is stored in accordance with statutory retention obligations.

Proof of consent may be stored for as long as this is necessary to document the consent and defend against possible claims.

When storage is no longer required, we delete personal data or restrict processing where statutory retention obligations prevent deletion.

18. Your rights

Subject to the statutory requirements, you have the following rights:

  • Right of access pursuant to Art. 15 GDPR
  • Right to rectification pursuant to Art. 16 GDPR
  • Right to erasure pursuant to Art. 17 GDPR
  • Right to restriction of processing pursuant to Art. 18 GDPR
  • Right to data portability pursuant to Art. 20 GDPR
  • Right to object pursuant to Art. 21 GDPR
  • Right to withdraw consent pursuant to Art. 7 para. 3 GDPR
  • Right to lodge a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR

If you have given consent, you may withdraw it at any time with effect for the future. The lawfulness of processing before the withdrawal remains unaffected.

If we process personal data on the basis of legitimate interests, you may object to the processing on grounds relating to your particular situation. If processing is carried out for direct marketing purposes, you have an unrestricted right to object at any time without giving reasons.

19. Competent supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority.

The authority likely competent for us is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart
Germany

Website: www.baden-wuerttemberg.datenschutz.de

Alternatively, you may also contact a data protection supervisory authority at your usual place of residence, place of work or the place of the alleged data protection infringement.

20. Obligation to provide personal data

You are generally not obliged to provide personal data. Without certain data, however, we may be unable or only partially able to handle individual inquiries, downloads, appointment bookings, contract offers or services.

21. Automated decisions and profiling

We do not make decisions based solely on automated processing that have legal effects concerning you or similarly significantly affect you.

If we use scorecards or qualification questions, they serve the internal structuring and prioritization of inquiries. No legally relevant automated decision is made as a result.

22. Data security

We use technical and organizational measures to protect personal data against loss, misuse, unauthorized access, alteration or disclosure.

Depending on the processing, this includes in particular:

  • Encrypted transmission
  • Access restrictions
  • Role-based permissions
  • Secure passwords and, where possible, multi-factor authentication
  • Regular review of services used
  • Careful selection of service providers
  • Internal rules for handling personal data

The measures used are selected taking into account the state of the art, implementation costs, the nature, scope, circumstances and purposes of processing, and the risks to data subjects.

23. Changes to this Privacy Policy

We update this Privacy Policy if our website, the services we use, our internal processes or legal requirements change.

The current version is available on our website.

Palancart

© 2026 Palancart

HomeImprintPrivacyGerman version