Company

EN

Privacy Policy

Datenschutzerklärung

Whenever you choose Xaver, you entrust us with your personal data. Personal data is processed when:

  • using our website (www.xaver.com),

  • using our Software as a Service products,

  • visiting our profiles on social media, and

  • contacting us.

To justify and maintain this trust, we want to inform you about how we handle this personal data.

Personal data refers to all data that can be related to a specific natural person, e.g., their name or IP address.


1. Contact Information

The responsible entity within the meaning of the General Data Protection Regulation ("GDPR") is:

Xaver Group GmbH c/o WeWork Pilgrimstraße 6 50674 Cologne, Germany

(hereinafter "Xaver Group" or "we").

Our Data Protection Officer is:

heyData GmbH Schützenstraße 5 10117 Berlin, Germany

datenschutz@heydata.eu


2. Legal Bases for Data Processing

We explain the scope of data processing, processing purposes, and legal bases in detail below. The following generally serve as legal bases for data processing:

  • Art. 6(1)(a) GDPR serves as the legal basis for processing operations for which we obtain consent.

  • Art. 6(1)(b) GDPR is the legal basis insofar as the processing of personal data is necessary for the performance of a contract, e.g., when a site visitor purchases a product from us or we perform a service for them. This legal basis also applies to processing necessary for pre-contractual measures, such as inquiries about our products or services.

  • Art. 6(1)(c) GDPR applies when we fulfill a legal obligation by processing personal data, as may be the case in tax law, for example.

  • Art. 6(1)(f) GDPR serves as the legal basis when we can rely on legitimate interests for processing personal data, e.g., for cookies that are necessary for the technical operation of our website.

Where service providers process personal data on our behalf, we have concluded a data processing agreement with these service providers and agreed on appropriate precautions to safeguard the protection of personal data. We carefully select our service providers. Service providers can be third parties or companies affiliated with Xaver Group GmbH. Moreover, these service providers process personal data exclusively to fulfill their tasks and are contractually bound by our instructions, have appropriate technical and organizational measures to protect personal data, and are regularly monitored by us.


3. Data Retention Period

Your personal data will be stored and processed for the duration of our business relationship with you. We delete your data after complete termination and settlement of the legal relationship with you, but at the earliest after the expiration of legal, regulatory, and/or other official retention periods, and provided that the data is no longer required for the assertion, exercise, and/or defense of legal claims. In addition, civil law limitation periods are also relevant for the duration of storage. These limitation periods can be up to 30 years according to the provisions of the German Civil Code (BGB), with the regular limitation period being three years.


4. Your Rights

Data subjects have the following rights regarding their personal data:

  • Right to Access: You have the right to request information about the data stored about you, its origin, recipients or categories of recipients to whom the data is disclosed, and the purpose of storage. (Art. 15 GDPR)

  • Right to Rectification: You have the right to request the correction and/or completion of inaccurate or incomplete personal data concerning you from the controller. (Art. 16 GDPR)

  • Right to Erasure: You can request that personal data concerning you be deleted immediately. However, there is no right to erasure if legal, regulatory, or other official retention obligations conflict with this, or if the storage serves to assert, exercise, or defend legal claims. (Art. 17 GDPR)

  • Right to Restriction of Processing: You can request the restriction of processing of personal data concerning you under certain conditions (contested accuracy, unlawful processing, cessation of processing purpose, or filing of an objection). (Art. 18 GDPR)

  • Right to Data Portability: You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format. (Art. 20 GDPR)

  • Right to Object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR. We will then no longer process your data unless there are compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or the processing serves the assertion, exercise or defense of legal claims. (Art. 21 GDPR)

  • Right to Withdraw Consent at Any Time: You have the right to withdraw your consent - if such consent has been given - at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

You also have the right, pursuant to Art. 77 GDPR, to lodge a complaint with a supervisory authority if you believe that the processing of personal data is not lawful. The address of the supervisory authority responsible for our company is: State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2-4, 40213 Düsseldorf, Germany, Phone: +49 (0)211 38424-0, Fax: +49 (0)211 38424-10, Email: poststelle@ldi.nrw.de, Website: www.ldi.nrw.de


5. Contact

5.1 Contact via Email or Phone

When contacting us, e.g., via email or phone, we store the data provided to us (e.g., names and email addresses) to answer questions. The legal basis for processing is our legitimate interest (Art. 6(1)(f) GDPR) in responding to inquiries directed to us.

We delete the data collected in this context when storage is no longer necessary, or restrict processing if there are statutory retention obligations.


5.2 Contact Form on the Website

When contacting us via the contact form on our website, we store the data requested there and the content of the message.

The legal basis for processing is our legitimate interest in responding to inquiries directed to us. Therefore, the legal basis for processing is Art. 6(1)(f) GDPR.

We delete the data collected in this context when storage is no longer necessary, or restrict processing if there are statutory retention obligations.


5.3 Booking Appointments

Visitors to our website can book appointments with us. For this purpose, we process meta or communication data in addition to the entered data. We have a legitimate interest in offering interested parties a user-friendly option for scheduling appointments. Therefore, the legal basis for data processing is Art. 6(1)(f) GDPR. If we use a third-party tool for scheduling, the information can be found under "Third-party providers".


5.4 Contact for Job Applications

For applications to job postings we have advertised, we refer to:

5.5 Contact by Us – Customer Surveys


From time to time, we conduct customer surveys to better understand our customers and their wishes. In doing so, we collect the requested data. It is our legitimate interest to better understand our customers and their wishes, so the legal basis for the associated data processing is Art. 6(1)(f) GDPR.

We delete the data when the results of the surveys have been evaluated.

6. Use of Our Websites

Our website stores information on the end devices of website visitors (e.g., cookies) or accesses information already stored on the end device (e.g., IP addresses). The specific information involved is detailed in the following sections.

This storage and access occurs on the basis of the following provisions:

  • To the extent that this storage or access is absolutely necessary for us to provide the service of our website expressly requested by website visitors (e.g., to operate a chatbot used by the website visitor or to ensure the IT security of our website), it is carried out on the basis of § 25 para. 2 no. 2 TDDDG.

  • Otherwise, this storage or access is based on the consent of website visitors (§ 25 para. 1 TDDDG).

The subsequent data processing is carried out in accordance with the following sections and on the basis of the provisions of the GDPR.


6.1 Visit to www.xaver.com

Our website uses cookies. Cookies are small text files that are stored in the web browser on the end device of a page visitor. Cookies help to make the offer more user-friendly, effective, and secure. When you visit our website, the following personal data is automatically stored in log files:

  • IP address

  • Browser type and version

  • Operating system

  • Date and time of access

  • Referrer URL

Insofar as the cookies are necessary for the operation of our website or its functions (hereinafter "Technically necessary cookies"), the legal basis for the associated data processing is Art. 6 para. 1 s. 1 lit. f GDPR. We have a legitimate interest in providing customers and other page visitors with a functional website.


6.2 Visit to demo.xaver.com – Use of our Software as a Service Products

As part of your registration on demo.xaver.com (use of our SaaS product for needs/pension checks and to derive potential product interest), we require the following personal data:

  • Age

  • Email address

  • Marital status

  • Occupation and salary

  • Special data categories (e.g., sensitive data from insurance contracts)

  • Family situation (partner, children)

  • Housing situation (current and planned)

  • Other personal/economic circumstances, provision wishes

This personal data is collected in addition to the data mentioned under 6.1 Visit to www.xaver.com. Technically necessary cookies are also used on demo.xaver.com. We have a legitimate interest in providing customers and other page visitors with a functional website.

Part of the data processing may also be carried out by the following service providers. Insofar as they process personal data on our behalf, we have concluded a data processing agreement with these service providers and agreed on appropriate guarantees to safeguard the protection of personal data.

The use of service providers is, unless otherwise stated, for the purpose of fulfilling contracts with potential customers (Art. 6 para. 1 lit. b GDPR) and in the interest of secure, fast, and efficient provision of our services, supported by professional providers (Art. 6 para. 1 lit. f GDPR).


6.2.1 Hosting Task

(i) MongoDB Atlas

  • Function: Data hosting and management (database and admin interface)

  • Location: Frankfurt, Germany

  • Certifications: ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO 9001:2015, PCI DSS (https://www.mongodb.com/products/platform/trust)

(ii) AWS Data Hosting

(iii) AWS Application Hosting

(iv) Google Cloud

  • Function: Database hosting for anonymized usage analysis (no IP storage), managed by Mixpanel

  • Location: Netherlands (Google Cloud Region europe-west4)

  • Certifications: ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO 9001:2015, PCI DSS (https://business.safety.google/intl/de/compliance/)


6.2.2 Data Analysis Task

For this purpose, we use the following service providers:

(i) Mixpanel (Mixpanel, Inc., USA)

  • Function: Database hosting for anonymized usage analysis (no IP storage), managed by Mixpanel

  • Data: The processed data includes IP address, device information, and usage data (e.g., pages accessed). The data is used for demo purposes.

  • Basis: The processing is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR. For more information, please refer to Mixpanel's privacy policy (https://mixpanel.com/).

  • Location: Netherlands (Google Cloud Region europe-west4)

  • Certifications: ISO 27001, ISO 27701 (https://mixpanel.com/legal/security-overview/).

(ii) Microsoft Azure OpenAI Service

  • Function: Large Language Models (AI, LLM) for text analysis and text generation and to perform other AI-based functions efficiently and precisely.

  • Location: Sweden (Gävle, Sandviken and Staffanstorp)

  • Certifications: ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO 9001:2015, PCI DSS (https://learn.microsoft.com/de-de/azure/compliance/)

(iii) Langfuse

  • Function: We use LangFuse for LLM chat analytics which stores all chat histories for analysis.

  • Location: Germany/Frankfurt (AWS eu-central-1) & Ireland (AWS eu-west-1)

  • Certifications: SOC 2 Type II Certified; ISO 27001 (https://langfuse.com/docs/data-security-privacy)


7. Visit to Our Profiles on Social Media

We are represented on social media networks to present our organization and our services there. The operators of these networks regularly process data of their users for advertising purposes. Among other things, they create user profiles from their online behavior, which are used, for example, to display advertisements on the pages of the networks and elsewhere on the Internet that correspond to the interests of the users. For this purpose, the network operators store information about the usage behavior in cookies on the users' computers. It also cannot be ruled out that the operators combine this information with other data. Further information and instructions on how users can object to processing by the site operators can be found in the privacy policies of the respective operators listed below. It may also be the case that the operators or their servers are located in non-EU countries, so that they process data there. This may result in risks for users, e.g., because the enforcement of their rights is made more difficult or government agencies gain access to the data.

We maintain a profile on Instagram. The operator is Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The privacy policy can be accessed here: https://help.instagram.com/519522125107875.

When users of the networks contact us through our profiles, we process the data communicated to us in order to respond to the inquiries. This is our legitimate interest, so the legal basis is Art. 6 para. 1 s. 1 lit. f GDPR.


8. Changes to This Privacy Policy

We reserve the right to change this privacy policy with effect for the future. An up-to-date version is always available here.


9. Questions and Comments

For questions or comments regarding this privacy policy, we are happy to be available at the contact details provided above.

Privacy Policy

Datenschutzerklärung

Whenever you choose Xaver, you entrust us with your personal data. Personal data is processed when:

  • using our website (www.xaver.com),

  • using our Software as a Service products,

  • visiting our profiles on social media, and

  • contacting us.

To justify and maintain this trust, we want to inform you about how we handle this personal data.

Personal data refers to all data that can be related to a specific natural person, e.g., their name or IP address.


1. Contact Information

The responsible entity within the meaning of the General Data Protection Regulation ("GDPR") is:

Xaver Group GmbH c/o WeWork Pilgrimstraße 6 50674 Cologne, Germany

(hereinafter "Xaver Group" or "we").

Our Data Protection Officer is:

heyData GmbH Schützenstraße 5 10117 Berlin, Germany

datenschutz@heydata.eu


2. Legal Bases for Data Processing

We explain the scope of data processing, processing purposes, and legal bases in detail below. The following generally serve as legal bases for data processing:

  • Art. 6(1)(a) GDPR serves as the legal basis for processing operations for which we obtain consent.

  • Art. 6(1)(b) GDPR is the legal basis insofar as the processing of personal data is necessary for the performance of a contract, e.g., when a site visitor purchases a product from us or we perform a service for them. This legal basis also applies to processing necessary for pre-contractual measures, such as inquiries about our products or services.

  • Art. 6(1)(c) GDPR applies when we fulfill a legal obligation by processing personal data, as may be the case in tax law, for example.

  • Art. 6(1)(f) GDPR serves as the legal basis when we can rely on legitimate interests for processing personal data, e.g., for cookies that are necessary for the technical operation of our website.

Where service providers process personal data on our behalf, we have concluded a data processing agreement with these service providers and agreed on appropriate precautions to safeguard the protection of personal data. We carefully select our service providers. Service providers can be third parties or companies affiliated with Xaver Group GmbH. Moreover, these service providers process personal data exclusively to fulfill their tasks and are contractually bound by our instructions, have appropriate technical and organizational measures to protect personal data, and are regularly monitored by us.


3. Data Retention Period

Your personal data will be stored and processed for the duration of our business relationship with you. We delete your data after complete termination and settlement of the legal relationship with you, but at the earliest after the expiration of legal, regulatory, and/or other official retention periods, and provided that the data is no longer required for the assertion, exercise, and/or defense of legal claims. In addition, civil law limitation periods are also relevant for the duration of storage. These limitation periods can be up to 30 years according to the provisions of the German Civil Code (BGB), with the regular limitation period being three years.


4. Your Rights

Data subjects have the following rights regarding their personal data:

  • Right to Access: You have the right to request information about the data stored about you, its origin, recipients or categories of recipients to whom the data is disclosed, and the purpose of storage. (Art. 15 GDPR)

  • Right to Rectification: You have the right to request the correction and/or completion of inaccurate or incomplete personal data concerning you from the controller. (Art. 16 GDPR)

  • Right to Erasure: You can request that personal data concerning you be deleted immediately. However, there is no right to erasure if legal, regulatory, or other official retention obligations conflict with this, or if the storage serves to assert, exercise, or defend legal claims. (Art. 17 GDPR)

  • Right to Restriction of Processing: You can request the restriction of processing of personal data concerning you under certain conditions (contested accuracy, unlawful processing, cessation of processing purpose, or filing of an objection). (Art. 18 GDPR)

  • Right to Data Portability: You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format. (Art. 20 GDPR)

  • Right to Object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR. We will then no longer process your data unless there are compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or the processing serves the assertion, exercise or defense of legal claims. (Art. 21 GDPR)

  • Right to Withdraw Consent at Any Time: You have the right to withdraw your consent - if such consent has been given - at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

You also have the right, pursuant to Art. 77 GDPR, to lodge a complaint with a supervisory authority if you believe that the processing of personal data is not lawful. The address of the supervisory authority responsible for our company is: State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2-4, 40213 Düsseldorf, Germany, Phone: +49 (0)211 38424-0, Fax: +49 (0)211 38424-10, Email: poststelle@ldi.nrw.de, Website: www.ldi.nrw.de


5. Contact

5.1 Contact via Email or Phone

When contacting us, e.g., via email or phone, we store the data provided to us (e.g., names and email addresses) to answer questions. The legal basis for processing is our legitimate interest (Art. 6(1)(f) GDPR) in responding to inquiries directed to us.

We delete the data collected in this context when storage is no longer necessary, or restrict processing if there are statutory retention obligations.


5.2 Contact Form on the Website

When contacting us via the contact form on our website, we store the data requested there and the content of the message.

The legal basis for processing is our legitimate interest in responding to inquiries directed to us. Therefore, the legal basis for processing is Art. 6(1)(f) GDPR.

We delete the data collected in this context when storage is no longer necessary, or restrict processing if there are statutory retention obligations.


5.3 Booking Appointments

Visitors to our website can book appointments with us. For this purpose, we process meta or communication data in addition to the entered data. We have a legitimate interest in offering interested parties a user-friendly option for scheduling appointments. Therefore, the legal basis for data processing is Art. 6(1)(f) GDPR. If we use a third-party tool for scheduling, the information can be found under "Third-party providers".


5.4 Contact for Job Applications

For applications to job postings we have advertised, we refer to:

5.5 Contact by Us – Customer Surveys


From time to time, we conduct customer surveys to better understand our customers and their wishes. In doing so, we collect the requested data. It is our legitimate interest to better understand our customers and their wishes, so the legal basis for the associated data processing is Art. 6(1)(f) GDPR.

We delete the data when the results of the surveys have been evaluated.

6. Use of Our Websites

Our website stores information on the end devices of website visitors (e.g., cookies) or accesses information already stored on the end device (e.g., IP addresses). The specific information involved is detailed in the following sections.

This storage and access occurs on the basis of the following provisions:

  • To the extent that this storage or access is absolutely necessary for us to provide the service of our website expressly requested by website visitors (e.g., to operate a chatbot used by the website visitor or to ensure the IT security of our website), it is carried out on the basis of § 25 para. 2 no. 2 TDDDG.

  • Otherwise, this storage or access is based on the consent of website visitors (§ 25 para. 1 TDDDG).

The subsequent data processing is carried out in accordance with the following sections and on the basis of the provisions of the GDPR.


6.1 Visit to www.xaver.com

Our website uses cookies. Cookies are small text files that are stored in the web browser on the end device of a page visitor. Cookies help to make the offer more user-friendly, effective, and secure. When you visit our website, the following personal data is automatically stored in log files:

  • IP address

  • Browser type and version

  • Operating system

  • Date and time of access

  • Referrer URL

Insofar as the cookies are necessary for the operation of our website or its functions (hereinafter "Technically necessary cookies"), the legal basis for the associated data processing is Art. 6 para. 1 s. 1 lit. f GDPR. We have a legitimate interest in providing customers and other page visitors with a functional website.


6.2 Visit to demo.xaver.com – Use of our Software as a Service Products

As part of your registration on demo.xaver.com (use of our SaaS product for needs/pension checks and to derive potential product interest), we require the following personal data:

  • Age

  • Email address

  • Marital status

  • Occupation and salary

  • Special data categories (e.g., sensitive data from insurance contracts)

  • Family situation (partner, children)

  • Housing situation (current and planned)

  • Other personal/economic circumstances, provision wishes

This personal data is collected in addition to the data mentioned under 6.1 Visit to www.xaver.com. Technically necessary cookies are also used on demo.xaver.com. We have a legitimate interest in providing customers and other page visitors with a functional website.

Part of the data processing may also be carried out by the following service providers. Insofar as they process personal data on our behalf, we have concluded a data processing agreement with these service providers and agreed on appropriate guarantees to safeguard the protection of personal data.

The use of service providers is, unless otherwise stated, for the purpose of fulfilling contracts with potential customers (Art. 6 para. 1 lit. b GDPR) and in the interest of secure, fast, and efficient provision of our services, supported by professional providers (Art. 6 para. 1 lit. f GDPR).


6.2.1 Hosting Task

(i) MongoDB Atlas

  • Function: Data hosting and management (database and admin interface)

  • Location: Frankfurt, Germany

  • Certifications: ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO 9001:2015, PCI DSS (https://www.mongodb.com/products/platform/trust)

(ii) AWS Data Hosting

(iii) AWS Application Hosting

(iv) Google Cloud

  • Function: Database hosting for anonymized usage analysis (no IP storage), managed by Mixpanel

  • Location: Netherlands (Google Cloud Region europe-west4)

  • Certifications: ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO 9001:2015, PCI DSS (https://business.safety.google/intl/de/compliance/)


6.2.2 Data Analysis Task

For this purpose, we use the following service providers:

(i) Mixpanel (Mixpanel, Inc., USA)

  • Function: Database hosting for anonymized usage analysis (no IP storage), managed by Mixpanel

  • Data: The processed data includes IP address, device information, and usage data (e.g., pages accessed). The data is used for demo purposes.

  • Basis: The processing is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR. For more information, please refer to Mixpanel's privacy policy (https://mixpanel.com/).

  • Location: Netherlands (Google Cloud Region europe-west4)

  • Certifications: ISO 27001, ISO 27701 (https://mixpanel.com/legal/security-overview/).

(ii) Microsoft Azure OpenAI Service

  • Function: Large Language Models (AI, LLM) for text analysis and text generation and to perform other AI-based functions efficiently and precisely.

  • Location: Sweden (Gävle, Sandviken and Staffanstorp)

  • Certifications: ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO 9001:2015, PCI DSS (https://learn.microsoft.com/de-de/azure/compliance/)

(iii) Langfuse

  • Function: We use LangFuse for LLM chat analytics which stores all chat histories for analysis.

  • Location: Germany/Frankfurt (AWS eu-central-1) & Ireland (AWS eu-west-1)

  • Certifications: SOC 2 Type II Certified; ISO 27001 (https://langfuse.com/docs/data-security-privacy)


7. Visit to Our Profiles on Social Media

We are represented on social media networks to present our organization and our services there. The operators of these networks regularly process data of their users for advertising purposes. Among other things, they create user profiles from their online behavior, which are used, for example, to display advertisements on the pages of the networks and elsewhere on the Internet that correspond to the interests of the users. For this purpose, the network operators store information about the usage behavior in cookies on the users' computers. It also cannot be ruled out that the operators combine this information with other data. Further information and instructions on how users can object to processing by the site operators can be found in the privacy policies of the respective operators listed below. It may also be the case that the operators or their servers are located in non-EU countries, so that they process data there. This may result in risks for users, e.g., because the enforcement of their rights is made more difficult or government agencies gain access to the data.

We maintain a profile on Instagram. The operator is Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The privacy policy can be accessed here: https://help.instagram.com/519522125107875.

When users of the networks contact us through our profiles, we process the data communicated to us in order to respond to the inquiries. This is our legitimate interest, so the legal basis is Art. 6 para. 1 s. 1 lit. f GDPR.


8. Changes to This Privacy Policy

We reserve the right to change this privacy policy with effect for the future. An up-to-date version is always available here.


9. Questions and Comments

For questions or comments regarding this privacy policy, we are happy to be available at the contact details provided above.

Book your free demo today

Unlock your sales potential by letting the Xaver



AI work and save you hours of time and headaches.

Sign up to the newsletter to get our latest updates straight to your inbox

© 2024 Xaver. All rights reserved.

Proudly built by the Xaver team

Book your free demo today

Unlock your sales potential by letting the Xaver



AI work and save you hours of time and headaches.

Sign up to the newsletter to get our latest updates straight to your inbox

© 2024 Xaver. All rights reserved.

Proudly built by the Xaver team