Privacy Policy

  1. Responsible party

Sevenflow GmbH

Humboldtstraße 67a

22083 Hamburg

info@sevenflow.de

+49 40 743 03959

  1. General information on data processing

We process personal data only to the extent necessary to provide our website, initiate and perform contracts, communicate with interested parties, customers, suppliers, and other business partners, and fulfill legal obligations. Insofar as we collect personal data directly from you, we inform you in this privacy policy about the purposes, legal bases, recipients, storage periods or criteria for determining them, as well as your rights under the applicable data protection regulations. Our offer is directed exclusively at companies and other commercial market participants. Nevertheless, we process personal data of natural persons, such as contact persons, employees, users, or applicants.


  1. Provision of the website and server log files

When you visit our website, our hosting or website service provider processes the technically necessary access data, in particular the IP address, date and time of retrieval, requested URL, referrer URL, browser type and browser version, operating system, hostname of the accessing computer, and the amount of data transferred. Processing is carried out to provide the website, ensure stability and security, perform error analysis, and prevent abusive access. The legal basis is Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the secure, stable, and efficient provision of our online offer. Recipients are our hosting or infrastructure service providers, in particular Framer.


  1. Contact via email, form, or other inquiry

If you contact us by email, contact form, appointment form or by any other means, we process the data you provide, in particular your name, company, function, contact details, communication content and, if applicable, contract or project reference. Processing is carried out to handle your request, to initiate a contract, to carry out pre-contractual measures, to document communication and, if necessary, to assert, exercise or defend legal claims. The legal basis is Art. 6 para. 1 lit. b GDPR, insofar as your inquiry is aimed at the conclusion or execution of a contract, and otherwise Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in orderly, comprehensible and efficient communication. We delete inquiries as soon as their processing is completed and there are no longer any statutory retention obligations or legitimate interests in proof.


  1. Appointment bookings via Calendly

If you schedule an appointment via an integrated booking tool, we process the data you enter or transmit, in particular your name, email address, company, requested appointment, time zone, communication content, and technical metadata. Processing is carried out for the purpose of appointment organization, communication, contract initiation, and project execution. The legal basis is Art. 6 (1) (b) GDPR and, additionally, Art. 6 (1) (f) GDPR for the efficient coordination of our business processes.

  1. Consent Management / Consent Management Platform Cookiebot

To the extent that we use technologies on our website that require consent, we use a Consent Management Platform (CMP) to obtain, manage, and document consents. In doing so, in particular your consent decision, the date and time, browser and device information, IP address in truncated form, consent ID, and the specific consent status may be processed. This processing is carried out to fulfill proof and control obligations under data protection law as well as for the legally compliant control of optional website technologies. The legal basis is Art. 6 para. 1 lit. c GDPR in conjunction with the relevant data protection and consent requirements and, additionally, Art. 6 para. 1 lit. f GDPR.


  1. Google Tag Manager

We can use Google Tag Manager to technically manage website tags. Google Tag Manager primarily serves to deploy and control other services and, according to our target configuration, does not process any independent analysis profiles itself as far as possible. Insofar as its use is associated with access to terminal equipment or downstream services requiring consent are controlled, activation only takes place after your consent. The legal basis is then Art. 6 Para. 1 lit. a GDPR; without consent, Google Tag Manager remains deactivated.


  1. Google Analytics

To the extent that we use Google Analytics, usage and interaction data of the website are processed in order to evaluate and improve the reach, usage patterns, and effectiveness of our online offer. In particular, shortened IP addresses, device and browser data, page views, duration of visit, events, referrer information, and approximate location information may be processed. Processing takes place solely on the basis of your consent pursuant to Art. 6 (1) lit. a GDPR. Without consent, the tool remains deactivated.

  1. Hotjar

To the extent that we use Hotjar, usage data is evaluated to better understand the behavior of website visitors and to improve the user-friendliness of our website. Depending on the configuration,

mouse movements, clicks, scrolling behavior, device information, screen size, browser information, language and country settings, as well as pseudonymized usage events can be processed. Processing takes place exclusively on the basis of your consent in accordance with Art. 6 Para. 1 lit. a GDPR. Without consent, Hotjar remains deactivated.

  1. Communication via video, chat, and collaboration

For communication with interested parties, customers, partners, and service providers, we use email, calendar, video conferencing, chat, and collaboration services—such as Google Workspace, Google Meet, Zoom, Microsoft Teams, Slack, Notion, or Gather—depending on the occasion. In doing so, we process in particular master and contact data, organizational data, communication content, appointment and meeting metadata, shared files, as well as technical usage data. The processing is carried out for the initiation, execution, and documentation of contractual and project relationships, for collaboration in projects, and for efficient communication. The legal basis is Art. 6 para. 1 lit. b GDPR and, additionally, Art. 6 para. 1 lit. f GDPR. If recordings, transcriptions, or AI-supported additional functions are to be used, we will indicate this separately and verify the legal basis individually.

11. Contract Performance, Project Work, and Use of Specialized Tools

In the context of initiating, executing, and processing our customer projects, we process, in particular, contact person data, communication data, contract data, project and ticket information, access and authorization data, and—depending on the project—data from the specialized systems used by the customer. This may include, in particular, CRM, support, automation, integration, data, and reporting tools such as HubSpot, Zendesk, make, n8n, Zapier, Fivetran, dbt Labs, Google Cloud, or Looker Studio, to the extent that these are actually used in a specific project. Insofar as we process such data on behalf of and in accordance with the instructions of our customer, we act as a processor; the primary responsibility under data protection law then lies with our respective customer as the controller. In these cases, data subjects should generally contact our customer first. The legal basis for processing our own contract and project data is Art. 6 (1) (b) GDPR; insofar as we act on behalf of a customer, the legal basis is determined by the controller.

12. Accounting, Billing and Dunning

For invoicing, payment processing, receivables management, and accounting processing, we specifically process master, contact, contract, billing, and payment data of our customers, suppliers, and business partners. The legal bases are Art. 6 para. 1 lit. b GDPR for contract execution, Art. 6 para. 1 lit. c GDPR for compliance with legal retention and documentation obligations, and Art. 6 para. 1 lit. f GDPR for efficient receivables management. For this purpose, we may specifically use Lexware Office, Paywise, and other financial and administrative tools in use. Please adapt this section to the stack actually being used.

  1. Applications as well as collaboration with freelancers and employees

If you apply to work with us or initiate a collaboration as a freelancer, we process the application and contract data you submit, such as master and contact data, resume, qualifications, references, compensation information, and correspondence. The processing is carried out to make a decision on the establishment and execution of an employment or freelance relationship, as well as for the administration of the collaboration. The legal basis is Art. 6 para. 1 lit. b GDPR or Art. 88 GDPR in conjunction with applicable national law, where relevant.

  1. Recipients and categories of recipients

We only transfer personal data to third parties if this is necessary for the stated purposes, if there is a legal obligation, if you have given your consent, or if another data protection authorization applies. In particular, recipients may include hosting and infrastructure service providers, CRM and marketing service providers, communication and collaboration services, accounting and payment services, legal and tax advisors, banks, subcontractors, and other technical service providers. Insofar as we use external service providers, they are integrated - where necessary - through data processing agreements or other contract instruments compliant with data protection laws.

  1. Transfers to third countries

For individual service providers used, the processing of personal data outside the European Union (EU) or the European Economic Area (EEA) cannot be ruled out, especially in the case of global cloud, communication, CRM, and analytics providers. In such cases, we ensure that an adequate level of data protection is guaranteed. This can be achieved in particular through an adequacy decision, the conclusion of standard contractual clauses, or other safeguards permitted under Chapter V of the GDPR. Please document the transfer basis used for each third-country service actually deployed in your record of processing activities and in the internal tool register before going live.

  1. Storage period

We store personal data only as long as necessary for the respective processing purposes or as required by statutory retention periods. The decisive criteria for the storage duration are, in particular, the completion of the inquiry or contract processing, the cessation of legitimate interests in documentation and proof, any limitation periods, as well as commercial and tax law retention obligations. Data that we process solely on the basis of consent is generally deleted upon revocation of consent, provided that no other legal basis or retention obligation applies.

  1. Your rights

Within the framework of legal requirements, you have the right to information about the personal data processed by us, to the correction of incorrect data, to deletion, to restriction of processing, to data portability, as well as to object to certain processing operations. Insofar as processing is based on your consent, you can revoke this at any time with effect for the future. To exercise your rights, you can contact the aforementioned contact details.

  1. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data. In particular, the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Str. 22, 20459 Hamburg, is responsible for us.

Last updated: May 26, 2026

Book Zendesk consulting now.

In this non-binding conversation, we will take the time to clarify your Zendesk requirements and discuss how I can help you get the most out of Zendesk.