Privacy policy

Last updated: 11 August 2026

1. Scope

This Privacy Policy explains how Zapdeck GmbH processes personal data when you visit www.zapdeck.ai, contact us through the website, subscribe to a newsletter or book a meeting through a scheduling service offered on or linked from the website.

It applies only to our public website and associated landing pages. Separate privacy information applies to the Zapdeck product and to data processed on behalf of our customers.

2. Controller

Zapdeck GmbH
Revaler Str. 13
10245 Berlin
Germany

Email: hello@zapdeck.ai

3. Legal bases

Depending on the processing activity, we process personal data on the basis of:

  • consent pursuant to Article 6(1)(a) GDPR;
  • pre-contractual measures or performance of a contract pursuant to Article 6(1)(b) GDPR;
  • compliance with legal obligations pursuant to Article 6(1)(c) GDPR; or
  • our legitimate interests pursuant to Article 6(1)(f) GDPR.

Where information is stored on or accessed from your device, we also apply Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG). Non-essential technologies, particularly advertising and marketing technologies, are activated only after you have provided consent.

4. Website hosting

We use Webflow, Inc. to create, host and operate our website.

When you visit the website, Webflow and its infrastructure providers may process technical information such as:

  • IP address;
  • requested page or file;
  • date and time of access;
  • referring page;
  • browser and device information;
  • operating system;
  • language and time-zone settings;
  • response status; and
  • security and diagnostic information.

The processing is necessary to deliver the website, ensure its stability and security, prevent misuse and resolve technical problems. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable provision of our website. Technically necessary access to information on your device is based on Section 25(2) TDDDG. Technical data is retained only for as long as necessary for operation, security and error analysis. Data required to investigate a security incident may be retained until the incident has been resolved. Webflow processes data on our behalf. Webflow and its subprocessors may process data outside the European Economic Area. Such transfers are protected, where required, by an adequacy decision, the EU–US Data Privacy Framework, Standard Contractual Clauses or another recognised transfer mechanism.

5. Contact and access-request forms

You can contact us or request access to our services through forms on the website.

Depending on the form, we process:

  • first and last name;
  • business email address;
  • company name;
  • company size;
  • information entered into the form;
  • date and time of submission;
  • technical submission data;
  • reCAPTCHA verification information; and
  • advertising-click information where marketing consent has been granted.

The forms are operated through Webflow. Submissions are stored in Webflow and sent to us by email. We process this information to respond to enquiries, assess access requests, arrange meetings, provide information about our services and prepare a possible contractual relationship. The legal basis is Article 6(1)(b) GDPR where the enquiry relates to a potential contract. For other enquiries, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the efficient handling and documentation of business enquiries. Submitting a form does not require consent to marketing technologies. Data relating to business enquiries and prospective customers is generally retained for three years after the last substantive contact. It is then deleted unless an active business relationship continues, retention is required by law, or the data is needed to establish, exercise or defend legal claims.

6. Email communication

Our business email accounts are hosted by:

netcup GmbH
Daimlerstraße 25
76185 Karlsruhe
Germany

When you send us an email or submit a form that generates an email notification, netcup may process sender and recipient addresses, message content, attachments, timestamps and technical delivery information. The legal basis is Article 6(1)(b) GDPR for contractual or pre-contractual communication and Article 6(1)(f) GDPR for other business communication. Emails relating to enquiries are generally retained for three years after the last substantive contact. Statutory retention requirements may result in longer storage.

7. Customer relationship management with Pipedrive

We use Pipedrive OÜ, Estonia, to manage business enquiries, prospective customers, meetings and sales-related communication. Information stored in Pipedrive may include:

  • name and business contact details;
  • company and role;
  • content and status of an enquiry;
  • meeting and communication history;
  • internal notes;
  • source of the enquiry; and
  • advertising-attribution information, including a GCLID where available.

The purposes are to organise enquiries, manage follow-up communication, document business relationships and prepare possible contracts. The legal basis is Article 6(1)(b) GDPR where processing relates to a potential or existing contract. Otherwise, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is efficient customer relationship management. Pipedrive processes data on our behalf and may use subprocessors, including providers located outside the European Economic Area. Data relating to business enquiries and prospective customers is generally retained for three years after the last substantive contact. It is then deleted unless an active business relationship continues, retention is required by law, or the data is required for legal claims.

8. Workflow automation with Make

For selected enquiries, we may use Make, a Celonis product, to transfer information between authorised systems such as Webflow, email services and Pipedrive. Depending on the workflow, Make may temporarily process:

  • form information;
  • business contact details;
  • message content;
  • identifiers and timestamps;
  • campaign and GCLID information; and
  • technical execution and error logs.

Make is not necessarily used for every enquiry. The purpose is to reduce manual administrative work and ensure that enquiries are transferred to the correct systems and employees. The legal basis is Article 6(1)(b) GDPR for pre-contractual processing and Article 6(1)(f) GDPR for efficient internal organisation. Make processes data on our behalf. International transfers are protected, where required, by appropriate safeguards. Workflow data and logs are retained only for as long as required for processing, troubleshooting and security.

9. Consent management with Cookiebot

We use Cookiebot CMP, provided by Usercentrics A/S, Denmark, to obtain, manage and document your privacy choices. Cookiebot may process:

  • the website URL;
  • browser and device information;
  • date and time of your selection;
  • consent categories accepted or rejected;
  • a generated consent identifier; and
  • the current consent status.

Cookiebot stores a necessary consent cookie named CookieConsent to remember and document your selection. The legal bases are Article 6(1)(c) and Article 6(1)(f) GDPR. The necessary storage on your device is based on Section 25(2) TDDDG. You can change or withdraw your consent at any time through the cookie settings on the website. Withdrawal does not affect processing carried out before withdrawal.

10. Google reCAPTCHA

We use Google reCAPTCHA and Cloudflare security services, including Cloudflare Turnstile where applicable, to protect our website and forms against spam, automated submissions, attacks and other misuse. The providers are:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

and

Cloudflare, Inc.

101 Townsend Street

San Francisco, CA 94107

United States

Depending on the service used, the following information may be processed:

  • IP address;
  • browser and device information;
  • operating system;
  • page and referrer information;
  • language settings;
  • mouse movements, keystrokes and interaction data;
  • cookies or browser-storage identifiers;
  • date and time;
  • verification results; and
  • security and risk information.

These services may store technically necessary identifiers such as _grecaptcha, rc::a, rc::c, cf.turnstile.u or _cfuvid. The purposes are to prevent spam, automated submissions, attacks and other misuse and to ensure the availability and security of our forms and website. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are protecting our website, preventing misuse and ensuring the security and availability of our forms. Where storage on or access to the device is strictly necessary for these security functions, Section 25(2) TDDDG applies. Google and Cloudflare may process data outside the European Economic Area. Applicable transfers are protected by recognised transfer mechanisms. You may alternatively contact us directly at hello@zapdeck.ai.

11. Google Ads conversion tracking

With your consent, we use Google Ads conversion tracking to measure whether advertisements lead to relevant actions on our website. The provider is Google Ireland Limited. Google Ads is loaded only after you consent to marketing technologies. The following information may be processed:

  • IP address;
  • browser and device information;
  • page and referrer information;
  • advertising and cookie identifiers;
  • campaign information;
  • Google Click Identifier;
  • date and time of the advertising click;
  • consent signals; and
  • information that a defined conversion occurred.

Google Ads may store cookies such as _gcl_au and _gcl_aw.

When a designated form is submitted successfully, we may report a conversion to Google. The conversion event does not include the contents of the form, your name, your email address or your telephone number. The purposes are to measure advertising performance, attribute enquiries to advertising campaigns and optimise our advertising activities. The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR. Google may process data outside the European Economic Area. Applicable transfers are protected by recognised transfer mechanisms. You can withdraw your consent at any time through the cookie settings.

12. GCLID storage and offline conversion measurement

Where you reach our website through a Google advertisement, the landing-page URL may contain a Google Click Identifier, or GCLID. Subject to your marketing consent, we:

  1. read the GCLID from the website URL;
  2. store it in your browser’s Local Storage;
  3. place it in a hidden field in the relevant website form; and
  4. transmit it with the form submission to Webflow and our authorised enquiry-management systems.

The GCLID is stored in the browser for a maximum of 90 days. It is deleted earlier if the relevant website data is removed or marketing consent is withdrawn. The GCLID may be stored together with the corresponding enquiry in our email system, Pipedrive and authorised workflow systems.

Where an enquiry qualifies as a relevant lead or reaches a defined sales milestone, we may transmit the GCLID, the conversion time and the relevant conversion category to Google Ads as an offline conversion. We do not transmit the contents of the enquiry, your name, email address or telephone number to Google as part of this offline conversion upload. The purposes are to associate enquiries and subsequent business outcomes with advertising campaigns, measure campaign performance and optimise advertising expenditure. The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR. GCLID information stored with an enquiry is generally deleted three years after the last substantive contact unless an active business relationship or legal retention requirement continues. You can use the form without agreeing to this processing.

13. Snitcher

With your consent, we use Snitcher, a service provided by: Snitcher B.V., Oude Enghweg 2, 1217 JC Hilversum, The Netherlands. Snitcher helps us identify organisations that visit our website and understand how business visitors use our website. For this purpose, Snitcher may process:

  • IP address;
  • browser, device and technical information;
  • a randomly generated device identifier and session identifier;
  • pages visited;
  • date, time and duration of visits;
  • referring page and source information;
  • interactions with website content; and
  • company information obtained by matching the IP address against Snitcher’s company database, including company name, website, industry, location and approximate size.

Snitcher processes the IP address to determine whether the visit can be associated with a business organisation. We receive company-level information and website-usage information, but Snitcher does not disclose the visitor’s IP address or identity to us. We currently do not use Snitcher’s optional form-tracking or individual-identification features.
The Snitcher tracker is activated only after you consent to marketing technologies through our consent-management system. After consent, Snitcher may store a first-party cookie named snitcher_device_id and a corresponding identifier in Local Storage for up to one year. Snitcher also stores session information under snitcher_session in Local Storage for up to 30 minutes after the last activity.

We use this information to understand which organisations are interested in our services, analyse the use of our website, improve our content and support our B2B sales activities. The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR. You can withdraw your consent at any time through the cookie settings. Withdrawal does not affect processing carried out before withdrawal. According to Snitcher, tracking data is processed and stored within the European Union using infrastructure located in Frankfurt, Germany, and is encrypted in transit and at rest. Where Snitcher processes personal data on our behalf, it acts as our processor. We retain company-visit information only for as long as necessary to assess and follow up potential business interest. It is generally deleted no later than three years after the last relevant interaction, unless it forms part of an active customer or prospect relationship or longer retention is required by law. Further information is available in Snitcher’s Privacy Policy. https://www.snitcher.com/privacy-policy

14. Newsletter with MailerLite

This section applies when a newsletter-subscription function is displayed on the website. We use MailerLite Limited, Ireland, to manage subscriptions and send newsletters. We may process:

  • email address;
  • name, where requested;
  • date and time of registration;
  • IP and technical registration information;
  • proof of consent;
  • newsletter preferences;
  • delivery and bounce information;
  • unsubscribe information; and
  • opening and link-click information.

Where the corresponding tracking options are enabled, MailerLite may record whether a newsletter was opened and which links were clicked. We use this information to evaluate and improve our newsletters. The newsletter is sent on the basis of your consent pursuant to Article 6(1)(a) GDPR. Where non-essential browser technologies are used, Section 25(1) TDDDG also applies. We may use a confirmation email to verify the subscription.

You can unsubscribe at any time using the unsubscribe link included in each newsletter or by contacting hello@zapdeck.ai. After unsubscribing, your address may be retained in a suppression list to ensure that no further newsletters are sent. The legal basis is Article 6(1)(f) GDPR.

15. Appointment scheduling with Cal.com

This section applies when a Cal.com booking function is displayed or linked on the website. We use Cal.com, Inc. to allow interested persons to select and book meetings. Cal.com may process:

  • name and email address;
  • company information;
  • selected meeting type;
  • date, time and time zone;
  • information entered into booking fields;
  • IP address and technical usage information;
  • availability information; and
  • confirmation and reminder information.

The purposes are to display available times, arrange meetings, avoid scheduling conflicts and send confirmations or reminders. The legal basis is Article 6(1)(b) GDPR where the meeting relates to a potential contract. Otherwise, the legal basis is Article 6(1)(f) GDPR. Booking information is generally retained for three years after the meeting unless it becomes part of an active business relationship or longer retention is required by law. Where Cal.com is embedded directly into our website and uses non-essential technologies, these technologies are activated only after the relevant consent. Where we provide only an external link, Cal.com processes your information after you follow that link.

16. YouTube videos

We may embed videos from our YouTube account on the website. The provider is Google Ireland Limited. YouTube videos are activated only after you provide the relevant consent. Before activation, no connection to YouTube should be established through the embedded player. When you activate or play a video, Google and YouTube may process:

  • IP address;
  • page and referrer information;
  • browser and device information;
  • date and time;
  • video viewed and playback activity;
  • cookies and online identifiers;
  • interactions with the video player; and
  • information associated with your Google account where you are signed in.

Google may use this information to provide the video, maintain security, measure usage and personalise services or advertising. The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR. Google may process data outside the European Economic Area. Applicable transfers are protected by recognised transfer mechanisms. You can withdraw your consent through the cookie settings.

17. Finsweet Attributes and jsDelivr

We use the Finsweet Attributes JavaScript library for functional website features. The script is delivered through the jsDelivr content delivery network. The CDN infrastructure may process:

  • IP address;
  • browser and device information;
  • requested file;
  • date and time;
  • referring page; and
  • security and diagnostic information.

The purpose is to provide website functions efficiently and securely. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the functional and reliable operation of the website.

18. Cookies and similar technologies

We use cookies and similar technologies in the following categories:

Necessary technologies

These technologies are required to operate the website, remember privacy choices, protect forms or provide functions requested by the visitor. The legal basis for storing or accessing information on the device is Section 25(2) TDDDG.

Marketing technologies

These technologies are used for advertising attribution, conversion measurement, embedded external content and business-visitor analysis. They are activated only after consent. The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR. The specific technologies, purposes and storage periods detected on the website are shown in our Cookie Declaration. You can change or withdraw your selection at any time through the cookie settings.

19. Recipients

Depending on the processing activity, recipients may include:

  • authorised Zapdeck employees;
  • website and hosting providers;
  • email providers;
  • consent-management providers;
  • CRM and workflow providers;
  • advertising and analytics providers activated with your consent;
  • newsletter and scheduling providers;
  • internal communication and collaboration providers;
  • legal, tax and other professional advisers; and
  • public authorities where legally required.

Service providers acting on our behalf are contractually required to process data only in accordance with our instructions and applicable law.

20. International transfers

Some providers or their subprocessors may process personal data outside the European Union or European Economic Area. Where no adequacy decision applies, transfers are protected, where required, by Standard Contractual Clauses, the EU–US Data Privacy Framework for certified recipients, binding corporate rules or another recognised transfer mechanism.

21. Storage and deletion

Unless a specific period is stated above, personal data is retained only for as long as necessary for the relevant purpose. Relevant criteria include:

  • whether an enquiry or business relationship remains active;
  • statutory retention requirements;
  • applicable limitation periods;
  • security requirements;
  • consent status; and
  • the need to establish, exercise or defend legal claims.

Data is deleted or anonymised when it is no longer required. It may remain temporarily in backups until the relevant backup is overwritten.

22. Your rights

Subject to the statutory requirements, you have the right to:

  • request access to your personal data;
  • request correction of inaccurate data;
  • request deletion;
  • request restriction of processing;
  • receive data in a portable format where applicable;
  • withdraw consent at any time with effect for the future;
  • object to processing based on legitimate interests; and
  • object at any time to direct-marketing processing.

To exercise your rights, contact: hello@zapdeck.ai

We may request information necessary to verify your identity.

23. Complaints

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for our registered office is:

Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61
10555 Berlin
Germany

Email: mailbox@datenschutz-berlin.de

24. Automated decision-making

We do not use data collected through the public website to make decisions based solely on automated processing that produce legal or similarly significant effects concerning an individual. Automated processes used for advertising attribution, company recognition or statistics are not used to make such decisions.

25. B2B prospect research and outreach

We may process professional contact information relating to potential business contacts, including names, job titles, employers, professional profiles and business email addresses. This information may originate from company websites, publicly accessible professional sources and commercial business-contact databases. Potential contacts may be selected based on their professional role, company characteristics and company-level business-interest signals. We do not identify or assume that the contacted person personally visited our website.

We process this information to research potentially relevant organisations, prepare personalised business communication and contact professional representatives about our services, where permitted by applicable law. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is developing relevant business relationships and presenting our services to potentially interested organisations. We may use service providers for business-data research, data enrichment, AI-assisted research and drafting, and email delivery. Data is retained only for as long as necessary for these purposes and is generally deleted no later than three years after the last substantive contact. You may object to the use of your personal data for direct marketing at any time by replying to our email or contacting hello@zapdeck.ai. After an objection, we will stop using your data for marketing. We may retain a minimal suppression record to ensure that you are not contacted again.

26. Security

We use appropriate technical and organisational measures to protect personal data, including encrypted connections, access restrictions, authorisation controls, backups and contractual safeguards for service providers.

27. Changes

We may update this Privacy Policy where our website, processing activities, providers or legal obligations change.

The version currently published on the website applies.

28. Cookie Declaration