Version 1.1 · As of 24 September 2026 · Controller: [Wendory GmbH], [Musterstraße 1], [10115 Berlin], Germany
Draft – legal review required
Draft for legal review. Before commercial operation the items marked with [ ] must be completed and the actual processing activities (in particular hosting, payment provider, AI provider, third-country transfers) must be aligned with this policy.
The controller within the meaning of the General Data Protection Regulation (GDPR) is [Wendory GmbH], [Musterstraße 1], [10115 Berlin], Germany, e-mail: [kontakt@wendory.com]. Data protection officer (if appointed): [name], reachable at [e-mail].
We process personal data only where this is necessary to provide the platform, to perform contractual obligations, to comply with legal requirements or to pursue legitimate interests.
The legal bases are in particular Art. 6(1)(b) GDPR (contract), Art. 6(1)(c) GDPR (legal obligations, e.g. tax and commercial law), Art. 6(1)(f) GDPR (legitimate interests: operational security, abuse and fraud prevention, enforcement of claims) and – for AI features involving third-country transfers – Art. 6(1)(a) GDPR (consent).
Account and master data: e-mail address, password (hashed), role, company name, country, contact details, language, time zone.
Profile and qualification data (in particular for call centers): description, services, capacities, languages, locations, certificates, pricing model, logos.
Project data: tenders published by clients including contact persons and contact details, volume, budgets, requirements.
Communication data: chat messages, applications, attachments, meeting suggestions, ratings and reports.
Verification data: evidence uploaded by call centers (e.g. trade or commercial register extracts).
Payment data: subscriptions, invoices, payment status (the payment method itself is processed by our payment provider).
Technical data: IP address, timestamps, device and browser information, logs for security and error analysis.
AI data: input (prompts, texts, file contents) and output of AI features if you use them.
Calendar and appointment data (only with a connected calendar): busy and free times, title and time range of appointments booked via the platform, and the access tokens required for the connection (encrypted).
Providing and operating the platform; matching clients and call centers; anonymising contact details until unlock; communication and notifications; meeting scheduling; verification of call centers; billing and accounting; security, abuse prevention and error analysis; compliance with legal obligations; operating AI features at your instigation.
Clients receive call center contact details only after unlock (lead) and vice versa; attachments and messages are accessible only to the participants of the respective conversation.
We disclose data to processors (see table), to our administrators for their tasks and to authorities and courts where we are legally obliged to do so. Data is not passed to third parties for advertising purposes.
Google Calendar connection (Google API services): If you connect your Google Calendar, we access your Google account via the Google Calendar API with the scopes https://www.googleapis.com/auth/calendar.events and https://www.googleapis.com/auth/calendar.events.freebusy – exclusively to check busy times, suggest free slots and add confirmed appointments. The OAuth tokens are stored encrypted on servers in Germany; data obtained from Google is not shared with third parties or sold, not used for advertising and not used to train AI models. Humans do not read this data, except for security purposes, troubleshooting or at your explicit request. You can disconnect at any time under Settings → Calendar; the stored tokens are then discarded. Data obtained from Google is used in accordance with the Google API Services User Data Policy, including the Limited Use requirements (https://developers.google.com/terms/api-services-user-data-policy).
For AI features (assistant for preparing tenders, text suggestions, reply suggestions, summaries, match assessments) we transmit your input to the model provider used. Currently in use: DeepSeek (based in China).
Transmission to China is particularly sensitive under data protection law: there is no adequacy decision by the European Commission. Use therefore requires your explicit consent (Art. 49(1)(a) GDPR) as well as a data processing agreement with standard contractual clauses and a documented transfer impact assessment. We point out that in third countries without an adequacy decision a level of protection comparable to EU law cannot be guaranteed.
We plan to switch to a model provider with EU data hosting. Until then AI features will not be called with the contents of your tenders without your consent.
Please do not enter special categories of personal data (Art. 9 GDPR) or third-party personal data without a legal basis into AI input.
We use a technically necessary, httpOnly cookie (wd_token) for login and a cookie for language selection. Both are required for operation (section 25(2) TDDDG) and are not used for advertising or tracking purposes. We do not currently use marketing or analytics cookies.
We store data for as long as your account exists and this is necessary for the stated purposes. After termination, personal data is generally deleted within 30 days; statutory retention obligations (in particular commercial and tax law, 6 to 10 years) remain unaffected.
Security and error logs are regularly deleted after [90] days. Verification documents are deleted after the review has been completed unless consent for further retention exists.
Transmission is TLS-encrypted. Passwords are hashed with bcrypt. Access is restricted to authorised roles; administrative access is logged. Servers are located in Germany. We back up the database regularly and check systems for known vulnerabilities.
However, complete security of transmission over the internet cannot be guaranteed.
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing (Art. 21). Consent given can be withdrawn at any time with effect for the future (Art. 7(3)).
To exercise these rights contact [kontakt@wendory.com]. You also have the right to lodge a complaint with a data protection supervisory authority, e.g. the authority competent for our registered office: [competent supervisory authority].
There is no decision based solely on automated processing with legal effect or similarly significant effects (Art. 22 GDPR). Match values (e.g. suitability scores) are non-binding suggestions that can be reviewed by humans.
Providing your e-mail address, company name and role is required to use the platform. Without this information we cannot provide an account. Further information is voluntary but affects matching results (e.g. capacities, languages, certificates).
Where you process personal data of your own customers or applicants via the platform, you are the controller and we process this data on your behalf. The data processing agreement (DPA) forms part of the Terms (§ 14) and is agreed upon conclusion of the contract. On request we provide a signed version and the list of sub-processors.
We update this Privacy Policy when processing activities, the legal situation or the service providers used change. We notify you of material changes in advance in text form. The version available at /datenschutz with the version note above is authoritative.
We use the following service providers. Data processing agreements are in place with all of them; transfers outside the EU/EEA take place only on the basis of appropriate safeguards.
| Provider | Purpose | Location / safeguard |
|---|---|---|
| Hetzner Online GmbH | Hosting of the platform and database | Germany (EU) |
| Stripe Payments Europe, Ltd. | Payment processing and subscriptions | Ireland (EU) / USA (SCC) |
| Resend (Plus Five Five, Inc.) | Sending system and notification e-mails | USA (SCC/DPF) |
| DeepSeek (model provider) | Generating text suggestions in AI features | China – only with consent; SCC + transfer impact assessment required |
| Trustpilot A/S | Retrieval of aggregated rating figures (no user texts) | Denmark (EU) |
| Google Ireland Ltd. (Google Calendar API) | Calendar connection and meeting scheduling – only with explicit consent and an active connection; used exclusively in line with the Google API Services User Data Policy (Limited Use) | Ireland (EU) / USA (SCC/DPF) |
| Microsoft Ireland (Microsoft Graph) | Calendar connection and meeting scheduling – only with explicit consent and an active connection | Ireland (EU) / USA (SCC/DPF) |
| Komoot GmbH (Photon) | Conversion of place names into geo data | Germany (EU) |
This text is a carefully structured draft and not legal advice. Before commercial operation a qualified lawyer must review it and complete the items marked with [ ].