Privacy Policy
As of: March 18, 2026
1. Controller (Art. 4 No. 7 GDPR)
NextGen IT Solutions GmbH
Stuttgart, Deutschland
E-Mail: datenschutz@nextgenitsolutions.de
2. What personal data we process
Account data
During registration, we collect: email address, name, company name, and optionally website and industry.
Payment data (affiliates)
IBAN (stored encrypted, AES-256), BIC, account holder, and optionally a PayPal email address. This data is used exclusively for payout processing.
Tracking data
When clicking affiliate links, we capture: truncated IP address (last octet anonymized), user agent string, referrer URL, click timestamp, and the attribution cookie _ngat_*. IP addresses are not stored in full (GDPR compliant).
Log data
Server logs contain IP address, timestamp, requested URL, and HTTP status code. These are automatically deleted after 30 days.
3. Legal basis for processing (Art. 6 GDPR)
| Processing purpose | Legal basis |
|---|---|
| Kontoregistrierung und -verwaltung | Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung) |
| Affiliate-Tracking und Attribution | Art. 6 Abs. 1 lit. a DSGVO (Einwilligung — Opt-IN gemäß TTDSG § 25) |
| Auszahlungsabwicklung (SEPA, PayPal) | Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung) |
| Rechnungsstellung und Buchführung | Art. 6 Abs. 1 lit. c DSGVO (rechtliche Verpflichtung) |
| Analytics und Performance-Berichte | Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse) |
| Sicherheits- und Betrugsprävention | Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse) |
4. Data sharing with EU/EEA processors
We use the following data processors based or operating in the EU/EEA. All are contractually bound under Art. 28 GDPR.
Hetzner Online GmbH (Nuremberg, Germany) — Hosting of all servers and databases (PostgreSQL, Redis, ClickHouse, Kafka, object storage). Processing exclusively within the EU.
Stripe Payments Europe, Ltd. (Dublin, Ireland) — Processing of SEPA transfers, card payments and subscription billing.
SevDesk GmbH (Offenburg, Germany) — Bookkeeping and invoice generation under SKR03 (statutory retention obligation: § 257 HGB, § 147 AO).
PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg (EU)) — Affiliate payouts via PayPal Payouts. Any onward processing by PayPal group entities outside the EU is covered by Standard Contractual Clauses (PayPal DPA).
4a. International (third-country) data transfers (Chapter V GDPR)
Certain features of our platform require personal data to be transferred to countries outside the European Economic Area. For every such transfer we rely on appropriate safeguards under Art. 46 GDPR (Standard Contractual Clauses pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, where indicated below, or on the EU-US Data Privacy Framework adequacy decision (EU) 2023/1795). The list is kept current and is also available at /docs/dsgvo/third-country-transfers in the repository.
| Service | Location | Data categories | Appropriate safeguard | Legal basis |
|---|---|---|---|---|
| Anthropic, PBC | USA | Prompt content (campaign briefs, merchant-authored descriptions). No end-customer PII. | Standard Contractual Clauses under Art. 46 (2) (c) GDPR + Transfer Impact Assessment | Art. 6 (1) (f) GDPR (AI-assisted product features) |
| Microsoft Azure OpenAI | EU or US region, depending on tenant configuration | Prompt content (as for Anthropic) | EU region: Microsoft EU Data Boundary, no third-country transfer. US region: Standard Contractual Clauses + EU-US Data Privacy Framework (Microsoft). | Art. 6 (1) (f) GDPR (fallback AI provider) |
| HubSpot, Inc. | USA | Affiliate email, first/last name, affiliate code, click/conversion totals — only when the per-tenant CRM integration is enabled. | EU-US Data Privacy Framework (HubSpot is certified) + Standard Contractual Clauses | Art. 6 (1) (f) GDPR (merchant CRM integration) |
| Salesforce.com, inc. | USA (default; org may be EU-region) | Affiliate email, first/last name, contact / opportunity records — only when the CRM integration is enabled. | EU-US Data Privacy Framework (Salesforce is certified) + Standard Contractual Clauses | Art. 6 (1) (f) GDPR |
| Shopify Inc. | Canada (adequacy decision, PIPEDA); storefront may use US/EU CDN | Order webhook payloads (customer email, tags); no card data. | EU Commission adequacy decision 2002/2/EC | Art. 6 (1) (b) and (f) GDPR |
| Resend, Inc. | USA | Recipient email address, email body (transactional emails such as reports). | EU-US Data Privacy Framework + Standard Contractual Clauses | Art. 6 (1) (b) GDPR (contractual performance) |
| Google LLC (Firebase Cloud Messaging) | USA | Device push token (no message content). | EU-US Data Privacy Framework (Google LLC is certified) + Standard Contractual Clauses | Art. 6 (1) (a) GDPR (consent via device-level push opt-in) |
| Functional Software, Inc. (Sentry) | EU region preferred (de.sentry.io); US region used as fallback | Error stack traces, request URL, scrubbed headers. No request bodies, no PII (per Sentry scrubbing configuration). | EU region: no third-country transfer. US region: Standard Contractual Clauses + EU-US Data Privacy Framework. | Art. 6 (1) (f) GDPR (service reliability, error analysis) |
You have the right to request a copy of the applicable Standard Contractual Clauses or adequacy decision. Please contact datenschutz@nextgenitsolutions.de.
5. Storage duration and deletion periods
| Data category | Retention period |
|---|---|
| Kontodaten (nach Kündigung) | Sofortige Anonymisierung auf Anfrage (Art. 17 DSGVO) |
| Sitzungsdaten | 90 Tage (automatisch); sofort bei Abmeldung |
| Tracking-Daten (Klicks) | 24 Monate (automatische Löschung) |
| Aktivitätsprotokolle (Audit Logs) | 24 Monate |
| Rechnungen und Buchungsbelege | 10 Jahre (§ 257 HGB, § 147 AO) |
| Löschungsanträge (Nachweis) | Unbegrenzt (Art. 17 DSGVO Dokumentationspflicht) |
6. Cookies
Required cookies
ng_session — enthält Sitzungs-ID, erforderlich für die Anmeldung. Laufzeit: 90 Tage.
Tracking cookies (with consent)
_ngat_* — Attribution-Cookie für Affiliate-Tracking. Speichert Affiliate-Code, Kampagnen-ID und Klick-Zeitstempel. Laufzeit: 30 Tage (konfigurierbar pro Kampagne). Kein Cross-Site-Tracking.
Consent management
Your cookie consent is stored locally in the browser and in our system. You can revoke it at any time via our consent banner.
7. Your rights as a data subject
Auskunftsrecht (Art. 15 DSGVO): Du hast das Recht, eine Kopie aller über dich gespeicherten personenbezogenen Daten zu erhalten. Im eingeloggten Bereich kannst du über Einstellungen › Datenschutz › Daten exportieren einen vollständigen Datenexport (JSON) herunterladen.
Berichtigungsrecht (Art. 16 DSGVO): Du kannst unrichtige Daten in deinem Profil jederzeit selbst korrigieren.
Löschungsrecht (Art. 17 DSGVO): Du kannst die Löschung deines Kontos jederzeit unter Einstellungen › Datenschutz › Konto löschen beantragen. Deine personenbezogenen Daten werden sofort anonymisiert. Buchhalterisch relevante Daten verbleiben entsprechend der gesetzlichen Aufbewahrungspflichten.
Widerspruchsrecht (Art. 21 DSGVO): Du kannst der Verarbeitung deiner Daten auf Basis berechtigter Interessen jederzeit widersprechen.
Datenübertragbarkeit (Art. 20 DSGVO): Du kannst deine Daten in einem maschinenlesbaren Format (JSON) exportieren.
Beschwerderecht: Du hast das Recht, eine Beschwerde bei der zuständigen Aufsichtsbehörde einzureichen: Landesbeauftragter für Datenschutz Baden-Württemberg.
8. Records of Processing Activities (Art. 30 GDPR)
Pursuant to Art. 30 GDPR we maintain a record of all processing activities. For each activity the record documents the purpose, legal basis, categories of data subjects and data, recipients, any third-country transfers, retention periods and the technical and organisational measures in place. The record is reviewed at least annually and is provided to the competent supervisory authority on request.
View the full records of processing activities (internal, GitHub)
9. Data protection inquiries
For all questions about data protection or to exercise your rights, please contact: datenschutz@nextgenitsolutions.de