Privacy Policy

Last updated: 21. Juni 2025

1. Controller

Gäking digital design, Konrad-Adenauer-Str. 20, 44534 Lünen, Germany, Phone: +49 151 19664693, Email: support@enlyst.de, Legal Representative: Christian Gäking

2. Principles of Data Processing

We process personal data according to GDPR principles: lawfully, fairly, transparently, for specific purposes, data minimized, accurate, storage limited, and ensuring appropriate security.

3. Legal Basis for Processing

Art. 6 Abs. 1 lit. a DSGVO: Consent for newsletter, marketing cookies

Art. 6 Abs. 1 lit. b DSGVO: Contract performance for registration, billing, support

Art. 6 Abs. 1 lit. c DSGVO: Legal obligation for retention of tax-relevant data

Art. 6 Abs. 1 lit. f DSGVO: Legitimate interest for website analysis, IT security

4. Types of Data Collected

Account Data

Name, email address, company, password (encrypted), subscription status

Usage Data

IP address, browser type, operating system, pages visited, duration, timestamps

Lead Data

Contact data you upload for enrichment (names, emails, companies)

Payment Data

Billing address, payment history (credit card data is only stored at Stripe)

5. Purposes of Data Processing

  • Provision and operation of lead enrichment services
  • Account management and authentication
  • Billing and payment processing
  • Customer support and technical assistance
  • Platform improvement and user experience
  • Fulfillment of legal obligations
  • IT security and fraud protection

6. Data Sharing with Third Parties

Data Processors (Art. 28 GDPR)

  • Hosting: Hetzner AG (Deutschland)
  • Payments: Stripe Inc. (USA) - Adequacy Decision
  • E-Mail: Mailgun

We do not sell your data to third parties. Sharing only occurs for contract fulfillment or legal obligation.

7. Cookies and Tracking

Technically Necessary Cookies

Session cookies for login, security tokens, language settings

Analytics Cookies (optional)

- currently not used -

Cookie Management

You can change your cookie settings at any time via our cookie banner or in your browser settings.

8. Storage Duration

Account Data: Until account deletion + 3 years for legal claims

Lead Data: Until manual deletion by the user

Log Data: Maximum 30 days for IT security

Payment Data: 10 years according to tax retention requirements

9. Your Rights as Data Subject

Right of Access (Art. 15 GDPR)

Information about processed data

Right to Rectification (Art. 16 GDPR)

Correction of incorrect data

Right to Erasure (Art. 17 GDPR)

Deletion of data under certain conditions

Right to Restriction (Art. 18 GDPR)

Restriction of processing

Data Portability (Art. 20 GDPR)

Export of your data in machine-readable format

Right to Object (Art. 21 GDPR)

Objection to processing based on legitimate interests

Exercising Your Rights: Contact support@enlyst.de. We process your request within one month.

10. Data Security

SSL/TLS encryption for all data transmissions

Encrypted data storage in ISO 27001 certified data centers

Regular security updates and penetration tests

Access controls and activity logs

Data protection impact assessment for new features

12. Automated Decision Making

We use automated procedures for the following purposes:

  • Data quality checking and cleansing
  • Spam and fraud protection
  • Enrichment algorithms for lead data

Human Review: You can request human review of automated decisions at any time.

13. Right to Complain

You have the right to complain to a data protection supervisory authority. Responsible for us is: State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, Kavalleriestr. 2-4, 40213 Düsseldorf, Germany, Email: poststelle@ldi.nrw.de

14. Changes to this Privacy Policy

We may occasionally update this privacy policy. We will notify you of significant changes by email. The current version can always be found on this page.