Skip to main content

Privacy Policy

Here you will find information on how FunnelCAD handles your data in accordance with the GDPR.

Preamble​

With this Privacy Policy, we want to inform you about the types of personal data we process, for what purposes, and to what extent. This statement applies to all data processing carried out by us – whether within the scope of our services, on our websites, in mobile applications, or on external online presences such as our social media profiles.

Date: September 24, 2026

Controller​

Overview of Processing​

The following overview summarizes the types of data processed, the purposes of their processing, and refers to the data subjects.

Types of Processed Data​

  • Inventory data (stock data)
  • Payment data
  • Contact data
  • Content data
  • Contract data
  • Usage data
  • Meta, communication, and procedural data
  • Protocol data (log data)

Categories of Data Subjects​

  • Service recipients and clients
  • Prospects
  • Communication partners
  • Users
  • Business and contractual partners

Purposes of Processing​

  • Provision of contractual services and fulfillment of contractual obligations
  • Communication
  • Security measures
  • Direct marketing
  • Reach measurement
  • Tracking
  • Office and organizational procedures
  • Conversion measurement
  • Target group formation
  • Organizational and administrative procedures
  • Feedback
  • Marketing
  • Creation of profiles with user-related information
  • Provision of our online offering and ensuring user-friendliness
  • Operation of the information technology infrastructure
  • Public relations
  • Sales promotion
  • Support for business processes and commercial procedures

Relevant Legal Bases according to the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the GDPR regulations, national data protection requirements in your or our country of residence or establishment may also apply. Should more specific legal bases be relevant in individual cases, we will inform you of these in this privacy policy.

  • Consent (Art. 6 para. 1 sentence 1 lit. a GDPR): You have given your consent to the processing of your personal data for one or more specific purposes.
  • Performance of Contract and Pre-Contractual Inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR): Processing is necessary for the performance of a contract or to take steps at your request prior to entering into a contract.
  • Legal Obligation (Art. 6 para. 1 sentence 1 lit. c GDPR): Processing is necessary for compliance with a legal obligation.
  • Legitimate Interests (Art. 6 para. 1 sentence 1 lit. f GDPR): Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your rights.

National Data Protection Regulations in Germany: In addition, specific regulations apply in Germany, namely the Federal Data Protection Act (BDSG) – particularly regarding access, deletion, objection, processing of special categories of personal data, as well as transmission and automated decision-making.

Note on the Applicability of the GDPR and Swiss DPA: This privacy notice serves both to inform in accordance with the Swiss DPA (Data Protection Act) and the GDPR. For reasons of better comprehensibility, we use the terms of the GDPR. However, the legal definitions are based on the respective law.

Security Measures​

In accordance with legal requirements – taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing – we take appropriate technical and organizational measures to ensure a level of security commensurate with the risk.

Important measures include:

  1. Ensuring the confidentiality, integrity, and availability of your data by controlling access and processing.
  2. Establishing procedures for exercising your data subject rights and for erasing or restricting processing.
  3. Considering data protection already when selecting hardware, software, and procedures through data-protection-friendly default settings.

Securing Online Connections: We use TLS/SSL encryption (HTTPS). A website protected by an SSL/TLS certificate displays "HTTPS" in the URL, signaling to you that your data is transmitted securely and encrypted.

Transfer of Personal Data​

We may transmit or disclose your personal data to other bodies, companies, legally independent organizational units, or persons – for example, to IT service providers or providers of services and content that are integrated into our website. In doing so, we always comply with legal requirements and conclude corresponding contracts or agreements.

International Data Transfers​

If we process or transfer your data in a third country (outside the EU/EEA), this will only take place in compliance with legal requirements. If the data protection level of a third country is recognized by an Adequacy Decision (Art. 45 GDPR), this serves as the basis. Otherwise, the data transfer only takes place if the data protection level is otherwise secured, for example, through Standard Contractual Clauses (Art. 46 para. 2 lit. c GDPR), explicit consent, or contractual/statutory requirements.

Further information can be found at https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de and at https://www.dataprivacyframework.gov/.

General Information on Data Storage and Deletion​

We delete your personal data in accordance with statutory provisions as soon as the underlying consents are revoked or no further legal bases exist – this applies if the original processing purpose ceases to apply or the data is no longer required. Exceptions exist if legal obligations or special interests require longer retention.

Data that must be retained for commercial or tax reasons or for legal prosecution will be archived accordingly.

Further information on specific retention and deletion periods can be found in the following points:

  1. 10 years: Retention period for books, records, annual financial statements, inventories, management reports, opening balance sheets, and related working instructions (§ 147 para. 1 no. 1 in conjunction with para. 3 AO, § 14b para. 1 UStG, § 257 para. 1 no. 1 in conjunction with para. 4 HGB).
  2. 8 years: Retention period for booking documents (e.g., invoices, cost receipts) (§ 147 para. 1 no. 4 and 4a in conjunction with para. 3 AO, § 257 para. 1 no. 4 in conjunction with para. 4 HGB).
  3. 6 years: Retention period for other business documents, insofar as they are relevant for taxation (§ 147 para. 1 no. 2, 3, 5 in conjunction with para. 3 AO, § 257 para. 1 no. 2 and 3 in conjunction with para. 4 HGB).
  4. 3 years: Storage of data to consider potential warranty and damage claims (§§ 195, 199 BGB).

Rights of Data Subjects​

According to the GDPR, you have the following rights as a data subject:

  • Right to Object: You can object at any time to the processing of your personal data based on Art. 6 para. 1 lit. e or f GDPR – even if this relates to profiling. In particular, you have the right to object to processing for direct marketing purposes.
  • Right to Withdraw Consent: You can withdraw your given consent at any time.
  • Right of Access (Information): You have the right to know whether and what data of yours is being processed, as well as to receive a copy of this data and further information in accordance with statutory provisions.
  • Right to Rectification: You can request the completion or correction of inaccurate data.
  • Right to Erasure and Restriction of Processing: You can request the erasure of your data or a restriction of processing in accordance with statutory provisions.
  • Right to Data Portability: You have the right to receive your data in a structured, common, and machine-readable format or to request transmission to another controller.
  • Complaint to Supervisory Authority: You can lodge a complaint with a supervisory authority if you believe that the processing of your data violates the GDPR.

Business Services​

We process data of our contractual partners – i.e., customers and prospects – within the framework of contractual and similar legal relationships and in communication (also pre-contractual), such as for answering inquiries.

This data serves to fulfill our contractual obligations, such as providing the agreed services, update obligations, and support in case of warranty or service disruptions. It is also processed to safeguard our rights, for administrative tasks, and the organization of our company – based on our legitimate interests in ensuring proper business management and security measures.

Data is only passed on to third parties if this is necessary for the fulfillment of the mentioned purposes or for compliance with legal obligations. We will inform you about further processing, for example for marketing purposes, in this privacy policy.

You will usually find out which data is necessary for this purpose before or during data collection (e.g., in online forms or through specific markings).

We generally delete this data after four years, unless longer statutory periods apply (e.g., ten years for tax purposes). Data transmitted within the scope of an order is deleted after the end of the order.

  • Types of Data Processed: Inventory data, payment data, contact data, contract data, usage data, and meta, communication, and procedural data.
  • Data Subjects: Service recipients, clients, prospects, communication partners, and business and contractual partners.
  • Purposes of Processing: Contract fulfillment, security measures, communication, organizational procedures, business processes.
  • Legal Bases: Performance of contract and pre-contractual inquiries, legal obligations, legitimate interests (see Section 4).

Business Processes and Procedures​

We process personal data within the framework of our business processes to efficiently manage customer management, sales, payment transactions, accounting, and project management. This data supports us in transaction processing, building customer relationships, and internal administrative tasks.

Data may be passed on to third parties (e.g., tax or legal advisors, banks, shipping service providers, IT services) if this is legally required or necessary for the fulfillment of our obligations. We conclude corresponding contracts for this purpose.

  • Types of Data Processed: Inventory data (name, address, contact info, customer number, date of birth, nationality); Payment data (bank details, invoices, payment history, credit card data, IBAN, BIC); Contact data (postal/email addresses, phone numbers, messenger IDs, social media profiles); Content data (messages, contributions, authorship, publication times); Contract data (contract subject, term, customer category, payment modalities); Usage data (page views, dwell time, click paths, interactions); Meta, communication, and procedural data (IP addresses, time details, IDs, log files).

  • Data Subjects: All groups mentioned above.

  • Purposes of Processing: Contract fulfillment, administration, organization, and commercial procedures.

  • Legal Bases: See Section 4.

  • Economic Analyses and Market Research: We analyze data on business transactions and contracts to identify market trends and make business decisions. These analyses are carried out internally and based on pseudonymized or anonymized data. Legal Bases: Legitimate Interests.

Provision of the Online Offering and Web Hosting​

We process user data to provide our online services. This includes, in particular, the IP address, which is required to send content and functions to your browser or device.

  • Types of Data Processed: Usage data, meta, communication, and procedural data, protocol data, and content data.

  • Data Subjects: Users of our websites and online services.

  • Purposes of Processing: Provision of the online offering, ensuring user-friendliness, operation of the IT infrastructure, and security measures.

  • Legal Bases: Legitimate Interests.

  • Collection of Access Data and Log Files: All accesses to our online offering are logged in server log files, which include, among others, IP addresses, access times, and browser information. This serves to protect against overload and misuse. Legal Bases: Legitimate Interests. Deletion: Log files are deleted or anonymized after a maximum of 30 days.

  • Hosting of funnelcad.com via Cloudflare: Our website funnelcad.com is provided via Cloudflare, which offers a Content Delivery Network (CDN) and other security and optimization services. Service Provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Legal Bases: Legitimate Interests. Website: https://www.cloudflare.com/de-de Privacy Policy: https://www.cloudflare.com/de-de/privacypolicy/ Third Country Transfers: Cloudflare also processes data outside the EEA within its global network and describes appropriate safeguards pursuant to Art. 45 and 46 GDPR for this.

Use of Cookies​

Cookies are functions that store and read information on your devices. They serve, among other things, the functionality, security, and user-friendliness of our offerings, as well as the creation of visitor statistics. We use cookies in accordance with legal regulations. Where necessary, we obtain your consent. Otherwise, we rely on our legitimate interests, especially when storing and reading information is essential to provide content and functions requested by you.

Notes on Data Protection Legal Bases: The processing of personal data using cookies is based on your consent or our legitimate interests.

Storage Duration: We distinguish between:

  • Temporary Cookies (Session Cookies): These are deleted as soon as you leave our offer or close your browser.
  • Permanent Cookies: These remain stored even after the browser is closed (up to two years, unless otherwise specified).

General Notes on Withdrawal and Objection: You can withdraw your consent and object to the processing at any time – for example, via your browser settings.

  • Types of Data Processed: Meta, communication, and procedural data (e.g., IP addresses, time details, IDs).
  • Data Subjects: Users of our websites and online services.
  • Legal Bases: Consent or legitimate interests (see above).

Further Notes:

  • Processing of Cookie Data based on Consent: We use a consent management solution that obtains, logs, and manages your consent to the use of cookies. Your choice is stored in the local storage of your browser, together with the time of the choice and a random consent ID, until you change it or delete the data stored by your browser. You can change or withdraw your choice at any time via "Cookie settings" at the bottom of every page. Legal Bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR).

Blogs and Publication Media​

We use blogs or similar media to provide content and communicate with you. The data of readers is only processed to the extent necessary for the presentation of the content, communication between authors and readers, or for security reasons.

  • Types of Data Processed: Inventory data, contact data, content data, usage data, and meta, communication, and procedural data.
  • Data Subjects: Users of our websites and online services.
  • Purposes of Processing: Feedback and provision of our online offering.
  • Legal Bases: Legitimate Interests.

Contact and Inquiry Management​

If you contact us – whether by post, contact form, email, phone, or via social media – or are already in a business relationship, we process your information to the extent necessary to process your inquiry.

  • Types of Data Processed: Inventory data, contact data, content data, usage data, meta, communication, and procedural data.
  • Data Subjects: Communication partners.
  • Purposes of Processing: Communication, administrative and organizational procedures, feedback.
  • Legal Bases: Performance of contract, pre-contractual inquiries, and legitimate interests.

Promotional Communication via Email, Post, Fax, or Phone​

We also process personal data for advertising purposes – for example, via email, phone, post, or fax – provided this complies with legal requirements.

You can withdraw your consent or object to promotional communication at any time. After a withdrawal or objection, we store the necessary data (e.g., email address, phone number) for up to three years to secure proof of previous authorization. This storage is solely for the defense against possible claims. If withdrawal or objection is permanently respected, the data will be stored in a blocking list.

  • Types of Data Processed: Inventory data, contact data, and content data.
  • Data Subjects: Communication partners.
  • Purposes of Processing: Direct marketing, sales promotion.
  • Legal Bases: Consent; for email advertising to existing customers, § 7 para. 3 UWG in conjunction with Art. 13 para. 2 of Directive 2002/58/EC; legitimate interests only for forms of advertising that do not require prior consent or a special statutory permission.

Web Analysis, Monitoring, and Optimization​

Our web analysis (also called "reach measurement") serves to evaluate the visitor flows of our online offering. It collects pseudonymized data about the behavior, interests, and demographic information (e.g., age, gender) of users, so we can understand when and how our offer is used and where improvements are needed.

We also use testing procedures (e.g., A/B tests) to compare and optimize different versions of our offer. Profiles may be created in your browser or device. If you have consented, location data will also be processed.

We store the IP addresses of users, but pseudonymize them using IP masking to prevent personal identification.

  • Types of Data Processed: Usage data, meta, communication, and procedural data.
  • Data Subjects: Users of our websites.
  • Purposes of Processing: Reach measurement, creation of user profiles, optimization of our offering.
  • Legal Bases: Consent or legitimate interests.

Further Notes:

  • PostHog: If you enable the "Analytics" category in the cookie banner, we use PostHog (PostHog, Inc.) via its EU cloud for reach measurement and to improve our website. In doing so, we record pseudonymous browser identifiers, page views, and predefined interactions, for example clicks on buttons and links. We do not transmit email addresses or free-text entries to PostHog. Session recordings are disabled. You can withdraw your consent at any time via the cookie settings. Legal Bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR). Service Provider: PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA; processing for this project in the EU cloud. Website: https://posthog.com Privacy Policy: https://posthog.com/privacy

Online Marketing​

We process personal data for online marketing purposes – this includes, in particular, placing advertising spaces or displaying content that is based on your potential interests, as well as measuring the effectiveness of these measures.

For this purpose, we may create user profiles and store data in cookies or similar procedures. Information on viewed content, visited websites, technical data (e.g., browser, device), usage times, and communication partners, and – if you have consented – also location data, are stored.

We store IP addresses and pseudonymize them using IP masking. No directly personal data such as name or email address is stored.

Notes on Legal Bases: Processing takes place either on the basis of your consent or based on our legitimate interests in showing you personalized advertising and measuring the effectiveness of our marketing measures.

Notes on Withdrawal and Objection: You can object to personalized advertising via the privacy notices of the respective providers. Alternatively, you can disable cookies in your browser – however, this may limit the functionality of our website.

  • Types of Data Processed: Usage data, meta, communication, and procedural data.

  • Data Subjects: Users of our websites and online services.

  • Purposes of Processing: Reach measurement, tracking, target group formation, personalized marketing, and conversion measurement.

  • Legal Bases: Consent or legitimate interests.

  • Google Ads and Conversion Measurement: We use Google Ads to place ads in Google's advertising network and measure their success. Service Provider: Google Ireland Limited, Dublin 4, Ireland; Legal Bases: Consent and legitimate interests; Website: https://marketingplatform.google.com; Privacy Policy: https://policies.google.com/privacy; Basis for Third Country Transfers: Data Privacy Framework (DPF).

  • Meta Pixel and Conversion Measurement: If you enable the "Marketing" category in the cookie banner, we use the Meta Pixel to measure the success of our ads on Facebook and Instagram and to show our ads to people who have visited our website (Custom Audiences). The Meta Pixel sets a cookie with a pseudonymous ID and transmits usage data (e.g., visited pages, time, browser and device information, IP address) to Meta. Service Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal Bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR); Joint Controllership: For the collection of the data on our website and its transmission to Meta, we and Meta are jointly responsible (Art. 26 GDPR); the agreement is available at https://www.facebook.com/legal/controller_addendum; Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/privacy/policy/; Basis for Third Country Transfers: Data Privacy Framework (DPF).

Presences in Social Networks (Social Media)​

We maintain online presences in social networks to communicate with active users and offer information about us. Please note that your data may be processed outside the EU, which may limit your rights.

Processing usually takes place for market research and advertising purposes using cookies that record your usage behavior.

Amendment and Update​

Please regularly inform yourself about the content of this privacy policy. We will adapt it as soon as changes in our data processing make this necessary. As soon as a change requires your cooperation (e.g., renewed consent) or an individual notification is necessary, we will inform you.

Please note that addresses and contact data of companies mentioned in this privacy policy may change over time. Please check this information before contacting them.

Definitions of Terms​

Below you will find an overview of the terms used in this privacy policy. Where legal definitions exist, they apply. The following explanations serve for better comprehensibility:

  • Inventory Data (Stock Data): Essential information necessary for the identification and management of contractual partners, user accounts, profiles, etc. (e.g., name, contact information, date of birth, user IDs).
  • Content Data: Information generated during the creation, editing, and publication of content (e.g., texts, images, videos, audio files, and associated metadata such as author, date, tags).
  • Contact Data: Information that enables communication (e.g., phone numbers, email addresses, postal addresses).
  • Conversion Measurement: Procedure for recording the reaction to marketing measures (e.g., clicks on ads, purchases), often with the help of cookies.
  • Meta, Communication, and Procedural Data: Data about the handling of information (e.g., file size, creation date, communication histories, audit logs).
  • Usage Data: Information about how and when users interact with digital offerings (e.g., page views, click paths, device information, location data).
  • Personal Data: All information relating to an identified or identifiable natural person (e.g., name, ID, location data, online identifier).
  • Profiles with User-Related Information: Automated processing in which personal data is analyzed or evaluated to determine personal aspects (e.g., interests, behavior).
  • Protocol Data (Log Data): Records of events or activities in a system (e.g., timestamps, IP addresses, error messages).
  • Reach Measurement: Also known as Web Analytics, used to evaluate visitor flows to optimize the offering.
  • Tracking: The monitoring of user behavior across various offers, often using cookies and profiling.
  • Controller: The person or organization that decides on the purposes and means of the processing of your personal data.
  • Processing: Any operation related to personal data, be it collection, evaluation, storage, transmission, or deletion.
  • Contract Data: All details of an agreement between parties (e.g., services, term, payment modalities).
  • Payment Data: Information required for processing transactions (e.g., credit card number, bank details, invoice information).
  • Target Group Formation: Procedure for identifying specific user groups for advertising purposes (e.g., Custom Audiences), often using cookies.