Legal
Privacy Notice
Website, contact, newsletter, first-party analytics and business relationships — explained transparently.
1. Scope
This Privacy Notice explains how personal data is processed when you visit lumen-cloud.de, use the contact and newsletter features offered there, or enter into or maintain a business relationship with us.
Sign-in to the Lumen applications takes place on separate application or account domains. Where customers manage users, organisations, roles, permissions and authentication for their tenant, or use the Lumen applications to process personal data for their own purposes, vss software GmbH generally acts as a processor on the customer’s instructions. The separate Data Processing Agreement applies to that processing. We act as a controller where we process the same or other data for our own purposes, in particular for contracts, billing, customer-account provisioning, protection of the overall platform, abuse prevention and compliance with legal duties. The applicable role is determined by the specific processing purpose.
2. Controller and privacy contact
vss software GmbH
Kleiner Burstah 12
20457 Hamburg
Germany
Phone: +49 40 239 366 870
Email: kontakt@vss-software.de
3. Website delivery and server logs
We host the website, content management system and related databases on infrastructure provided by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, in German data centres.
When the website is accessed, our systems process technically necessary connection and log data. This may include the IP address, date and time, requested address or file, referrer, amount of data transferred, HTTP status, and browser, operating-system and device information including the user agent. We process this data to deliver content, maintain stability and security, detect attacks and analyse errors.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, stable and economical operation of our website. Log data is retained only for as long as needed for operations, error analysis and security. Data connected with a specific security or abuse incident may be retained for longer until the incident has been investigated and legal claims have been established, exercised or defended.
4. First-party, cookieless audience measurement
We operate our own audience measurement on our infrastructure. It does not set analytics or marketing cookies, does not use Local Storage or Session Storage for measurement, and does not assign a user or session identifier.
Depending on the interaction, we record:
- the requested path without URL query parameters,
- page language and product context,
- referral category and, where applicable, the host of the referring page,
- campaign parameters such as
utm_source,utm_mediumandutm_campaign, - device category, browser and operating-system family, and a size category for the browser window,
- page views, scroll depth, time on page and interactions with buttons, links and forms.
The IP address necessarily used to establish the connection is not written to the analytics record. It is processed temporarily in server memory for abuse prevention and rate limiting; the applicable rate-limit window is no longer than approximately one hour. Before storage, the full user agent is reduced to general browser, operating-system and device categories. Events are not combined into a personal or session-based profile.
Raw events are deleted after 90 days. Only aggregated daily values without a user or session identifier remain afterwards.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to assess the reach, functionality and clarity of our content in a data-minimising way and to improve the website. As the measurement neither stores information on your device nor accesses information already stored there, consent under § 25 TDDDG is not required.
5. Contact, demo and sales enquiries
When you submit a form or otherwise contact us, we process the information you provide. Depending on the form and enquiry, this particularly includes:
- name, email address, telephone number and company,
- message, product context, request type, voluntary estimate of monthly redaction workload, and language,
- source page and campaign parameters,
- timestamp, IP address and user agent for technical protection and abuse prevention.
We process this data to assess and answer your enquiry, carry out the requested communication and, where applicable, take steps prior to entering into or performing a contract. The legal basis is Article 6(1)(b) GDPR where the enquiry concerns a contract or pre-contractual steps. For other enquiries and abuse prevention, the legal basis is Article 6(1)(f) GDPR; our legitimate interests are orderly communication, assigning enquiries to the appropriate context, and protecting our systems.
Form data is stored in our self-hosted Directus system at Hetzner. To send acknowledgements and internal notifications, we use Postmark, a service of AC PM LLC in the United States. Postmark receives the recipient, sender, content and delivery data needed for the relevant email. Further information about Postmark and international transfers is provided in section 9.
Direct emails sent to kontakt@vss-software.de are received in a Microsoft 365 mailbox operated for us by vsquadrat GmbH. The technical platform provider is Microsoft Exchange Online. Further information about these providers is set out in section 9.
We delete enquiries once they have been fully handled and no contractual, statutory or overriding evidentiary interests remain. Contract-related correspondence may be retained for the contract term and until expiry of the regular limitation period. Commercial and business correspondence is retained for six years where applicable, and tax-relevant accounting records for eight years. Technical accompanying data is deleted earlier once it is no longer needed for security and abuse prevention.
6. Newsletter
For newsletter registration, we process your email address, selected topics, language, source of registration, and status and timestamp information. To evidence registration, we also store the time and IP address associated with consent. Registration uses a double opt-in: after registering, we send you an individual confirmation link valid for 30 days. You receive the newsletter only after confirmation.
The legal basis for sending the newsletter is your consent under Article 6(1)(a) GDPR. You may withdraw it at any time with future effect by using the unsubscribe link in each message or emailing kontakt@vss-software.de. Processing carried out before withdrawal remains lawful. Recording the double opt-in and maintaining a suppression list are based on Article 6(1)(f) GDPR; our legitimate interests are demonstrating valid consent and ensuring that no further messages are sent after an unsubscribe request.
The confirmation link expires after 30 days; no newsletter is sent without confirmation. Unconfirmed records are then processed only to the extent needed for abuse prevention and evidence and are deleted once those purposes cease. When you unsubscribe, we set the status to “unsubscribed” and remove the selected topics. The email address, consent, confirmation and unsubscribe timestamps, and metadata needed as evidence may remain in the suppression list and withdrawal record. Necessity is assessed in particular against potential claims and reviewed by reference to statutory limitation periods; the standard period is three years from the end of the calendar year in which you unsubscribed. Information that is no longer needed is deleted.
Confirmation, welcome and unsubscribe emails are sent through Postmark. In particular, the email address, consent and delivery time, IP address, source and selected topics may be transferred as part of the delivery or evidence data.
7. Contract, account and billing data
In connection with offers and contractual relationships, we particularly process company and contact-person master data, contract and product data, user, organisation and authorisation data, account and security events, communication and support data, and invoice and payment information.
The legal bases are Article 6(1)(b) GDPR for entering into and performing the contract, Article 6(1)© GDPR for statutory duties, and Article 6(1)(f) GDPR for secure account and platform administration, abuse prevention, internal organisation, and establishing, exercising or defending legal claims. Data forming part of accounting records is generally retained for eight years; commercial and business correspondence is generally retained for six years. Account and security logs are retained according to the security risk and necessity; records connected with a specific incident may be retained until it is resolved and related claims expire. Other contract data is deleted after the contract ends once statutory retention and limitation periods and legitimate evidentiary interests have expired.
For invoicing and accounting, Pennylane SAS, 2–4 rue Jules Lefebvre, 75009 Paris, France, may receive contract, contact, invoice and accounting data. Where an online payment through Stripe is offered and used in a particular case, Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland, particularly processes contact, invoice, payment, transaction and fraud-prevention data. Stripe may use other group companies and providers outside the EEA; the adequacy decisions, EU-US Data Privacy Framework and/or EU Standard Contractual Clauses identified by the provider apply to those transfers. The legal bases are the contract, statutory and security purposes described above.
8. External links and locally hosted content
The public website does not embed external fonts, maps, videos or social-media plugins that transfer data to the relevant provider merely when a page is loaded. Fonts and static content are delivered from our own infrastructure. If you follow an external link, for example to a social network, you leave our website and the relevant provider is responsible for subsequent processing.
The public website does not use non-essential analytics or marketing cookies. A preview function limited to twelve hours is intended solely for authorised editorial access and uses a technically necessary cookie for that purpose.
9. Recipients, processors and international transfers
We disclose personal data only where necessary for the purposes described, required by law, or covered by your consent. Recipients may particularly include hosting and email providers, professional advisers, authorities and courts.
We particularly use the following recipients and providers. Where a provider processes data on our documented instructions, an agreement under Article 28 GDPR is in place. Payment providers may act as separate or joint controllers for regulatory, fraud-prevention and payment purposes.
- Hetzner Online GmbH: Hosting of the website, CMS and databases; processor; processing in Germany.
- AC PM LLC (Postmark): Transactional emails and newsletter system messages and newsletter campaigns; processor; processing in the United States.
- vsquadrat GmbH: Operation and administration of our business mailbox in its Microsoft 365 tenant; processor; tenant country Germany.
- Microsoft Ireland Operations Limited (Microsoft 365/Exchange Online): Technical provision of the email service as a sub-processor of vsquadrat GmbH; processing under Microsoft’s contractual and data-protection terms, with possible further international transfers.
- Pennylane SAS: Invoicing and accounting; processor depending on the service; processing in France.
- Stripe Payments Europe, Limited: Online payment processing where offered and used; processor or (joint) controller depending on the processing; processing in Ireland with possible further transfers.
Postmark processes email content and delivery metadata on primary systems in the United States. According to the provider, the default retention period for message content and related metadata is 45 days; the actual period may differ according to the account configuration and is limited by us to what is necessary for delivery, troubleshooting and evidence. Suppression data may be retained for longer to prevent repeated failed delivery or unwanted messages.
The Microsoft 365 tenant is assigned to Germany. This does not mean that all processing takes place exclusively in Germany. Microsoft documents an EU Data Boundary for European tenants, while also describing limited exceptions and possible international access. Where this entails a transfer to a third country, the transfer mechanisms and supplementary safeguards agreed in the Microsoft DPA apply.
For transfers to third countries, particularly the United States, we rely on the adequacy decision for the EU-US Data Privacy Framework under Article 45 GDPR to the extent that the specific recipient and processing are covered by a valid certification. In addition, or where the framework does not apply, the European Commission’s Standard Contractual Clauses under Article 46(2)© GDPR and any necessary supplementary safeguards are agreed. You may request information or a copy of the applicable safeguards from kontakt@vss-software.de.
10. Requirement to provide data and automated decision-making
You are not legally or contractually required to provide data through the public website. Without the fields marked as required, however, we may be unable to handle an enquiry, newsletter registration or pre-contractual request. We do not make solely automated decisions producing legal or similarly significant effects, and we do not perform personal profiling in connection with the activities described in this notice.
11. Your rights
Subject to the statutory conditions, you have the right to:
- obtain access to your personal data (Article 15 GDPR),
- have inaccurate data rectified (Article 16 GDPR),
- request erasure (Article 17 GDPR),
- request restriction of processing (Article 18 GDPR),
- receive data you provided in a portable format (Article 20 GDPR),
- withdraw consent at any time with future effect (Article 7(3) GDPR).
Right to object: Where we process data on the basis of Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation under Article 21 GDPR. You may object to direct marketing at any time without giving reasons.
Please send your request to kontakt@vss-software.de. To prevent unauthorised disclosure, we may request reasonable proof of identity.
You also have the right to lodge a complaint with a data-protection supervisory authority. Our competent authority is:
The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Straße 22
20459 Hamburg
https://datenschutz-hamburg.de
12. Amendments and date
We update this Privacy Notice when processing activities or the legal framework change. The version published on this page at the relevant time applies.
This English version is provided for convenience. The German version is authoritative.
Last updated: 24 July 2026