Privacy Policy
Last updated: 21. Juni 2025
1. Controller
Gäking digital design, Konrad-Adenauer-Str. 20, 44534 Lünen, Germany, Phone: +49 151 19664693, Email: support@enlyst.de, Legal Representative: Christian Gäking
2. Principles of Data Processing
We process personal data according to GDPR principles: lawfully, fairly, transparently, for specific purposes, data minimized, accurate, storage limited, and ensuring appropriate security.
3. Legal Basis for Processing
Art. 6 Abs. 1 lit. a DSGVO: Consent for newsletter, marketing cookies
Art. 6 Abs. 1 lit. b DSGVO: Contract performance for registration, billing, support
Art. 6 Abs. 1 lit. c DSGVO: Legal obligation for retention of tax-relevant data
Art. 6 Abs. 1 lit. f DSGVO: Legitimate interest for website analysis, IT security
4. Types of Data Collected
Account Data
Name, email address, company, password (encrypted), subscription status
Usage Data
IP address, browser type, operating system, pages visited, duration, timestamps
Lead Data
Contact data you upload for enrichment (names, emails, companies)
Payment Data
Billing address, payment history (credit card data is only stored at Stripe)
5. Purposes of Data Processing
- Provision and operation of lead enrichment services
- Account management and authentication
- Billing and payment processing
- Customer support and technical assistance
- Platform improvement and user experience
- Fulfillment of legal obligations
- IT security and fraud protection
6. Data Sharing with Third Parties
Data Processors (Art. 28 GDPR)
- Hosting: Hetzner AG (Deutschland)
- Payments: Stripe Inc. (USA) - Adequacy Decision
- E-Mail: Mailgun
We do not sell your data to third parties. Sharing only occurs for contract fulfillment or legal obligation.
7. Cookies and Tracking
Technically Necessary Cookies
Session cookies for login, security tokens, language settings
Analytics Cookies (optional)
- currently not used -
Cookie Management
You can change your cookie settings at any time via our cookie banner or in your browser settings.
8. Storage Duration
Account Data: Until account deletion + 3 years for legal claims
Lead Data: Until manual deletion by the user
Log Data: Maximum 30 days for IT security
Payment Data: 10 years according to tax retention requirements
9. Your Rights as Data Subject
Right of Access (Art. 15 GDPR)
Information about processed data
Right to Rectification (Art. 16 GDPR)
Correction of incorrect data
Right to Erasure (Art. 17 GDPR)
Deletion of data under certain conditions
Right to Restriction (Art. 18 GDPR)
Restriction of processing
Data Portability (Art. 20 GDPR)
Export of your data in machine-readable format
Right to Object (Art. 21 GDPR)
Objection to processing based on legitimate interests
Exercising Your Rights: Contact support@enlyst.de. We process your request within one month.
10. Data Security
• SSL/TLS encryption for all data transmissions
• Encrypted data storage in ISO 27001 certified data centers
• Regular security updates and penetration tests
• Access controls and activity logs
• Data protection impact assessment for new features
12. Automated Decision Making
We use automated procedures for the following purposes:
- Data quality checking and cleansing
- Spam and fraud protection
- Enrichment algorithms for lead data
Human Review: You can request human review of automated decisions at any time.
13. Right to Complain
You have the right to complain to a data protection supervisory authority. Responsible for us is: State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, Kavalleriestr. 2-4, 40213 Düsseldorf, Germany, Email: poststelle@ldi.nrw.de
14. Changes to this Privacy Policy
We may occasionally update this privacy policy. We will notify you of significant changes by email. The current version can always be found on this page.