Privacy Notice
Last updated:
This privacy notice explains how personal data is processed on the website purrcruit.com and in connection with our services.
This is a translation of the German original. In case of divergence, the German version prevails.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Purrcruit GmbH i.G.
Kaiserswerther Straße 135
40474 Düsseldorf
Germany
Email: [email protected]
Further provider details are set out in the Impressum. No data protection officer is currently appointed, as the requirements of Art. 37 GDPR in conjunction with § 38 German Federal Data Protection Act are not met. Please direct your enquiries to the address above.
2. Our role: controller and processor
We act in two distinct roles:
- We are the controller for the personal data we ourselves collect about visitors to this website, about prospects, customers and their user accounts — that is, for everything described in this notice.
- We are a processor for the personal data our customers process in the Purrcruit platform, in particular applicant and employee data. In those cases the controller is the company using the platform. The basis is a data processing agreement under Art. 28 GDPR, which we provide on request. Applicants should direct their requests to the company they applied to.
3. Processing activities in detail
3.1 Visiting the website and server logs
When you visit this website, technically necessary data is processed to deliver the page and secure operation.
- Data categories: IP address, date and time of access, URL requested, referrer, user agent (browser, operating system), volume of data transferred, HTTP status code.
- Purposes: delivering the website, ensuring system security and stability, detecting and defending against attacks and misuse.
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and functional operation of the website.
- Recipients: Microsoft Ireland Operations Limited as hosting provider (Azure Static Web Apps).
- Retention: server logs are deleted or truncated after 30 days at the latest, unless a specific security incident requires longer retention for investigation.
The Montserrat typeface used on this website is served from our own server. No connection is made to Google Fonts or fonts.gstatic.com, so your IP address is not transmitted to third parties for this purpose.
3.2 Waiting list and newsletter sign-up
If you enter your email address in the sign-up form on this website, we process that information to tell you about the product launch and relevant news.
- Data categories: email address, IP address, date and time of sign-up, record of the consent given.
- Purposes: sending product and launch information, demonstrating consent.
- Legal basis: Art. 6(1)(a) GDPR (consent). Storing the IP address and timestamp serves to demonstrate consent under Art. 7(1) GDPR and is based on Art. 6(1)(c) and (f) GDPR.
- Recipients: the data is stored on a server we operate within the European Union. No external newsletter provider is used.
- Retention: until you withdraw your consent, and at most twelve months after the product launch. We retain the consent record for the duration of the statutory limitation periods.
You can withdraw your consent at any time with effect for the future, informally by email to [email protected]. The lawfulness of processing carried out before withdrawal is unaffected.
3.3 Analytics with PostHog
We use PostHog to understand how this website is used and to improve it. PostHog is only loaded after you have consented. Until you consent, no script is loaded, no cookie is set and no connection to PostHog is made.
- Data categories: pseudonymous user ID, pages visited, time spent, referrer, truncated IP address, device type, browser, operating system, screen resolution, and events triggered (such as clicking a pricing button, switching the billing period, or clicking a social media link in the footer).
- Purposes: statistical analytics, analysis of usage behaviour, improvement of content and usability.
- Legal basis: Art. 6(1)(a) GDPR in conjunction with § 25(1) German Telecommunications Digital Services Data Protection Act (TDDDG) — consent.
- Recipients: PostHog. Processing takes place in PostHog’s EU region (eu.i.posthog.com) on servers within the European Union, under a data processing agreement pursuant to Art. 28 GDPR.
- Retention: event data is deleted or aggregated after twelve months at the latest.
You can withdraw your consent at any time using the Cookie settings button in the footer of this website. After withdrawal no further data is collected.
3.4 Purchase, billing and payment processing
If you take out a paid subscription, the payment is handled by our merchant of record, Paddle.
- Data categories: name, billing address, country, email address, VAT identification number, order and invoice data, payment status. We never receive full payment details such as card numbers.
- Purposes: performance of the contract, invoicing, collection and remittance of tax, subscription management, fraud prevention, compliance with commercial and tax law obligations.
- Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(c) GDPR (statutory retention and tax obligations) and Art. 6(1)(f) GDPR (fraud prevention).
- Recipients: Paddle.com Market Limited, 30 Old Bailey, London EC4M 7AU, United Kingdom (for purchases from the United States or Canada: Paddle.com Inc. or Paddle.com (Canada) Ltd. respectively). Paddle acts as merchant of record and, for payment processing, as an independent controller. The Paddle privacy notice applies in that respect.
- Retention: contract and billing data is retained for six or ten years in line with the statutory retention periods under § 257 German Commercial Code and § 147 German Fiscal Code, and deleted thereafter.
3.5 Contact and support
- Data categories: name, email address, company affiliation, the content of your enquiry and subsequent correspondence.
- Purposes: handling your enquiry, support, keeping a record of the exchange.
- Legal basis: Art. 6(1)(b) GDPR for contract-related enquiries, otherwise Art. 6(1)(f) GDPR based on our legitimate interest in responding to enquiries.
- Retention: until your enquiry has been fully dealt with, then in line with statutory retention periods. Commercial letters are subject to the six-year period under § 257(4) German Commercial Code.
3.6 User accounts and use of the platform
If you use the Purrcruit platform as a customer, we process account, permission and usage data in order to provide and secure the service.
- Data categories: master and contact data, company affiliation, account and permission data, login and log data, technical usage data on configuration, availability, errors and security events.
- Purposes: providing and administering the platform, user management, security and abuse prevention, error analysis, further development.
- Legal basis: Art. 6(1)(b) GDPR for performance of the contract, Art. 6(1)(f) GDPR for security, abuse prevention and further development.
- Retention: for the duration of the contractual relationship. After the contract ends we make the data available for export for 60 days and then delete or anonymise it, unless statutory retention obligations apply. Security logs are deleted in accordance with our erasure policy.
We process our customers’ content data — in particular application documents and employee data — exclusively on their instructions, as a processor (see section 2).
4. Recipients and processors
We only share personal data where this is necessary and legally permissible. Categories of recipients are:
- Hosting and infrastructure: Microsoft Ireland Operations Limited (Azure, data centres in the EU).
- Analytics: PostHog (EU region), only after consent.
- Payment processing and merchant of record: Paddle (see section 3.4) for the sale, subscription management, payments, and tax and invoicing.
- Professional advisers: lawyers, tax advisers and auditors, where necessary to assert our rights or comply with statutory obligations.
- Authorities and courts, where we are legally obliged to provide information or where disclosure is necessary to pursue legal claims or protect rights and safety.
We conclude data processing agreements under Art. 28 GDPR with service providers who process personal data on our behalf. A list of the sub-processors used for the platform is provided to customers on request.
5. Transfers to third countries
Processing for hosting and analytics takes place within the European Union.
A transfer to a third country occurs in connection with payment processing: Paddle.com Market Limited is established in the United Kingdom. An adequacy decision of the European Commission under Art. 45 GDPR is in place for the United Kingdom, so the transfer is permitted without additional safeguards. If you purchase from the United States or Canada, your contracting party is the local Paddle entity.
Where, in an individual case, service providers outside the European Economic Area and without an adequacy decision are used, we base the transfer on the European Commission’s standard contractual clauses under Art. 46(2)(c) GDPR together with supplementary safeguards. You can request a copy of the safeguards at [email protected].
6. Retention
We store personal data only for as long as is necessary for the respective purposes. The specific periods are stated with each processing activity in section 3. Statutory retention obligations also apply, in particular six years for commercial letters under § 257(4) German Commercial Code and ten years for accounting records and invoices under § 147(3) German Fiscal Code. Once the relevant period has expired, the data is deleted or irreversibly anonymised.
7. Your rights
You have the following rights in relation to us:
- Access to the data processed about you (Art. 15 GDPR);
- Rectification of inaccurate or incomplete data (Art. 16 GDPR);
- Erasure of your data (Art. 17 GDPR);
- Restriction of processing (Art. 18 GDPR);
- Data portability in a structured, commonly used and machine-readable format (Art. 20 GDPR);
- Objection to processing based on Art. 6(1)(f) GDPR, on grounds relating to your particular situation (Art. 21 GDPR);
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR), without affecting the lawfulness of processing carried out up to that point.
An informal message to [email protected] or to our postal address is sufficient to exercise them. We respond to requests within one month of receipt. That period may be extended by up to two further months for complex or numerous requests; we will inform you of any extension and its reasons within the first month.
Right to lodge a complaint: you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf, Germany
ldi.nrw.de
You may also contact the supervisory authority of your habitual residence or place of work.
8. Security
We implement technical and organisational measures under Art. 32 GDPR to protect your data against loss, misuse and unauthorised access. These include in particular:
- encryption in transit (TLS) and encryption of data at rest;
- access control on a need-to-know basis, role-based permissions and multi-factor authentication for administrative access;
- logging of security-relevant events and regular review;
- regular backups and tested recovery and contingency plans;
- confidentiality obligations for all staff and regular training.
These measures are developed further on a risk basis. A detailed description of the technical and organisational measures is provided to customers on request.
9. No automated decision-making
There is no solely automated decision-making, including profiling, within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you. The platform’s AI-assisted features are supportive; the decision is always made by a person at the responsible company.
10. Cookies and similar technologies
We use cookies and comparable storage technologies only to the extent described below. Technologies that are not strictly necessary are activated only after your consent (§ 25(1) TDDDG).
Necessary
| Name | Purpose | Provider | Duration | Legal basis |
|---|---|---|---|---|
purrcruit_consent |
Stores your decision about analytics so we do not ask again and can demonstrate consent (local storage). | Purrcruit | Until withdrawal or clearing of browser data | § 25(2) no. 2 TDDDG; Art. 6(1)(c) and (f) GDPR |
Analytics (only with consent)
| Name | Purpose | Provider | Duration | Legal basis |
|---|---|---|---|---|
ph_<project token>_posthog |
Stores a pseudonymous identifier to recognise returning sessions and analyse usage statistically. | PostHog (EU) | 12 months | § 25(1) TDDDG; Art. 6(1)(a) GDPR |
We do not use marketing or advertising cookies.
How to change your setting
You can change or withdraw your decision at any time using the Cookie settings button in the footer of this website. You can also delete or block cookies and local storage in your browser settings. If you clear your browser data, we will ask again on your next visit.
11. Whether provision is required
Providing contract and account data is necessary to perform the contract; without it we cannot provide the platform. Providing your email address for the waiting list and consenting to analytics are entirely voluntary, and you suffer no disadvantage if you do not.
12. Source of the data
We generally collect personal data directly from you. Where we exceptionally receive data from third parties — for example contact details of a contact person via the company using the platform — we inform the data subject about the source and the processing in accordance with Art. 14 GDPR.
13. Changes to this privacy notice
We update this notice when the procedures we use or the legal position change. The version published on this page applies. The date of the last change is shown at the top of this page.