Legal

Privacy Policy

This privacy policy transparently informs you about the nature, scope and purpose of the processing of personal data when you visit this website. It applies to https://www.kaemi.website.

Last updated: 5 September 2026

Controller

The controller responsible for data processing within the meaning of the DSGVO (the German designation of the EU General Data Protection Regulation, GDPR) is:

KAEMI GmbH
Glogauer Str. 5
10999 Berlin
Germany

Phone: +49 30 3642 878-0
Fax: +49 30 3642 878-99
Email: info@kaemi.email

Please address any inquiries relating to data protection in writing to the address above or by email to datenschutz@kaemi.email.

You can reach our data protection officer at: Samir Omar, c/o KAEMI GmbH, Glogauer Str. 5, 10999 Berlin, email: datenschutz@kaemi.email.

Hosting and Processors

This website is operated on the edge platform of Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA) and delivered via Cloudflare Workers. The content database (Cloudflare D1) and the media storage (Cloudflare R2) are set up with the “EU jurisdiction” restriction; for these two stores Cloudflare guarantees that data is stored and processed exclusively within the European Union. The key-value store (Cloudflare KV) is replicated globally; it holds no visitor data, only cached public pages, editorial login sessions and technical counters. Individual page requests (TLS termination, execution of the Worker, caching) are handled in the Cloudflare data centre closest to the respective visitor – usually within the EU for visitors from the EU, and in third countries for visitors from elsewhere. Technical log and analytics data about these requests (section 3) may be stored without a location restriction in Cloudflare’s core data centres worldwide.

Whenever a page is requested, technically required access data (IP address, date/time, requested URL, transmitted user agent, referrer) is processed by Cloudflare to enable delivery of the website and to fend off attacks (bot mitigation, DDoS protection). This processing is based on our legitimate interest in secure operation (Art. 6(1)(f) DSGVO).

A data processing agreement (DPA) including the EU Standard Contractual Clauses (SCC) is in place with Cloudflare to safeguard any data flows outside the European Economic Area. Cloudflare, Inc. is additionally certified under the EU-US Data Privacy Framework (DPF). Cloudflare’s privacy policy is available at https://www.cloudflare.com/privacypolicy/.

Server Log Files

When this website is accessed, technically required access data (server log files) is processed by our infrastructure provider Cloudflare: IP address, date and time of access, requested URL, transmitted user agent (browser/operating system) and the previously visited page (referrer).

This processing serves the secure and stable operation of the website, error analysis and the defence against attacks (bot mitigation, DDoS protection). The legal basis is our legitimate interest in a secure and trouble-free operation (Art. 6(1)(f) DSGVO).

The access data is stored for a maximum of 30 days; in the event of security-relevant incidents, individual records may be retained for longer where this is necessary for investigation and defence.

Cookies and Similar Technologies

We use technically necessary cookies (no consent required pursuant to § 25 (2) no. 2 TDDDG — German Telecommunications Digital Services Data Protection Act) and – only with your consent – cookies and storage data for the categories “Statistics”, “Visitor identification (sales)”, “Marketing” and “Functional”. Consent is given via the cookie notice and can be withdrawn at any time (see “Withdrawing your cookie consent”). In addition to cookies, comparable technologies such as your browser’s local storage may be used — by optional third-party services only after your consent.

On your first visit, our cookie notice shows the most important information and offers the choices “Accept all”, “Decline” (technically necessary cookies only) and “Settings” for a granular selection per category.

Overview of the cookies used

Withdrawing your cookie consent

You can change your selection in the cookie notice at any time. To do so, click “Cookie settings” in the page footer. The banner opens again and you can adjust your decision.

Processing of Form Inquiries

This website offers several forms you can use to contact us: the contact form at /kontakt/ and /en/contact/, the enquiry form on the Cloudflare One page, the whitepaper request form on the SASE whitepaper page (/sase-whitepaper-download/), the workshop registration form and the compact form in the page footer.

Mandatory fields are marked with an asterisk (*). Only the information you actively enter into the form is transmitted (name or first and last name, email address, company, phone number and message where applicable; on the whitepaper form additionally – optionally – your role in the company, so that we can answer follow-up questions in a way that fits your function). The legal basis is Art. 6(1)(b) DSGVO: we process your details to answer your enquiry, to provide the requested whitepaper or to carry out your workshop registration (performance of a contract or of pre-contractual measures at your request). If you contact us as an employee of a company in the course of business communication, we additionally rely on our legitimate interest in handling and answering business enquiries (Art. 6(1)(f) DSGVO). No separate consent is required for this; the privacy notice next to the form is provided for your information. Marketing communication beyond answering your enquiry only takes place within the limits permitted by law (§ 7(3) UWG, existing customers) or with your separate consent. On the whitepaper form, a voluntary, unticked checkbox lets you allow us to inform you by email about products, services, studies and events (Art. 6(1)(a) DSGVO, § 7(2) no. 2 UWG); you receive the whitepaper regardless. You can withdraw this consent at any time with effect for the future – via the unsubscribe link in every email or by message to datenschutz@kaemi.email; we document the time and content of your consent for accountability purposes (Art. 7(1) DSGVO).

Providing your data is voluntary; there is no statutory or contractual obligation to provide it. Without the fields marked as mandatory (*), however, we cannot process your inquiry or provide the requested download. Merely visiting this website does not require you to provide any personal data either.

The transmission is encrypted (HTTPS / TLS). The contents of your inquiry are technically delivered via the email delivery service Cloudflare Email Service as an email from the sender domain noreply@kaemi.app to the central sales mailbox sales@kaemi.io. The reply-to address corresponds to the email address you provided so that our staff can respond directly.

Your details are not stored in the database of this website — the data is only forwarded as an email. We delete mere contact inquiries without any contractual relevance no later than six months after their final handling, unless statutory retention obligations prevent this. If you have consented to marketing emails, we keep your contact details for this purpose until you withdraw your consent. After a withdrawal we remove your contact details from the marketing list; we retain the record of your consent and of the withdrawal (time, content, source) until the end of the third calendar year following the withdrawal in order to demonstrate the lawfulness of earlier emails (standard limitation period, §§ 195, 199 BGB – German Civil Code), and your email address remains on a suppression list during this period so that no further marketing contact takes place (Art. 6(1)(f) DSGVO). If your inquiry leads to a business relationship, the retention periods under German commercial and tax law apply (including § 257 HGB — German Commercial Code — and § 147 AO — German Fiscal Code — generally six or eight years); once these periods expire, the data is deleted.

To protect against spam and abuse, we check form submissions server-side (including a honeypot field that is invisible to you) and limit the number of submissions per time unit (rate limiting). No further evaluation of your behaviour takes place.

In addition, we protect our forms with Cloudflare Turnstile, a bot-detection service provided by Cloudflare, Inc. When a form is loaded and submitted, your browser transmits technical information (including IP address, device and browser signals and interaction data) to Cloudflare so that human users can be distinguished from bots automatically; a technically necessary cookie may be set for this purpose. This processing serves abuse and bot detection only – no cross-site tracking and no use for advertising purposes takes place. The legal basis is our legitimate interest in protecting our forms against spam, abuse and automated attacks (Art. 6(1)(f) DSGVO); setting the technically necessary cookie does not require consent pursuant to § 25 (2) TDDDG. Cloudflare acts as a processor; the data processing agreement including Standard Contractual Clauses (SCC) referred to in section 2 and the DPF certification mentioned there apply.

Please do not send us any special categories of personal data within the meaning of Art. 9 DSGVO (for example health data or information on ideological beliefs) via the forms or by email. If transmitting such data is necessary in an individual case, please contact us in advance at datenschutz@kaemi.email.

Newsletter

We do not currently offer a newsletter (see also section 18). Should we introduce one in future, we will inform you here in advance about the associated data processing. You will only receive marketing emails from us with your consent or – as an existing customer – within the limits permitted by law under § 7(3) UWG (German Act against Unfair Competition) for our own similar services (see also section 5). You can object to such marketing communication at any time informally (see section 10); after that you will receive no further marketing emails.

Email Delivery via Cloudflare Email Service

We use Cloudflare Email Service on the domain kaemi.app to send the notifications described in section 5. As a result, the contents of your form inquiry (including your email address as the reply-to address) are processed by Cloudflare in order to deliver the email to the KAEMI recipient addresses. The processing takes place on behalf of KAEMI GmbH on the basis of a data processing agreement and the EU Standard Contractual Clauses. Cloudflare, Inc. is additionally certified under the EU-US Data Privacy Framework (DPF).

SSL/TLS Encryption

This website uses SSL/TLS encryption without exception. You can recognise this by the padlock symbol in the address bar of your browser and by the prefix “https://” before the domain. During an encrypted connection, data you transmit to us cannot be read by third parties.

Technical and Organisational Measures (Art. 32 DSGVO)

As an IT security company, we protect personal data through state-of-the-art technical and organisational measures (Art. 32 DSGVO). These include in particular:

  • Transport encryption with TLS (including TLS 1.3) for all connections
  • Post-quantum-secure key agreement (PQC) for TLS connections via the Cloudflare edge
  • Encryption of data at rest in the Cloudflare services used (D1, R2, KV)
  • Cloudflare Web Application Firewall (WAF), DDoS protection and bot management
  • Access restrictions for the internal administration area and multi-factor authentication (MFA)
  • Role-based permissions following the least-privilege principle
  • Regular security updates and backups for recoverability
  • Monitoring, logging of security-relevant events and patch management

Further information about our security measures, certifications and the subcontractors we use can be found in our Trust Center (trustcenter.kaemi.website).

Your Rights as a Data Subject

With regard to the personal data concerning you, you have the following rights vis-à-vis us at any time:

  • Right of access (Art. 15 DSGVO)
  • Right to rectification or erasure (Art. 16, 17 DSGVO)
  • Right to restriction of processing (Art. 18 DSGVO)
  • Right to data portability (Art. 20 DSGVO)
  • Right to object to processing (Art. 21 DSGVO)
  • Right to withdraw consent once given, with effect for the future (Art. 7(3) DSGVO)

To exercise your rights you can contact us informally – by email to datenschutz@kaemi.email, by post to the address given in section 1, or via our request portal in the KAEMI Trust Center . We confirm receipt within one week and respond within one month at the latest. A copy of the relevant safeguards for third-country transfers, in particular the Standard Contractual Clauses, is available on request via the contact channels mentioned, including our Trust Center.

To protect your data, we may request proof of your identity in the case of an access request or other data subject request – but only to the extent necessary and where there are reasonable doubts about your identity.

Notice of your right to object (Art. 21 DSGVO): Insofar as we process personal data on the basis of our legitimate interests (Art. 6(1)(f) DSGVO), you have the right to object to this processing at any time on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. An informal request via our Trust Center is sufficient to exercise this right, as is an informal message by email or post. If your personal data is processed for the purpose of direct marketing, you additionally have the right to object to this processing at any time and without giving reasons; this also applies to profiling insofar as it is related to such direct marketing (Art. 21(2) and (3) DSGVO). After your objection we will no longer use your data for these purposes.

Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the DSGVO.

The authority responsible for KAEMI GmbH is the Berlin Commissioner for Data Protection and Freedom of Information:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61
10555 Berlin
https://www.datenschutz-berlin.de/

Embedded External Content

On individual pages of this website we embed external content whose providers receive data (in particular your IP address) when it is retrieved:

  • Cloudflare Stream (https://*.cloudflarestream.com) — delivery of the explainer videos on the home page and the SD-WAN page. Provider: Cloudflare, Inc. When a video is played, your IP address is transmitted to Cloudflare; technically necessary storage/cookie entries may be set for playback. Cloudflare Stream is not used for tracking or advertising.
  • Google Maps (https://maps.google.com) — map section on the contact page. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, USA). The map is not loaded automatically: you first see only our address and the button “Load map”. Only when you click it is the map embedded from Google; your IP address as well as browser and device information are then transmitted to Google, and Google may set its own cookies or access storage on your device. Without the click, no data flows to Google. Via the “Remove map” button on the map you can end the embedding at any time; the map is removed and the connection to Google is closed. Reloading the page also restores the placeholder.

For Cloudflare Stream the legal basis is our legitimate interest in an appealing and functional presentation of our content (Art. 6(1)(f) DSGVO); Cloudflare processes the data as our processor (see section 2) and the content is an integral part of the respective page. Google Maps, by contrast, is only loaded on your click; the legal basis is your consent (Art. 6(1)(a) DSGVO, § 25(1) TDDDG), which you give by clicking “Load map” and which applies to the respective page view. You can withdraw your consent at any time with effect for the future (Art. 7(3) DSGVO): click “Remove map” – the map is hidden and the connection to Google ends; alternatively, reload the page. We cannot delete cookies that Google set while the map was displayed; you can remove them via your browser settings. Insofar as data is transferred to Google LLC in the USA, this is safeguarded by its certification under the EU-US Data Privacy Framework (DPF). For further information, please refer to the privacy policies of the respective providers.

Appointment booking via Cal.com (loaded on click)

On our contact page you can book an appointment directly. The booking calendar is provided by Cal.com and is only loaded once you actively open one of the appointment types – until then no data is transferred to Cal.com. Alternatively you can use the direct link to cal.com in each tile.

Provider: Cal.com, Inc., 2093 Philadelphia Pike #1602, Claymont, DE 19703, USA.
Data processed: when the calendar is opened, your IP address as well as browser and device information are transmitted; Cal.com sets storage entries required to operate the booking dialogue. If you complete a booking, the details you enter (in particular name, email address, appointment time, time zone and any message) are processed in order to arrange and confirm the appointment.
Legal basis: Art. 6(1)(b) DSGVO (performance of pre-contractual measures at your request) and, for the technically necessary storage access when you open the calendar yourself, § 25 (2) no. 2 TDDDG – the calendar is loaded only after your explicit action, which is why no separate cookie consent is required.
Data processing: a data processing agreement pursuant to Art. 28 DSGVO is in place; the transfer to the USA is safeguarded by the EU Standard Contractual Clauses (Art. 46(2)(c) DSGVO).
Storage period: booking data for as long as necessary to arrange the appointment and to meet statutory retention obligations.

Links to External Websites and Social Media Profiles

Our website contains links to external websites, for example to technology partners, as well as to our company profiles on LinkedIn, Facebook and Instagram and to our ProvenExpert profile. We do not use social media plugins with automatic data transfer; the profiles are linked only. Only when you click such a link do you leave our website, and the privacy policy of the respective provider applies.

The respective provider is responsible for data processing on the linked platforms. For our company pages, the platform operators provide us with aggregated usage statistics (“Insights”); in this respect we are joint controllers with the respective provider pursuant to Art. 26 DSGVO. The essence of these arrangements: the platform operator bears primary responsibility for processing the Insights data, fulfils the information obligations under Art. 12 et seq. DSGVO and ensures data subject rights; we only receive aggregated statistics without personal reference. You can exercise your rights against both parties (Art. 26(3) DSGVO). The arrangements are available online: the LinkedIn Page Insights Joint Controller Addendum for our LinkedIn company page and the Meta Page Insights Controller Addendum for our Facebook page and Instagram account.

Optional Third-Party Services Subject to Your Consent

We only embed the following third-party services with your express consent. The legal basis is Art. 6(1)(a) DSGVO (consent). You can withdraw your consent at any time via “Cookie settings” in the page footer or in the cookie notice; the withdrawal takes effect for the future.

14.1 Visitor identification (sales) – Web Visitors (Leadfeeder via Pipedrive)

We use the “Web Visitors” feature of our CRM provider Pipedrive for B2B visitor analysis. It is technically operated by Leadfeeder (Dealfront): a tracking script uses the IP address to identify which companies have visited our website; visits from private (residential) IP ranges are filtered out automatically by the provider and not shown to us. This analysis is not intended to identify individual natural persons. We use the results to approach identified companies for sales purposes; for this reason we obtain a separate consent for it, independent of general statistics (category “Visitor identification (sales)”).

Provider and roles: our contracting party and processor is our CRM provider Pipedrive OÜ, Mustamäe tee 3a, 10615 Tallinn, Estonia (data processing agreement pursuant to Art. 28 DSGVO, see also 14.5). For Web Visitors, Pipedrive uses Dealfront Finland Oy (Finland; brand Leadfeeder, part of the Dealfront group) as a sub-processor. We are the controller.
Data processed: IP address, name/domain of the IP owner, browser and device information, pages visited, referrer/traffic source, time spent, the cookies and local storage entries listed below, and coarse geolocation derived from the IP address (country/region).
Analysis: Leadfeeder matches the IP address to the company from which the visit originates; the results are synced hourly to our Pipedrive account and shown there as visit histories at company level (identified company, pages visited, time, traffic source). Visits from private IP ranges are filtered out. We use the analysis to approach companies; individual persons are not identified.
Storage on your device (provider information): cookie “_lfa” (pseudonymous client identifier) 1 year; cookie “_lfa_consent” (consent status, if set) 2 years; “_lfa_test_cookie_stored” (check whether cookies can be stored) is deleted immediately; local storage entries “_lfa” and “_lfa_expiry” (client identifier and its expiry date) with an intended validity of 2 years. Unlike cookies, local storage does not expire by itself: the entries remain stored until the script renews them after expiry or we delete them.
Storage at the providers: the tracking script collects the data through Leadfeeder’s AWS infrastructure (encrypted in transit and at rest); according to Leadfeeder, processing takes place exclusively on servers within the European Union. The results then reside in our Pipedrive account, which Pipedrive hosts for EU customers, according to its own information, in the AWS region EU Frankfurt (Germany); for Pipedrive, the intra-group transfers to Pipedrive, Inc. (USA) described in 14.5 apply, based on the EU Standard Contractual Clauses and the EU-US Data Privacy Framework.
Deletion: we manually delete visit data older than twelve months every quarter in our Pipedrive account. In addition, according to the providers, the data is deleted as soon as it is no longer required for its purpose; removing the tracking script from our Pipedrive account deletes all visitor data, and when our Pipedrive contract ends the account contents are deleted in accordance with the data processing agreement (section 5.11, typically within 180 days; archive backups are typically retained for 90 days). The cookies expire after the periods stated; the local storage entries remain stored until the script renews them or we delete them (see above). If you withdraw your consent via “Cookie settings”, we immediately delete the Leadfeeder cookies and the local storage entries “_lfa” and “_lfa_expiry” on your device (implemented technically in the cookie banner) and no longer load the script.
Legal basis: Art. 6(1)(a) DSGVO (consent) and § 25 (1) TDDDG.
Withdrawal: via “Cookie settings” in the banner (disable the “Visitor identification (sales)” category).

14.2 Marketing – LinkedIn Insight Tag

We use the LinkedIn Insight Tag to measure the performance of our advertising campaigns on LinkedIn (conversion tracking and reach/website-demographics analysis) and to enable retargeting. It only runs after you consent to the “Marketing” category.

Provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (parent company: LinkedIn Corporation, 1000 W Maude Avenue, Sunnyvale, CA 94085, USA).
Data processed: IP address (shortened by LinkedIn), device and browser information, page URL and referrer, timestamp, and cookies: on our domain “li_fat_id” (30 days) and “ln_or” (1 day), on the linkedin.com domain among others “bcookie”/“bscookie” (1 year), “li_gc”/“li_mc” (6 months), “li_sugr”/“_guid” (90 days), “UserMatchHistory”, “AnalyticsSyncHistory”, “lms_ads”, “lms_analytics” (30 days) and “lidc” (24 hours) – lifetimes according to LinkedIn’s cookie table (https://www.linkedin.com/legal/l/cookie-table). If you are logged in to LinkedIn, LinkedIn may associate these events with your member account.
Storage period: according to LinkedIn, direct identifiers are removed within seven days and the remaining data is deleted within 180 days; cookie lifetimes between 1 day and 1 year (see above).
Legal basis: Art. 6(1)(a) DSGVO (consent) and § 25 (1) TDDDG.
Roles: we are the controller for the collection of the data on our website and its transmission to LinkedIn; LinkedIn processes the transmitted data for its own purposes (ad measurement, retargeting) as an independent controller. The contractual basis is the LinkedIn Independent Controller Addendum (https://www.linkedin.com/legal/l/linkedin-independent-controller-addendum); a joint-controller arrangement applies only to the Insights of our LinkedIn company page (see section 13). You can exercise your data subject rights against us and against LinkedIn.
Third-country transfer: data is transferred to LinkedIn Corporation in the USA on the basis of the EU Standard Contractual Clauses (Art. 46(2)(c) DSGVO); LinkedIn is additionally certified under the EU-US Data Privacy Framework (active status according to dataprivacyframework.gov).
Withdrawal: via “Cookie settings” in the banner (disable the “Marketing” category). LinkedIn members can additionally object to the use of their data for ads in their LinkedIn account settings.

14.3 Statistics – Cloudflare Zaraz (server-side embedding of Google Analytics 4)

We embed Google Analytics 4 via Cloudflare Zaraz, the tag-management service of Cloudflare, Inc. Zaraz runs on the Cloudflare network that also delivers this website: your browser does not load a Google script and does not connect to Google servers directly. Instead, the measurement data is sent to our own domain (/cdn-cgi/zaraz/) and forwarded to Google Analytics by Cloudflare on the server side. Zaraz is only loaded after you consent to the “Statistics” category; without your consent no Zaraz code runs and no data is collected.

Provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.
Data processed: IP address (processed transiently by Cloudflare to handle the request; Zaraz truncates IP addresses before passing anything to server-side loaded tools (“Trim IP addresses”) and does not forward yours to Google at all – see 14.4), page URL and title, referrer, browser and device information (e.g. screen size, language, time zone) as well as the pseudonymous client and session identifiers stored in the Zaraz cookies.
Cookies/storage: “cfz_google-analytics_v4” (12 months) and “cfzs_google-analytics_v4” (browser session), set as first-party cookies on kaemi.website (see section 4); no local storage entries.
Legal basis: Art. 6(1)(a) DSGVO (consent) and § 25 (1) TDDDG.
Data processing: Cloudflare acts as a processor; the data processing agreement including Standard Contractual Clauses (SCC) referred to in section 2 and the DPF certification mentioned there apply.
Withdrawal: via “Cookie settings” in the banner (disable the “Statistics” category) – Zaraz is then no longer loaded; cookies already set expire after 12 months at the latest or can be deleted in your browser.

14.4 Statistics – Google Analytics 4

We use Google Analytics 4 (measurement ID G-ZFYTXNPVED) to analyse how our website is used, so that we can improve our content and our offering. The service only runs after you consent to the “Statistics” category; without your consent Zaraz is not loaded and no data is transferred to Google. The embedding is server-side via Cloudflare Zaraz (see 14.3): your browser never communicates with Google directly.

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).
Data processed: pages visited and time spent, referrer/traffic source, device, browser and operating system information, interaction events and a pseudonymous client identifier. Your IP address is not forwarded to Google by Cloudflare Zaraz (“Hide Originating IP Address”); the approximate location in the reports is therefore derived only from the Cloudflare network node that handled your request (country/region level). Google Analytics 4 does not store IP addresses. Google Signals/audiences are disabled – no advertising or remarketing data is collected.
Cookies: no Google cookies are set on your device; the pseudonymous identifiers are stored in the Cloudflare Zaraz cookies described in 14.3 (“cfz_google-analytics_v4”, “cfzs_google-analytics_v4”).
Storage period: user and event data is retained in Google Analytics for 14 months and then deleted automatically. Renewed activity of the same pseudonymous user identifier restarts its retention period, so it may be stored longer for returning visitors; aggregated report data contains no personal identifiers.
Legal basis: Art. 6(1)(a) DSGVO (consent) and § 25 (1) TDDDG.
Data processing: a data processing agreement with Google Ireland Limited pursuant to Art. 28 DSGVO is in place; we have activated data minimisation settings (no advertising features unless separately consented).
Third-country transfer: data may be transferred to Google LLC in the USA on the basis of the EU Standard Contractual Clauses (Art. 46(2)(c) DSGVO); Google LLC is additionally certified under the EU-US Data Privacy Framework (active status according to dataprivacyframework.gov).
Withdrawal: via “Cookie settings” in the banner (disable the “Statistics” category); Zaraz is then no longer loaded and no further data is transmitted to Google.

14.5 Functional – Pipedrive LeadBooster Chat

We offer a live chat on our website via Pipedrive LeadBooster, which you can use to get in touch with our sales team directly.

Provider (contracting party for EU customers): Pipedrive OÜ, Mustamäe tee 3a, 10615 Tallinn, Estonia. Group-affiliated recipient in the USA: Pipedrive, Inc., 530 Fifth Avenue, 8th floor, Suite 802, New York, NY 10036, USA.
Data location (hosting): AWS region EU Frankfurt (Germany) according to Pipedrive – the registered office in Tallinn is not the hosting location; for intra-group access from the USA see third-country transfer.
Data processed: chat contents, contact details you provide voluntarily (e.g. name, email), session and storage data for chat control, browser and device information.
Cookies: “__cf_bm” (Cloudflare bot detection, 1 hour); additionally “_GRECAPTCHA” (Google reCAPTCHA, 179 days) if spam protection is active in LeadBooster.
Storage period: like completed contact enquiries (see section 5), we delete chat histories and the contact details provided in them no later than six months after the enquiry has been dealt with conclusively, unless a business relationship arises or statutory retention obligations apply. After termination of our Pipedrive contract, the provider deletes the account contents in accordance with the data processing agreement (section 5.11), typically within 180 days without a separate instruction; archive backups are typically retained for 90 days. Session cookies apply for the duration of the visit.
Legal basis: Art. 6(1)(a) DSGVO (consent).
Data processing: a data processing agreement (DPA) with Pipedrive OÜ pursuant to Art. 28 DSGVO is in place.
Third-country transfer: intra-group transfers to Pipedrive, Inc. in the USA are based on the EU Standard Contractual Clauses pursuant to Art. 46(2)(c) DSGVO. Pipedrive, Inc. is additionally certified under the EU-US Data Privacy Framework (active status according to dataprivacyframework.gov).
Classification as “Functional”: the chat serves solely to contact our sales team. No advertising is delivered and no retargeting takes place; the category “Functional” is therefore used instead of “Marketing”.
Withdrawal: via “Cookie settings” in the banner (disable the “Functional” category).

14.6 Functional – join.com (job and application widget)

On our careers page (/karriere/) we embed – only with your consent (category “Functional”) – the job and application widget provided by join.com. We use the widget to display open positions and to enable online applications.

Provider: JOIN Solutions AG, Eichenstrasse 2, 8808 Pfäffikon SZ, Switzerland (represented in the EU by JOIN Solutions GmbH, Schönhauser Allee 36, 10435 Berlin, registered in the commercial register of the Charlottenburg local court under HRB 201243 B).

Data processed: when the widget is loaded, your browser retrieves the widget script, the job list, language files and a font from join.com and cdn.join.com; in doing so, your IP address as well as browser and device information are transmitted to join.com. According to our review, the widget sets no cookies and no local storage entries on kaemi.website. If you click on a job, you are taken to join.com’s pages, where join.com’s privacy and cookie notices apply (https://join.com/privacy), including the cookie lifetimes stated there. If you apply, join.com processes the application data you enter (e.g. name, contact details, CV, cover letter, attachments).

Legal basis: Art. 6(1)(a) DSGVO (consent) for the transmission of your access data to join.com when the widget is loaded. For the processing of application data, Art. 88 DSGVO in conjunction with § 26 BDSG (German Federal Data Protection Act — employee data protection, initiation of an employment relationship) additionally applies.

Data processing: for applications received via the widget, join.com provides a data processing agreement (Art. 28 DSGVO); join.com processes this data exclusively as a processor acting on the instructions of KAEMI GmbH.

Third-country aspect: JOIN Solutions AG is based in Switzerland. An adequacy decision of the European Commission exists for Switzerland (Art. 45 DSGVO), so an adequate level of data protection is ensured.

Storage period: we process application data for the duration of the respective application procedure. In the event of a rejection, we generally store it for up to six months after the procedure has been completed in order to be able to handle any claims – in particular under the AGG (German General Equal Treatment Act); after that it is deleted, unless you have consented to longer storage (e.g. inclusion in a talent pool).

Withdrawal: via “Cookie settings” in the page footer (disable the “Functional” category).

ProvenExpert Rating Seal

On our website – in particular in the footer – we display a rating seal showing the overall score we have achieved on ProvenExpert. This seal is delivered exclusively from our own server. When you simply visit our pages, no data is transferred to ProvenExpert, no ProvenExpert scripts are loaded and no ProvenExpert cookies are set. Consent is therefore not required for displaying the seal.

The seal links to our public ProvenExpert profile. Only when you click the seal do you leave our website and are redirected to ProvenExpert. From that point on, the privacy policy of ProvenExpert applies. ProvenExpert is provided by Expert Systems AG, Quedlinburger Straße 1, 10589 Berlin, Germany. Its privacy policy is available at https://www.provenexpert.com/de-de/datenschutzbestimmungen/.

The legal basis for embedding the seal is our legitimate interest in the transparent presentation of independent customer reviews (Art. 6(1)(f) DSGVO).

Overview of Recipients

The following overview summarises the service providers and recipients of personal data we use (details in the respective sections):

ServicePurposeData location
Cloudflare, Inc.Hosting, CDN, security (incl. Turnstile bot protection), email deliveryDatabase and media: EU (EU jurisdiction); request processing: worldwide in the nearest data centre; log data: worldwide; registered office USA (SCC/DPF)
Pipedrive OÜ (registered office: Tallinn, Estonia)Live chat (LeadBooster)Hosting: AWS region EU Frankfurt (Germany) according to Pipedrive; intra-group access Pipedrive, Inc., USA (SCC/DPF)
Pipedrive OÜ (registered office: Tallinn, Estonia) – “Web Visitors” feature, operated by Dealfront Finland Oy (registered office: Finland; brand Leadfeeder) as sub-processorB2B visitor analysisHosting: collection on Leadfeeder’s AWS servers in the EU (according to the provider); analysis in the Pipedrive account, AWS region EU Frankfurt (Germany); intra-group access Pipedrive, Inc., USA (SCC/DPF)
LinkedIn Ireland Unlimited CompanyAd performance measurement & retargeting (Insight Tag)Ireland (EU) + USA (SCC/DPF)
Cloudflare, Inc. (Zaraz)Server-side embedding of Google Analytics 4 (tag management)EU/USA (SCC/DPF)
Google Ireland Limited (Google Analytics 4)Usage analysis (page views, sessions, traffic sources)Ireland (EU) + USA (SCC/DPF)
Cal.com, Inc.Appointment booking on the contact page (loaded on click)USA (SCC)
JOIN Solutions AGJob and application widgetSwitzerland (EU adequacy decision)
Google Ireland LimitedMap excerpt (Google Maps) on the contact page (loaded only on click), reCAPTCHA in the Pipedrive chatIreland (EU) + USA (Google LLC, SCC/DPF)

No Automated Decision-Making

No decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you (Art. 22 DSGVO) takes place.

Target Audience of This Website

This website is aimed exclusively at companies and their employees (B2B) and is not intended for minors. We do not knowingly process personal data of minors. We currently do not offer a newsletter.

Changes to This Privacy Policy

We reserve the right to amend this privacy policy in order to adapt it to a changed legal situation or to changes in our services. In the event of significant changes, the cookie notice will be displayed again so that you are informed about the current status.