Skip to content
Book a call
🇩🇪 Deutsch 🇬🇧 English 🇫🇷 Français
Flagships
Perstat Uptime monitoring, incident management and status pages for teams who promise availability. NextPKI Find, renew and manage certificates, whoever issued them. Databurg Audit-proof compliance documentation for companies with reporting duties.
Trust & crypto
sqlclient A native database client for macOS. Local, with no detour via someone else's servers. FoldMail An email client with encryption that is meant seriously, S/MIME and OpenPGP. Claro An app for separated parents: handovers, arrangements and costs in one place.
Bundle of the month
Reliability Bundle

Perstat + NextPKI as a single billed package. NIS2 evidence and certificate lifecycle from one cockpit.

Learn more
Learn
Blog Release notes, compliance news, roadmap. Careers
Trust
Legal & privacy DPA, sub-processor list.
Bundle of the month
Reliability Bundle

Perstat + NextPKI as a single billed package. NIS2 evidence and certificate lifecycle from one cockpit.

Learn more
Products Perstat NextPKI Databurg sqlclient FoldMail Claro
Imprint
Language
🇩🇪 Deutsch 🇬🇧 English 🇫🇷 Français
Book a call
Skip to content
Legal

Privacy Policy

Information on the processing of personal data when visiting and using this website pursuant to Articles 13 and 14 GDPR.

1. Overview and scope

(1) This privacy policy informs you about how Datargo GmbH (hereinafter “Datargo”, “we” or “us”) processes personal data arising from the visit to and use of this website as well as the functions directly connected with it (such as making contact). It is addressed to all persons whose data is processed in this context (hereinafter “data subjects” or “you”).

(2) Personal data means any information relating to an identified or identifiable natural person (Art. 4 No. 1 GDPR). The relevant legal bases are in particular the General Data Protection Regulation (GDPR), the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG) and the Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, TDDDG).

(3) This privacy policy concerns exclusively the processing in connection with visiting the website. Separate provisions apply to the processing of personal data that you, as a business customer or its staff, enter into one of our products within the scope of its contractual use; see Section 11 in this regard.

2. Controller

(1) The controller within the meaning of Art. 4 No. 7 GDPR for the processing operations described in this policy is:

Datargo GmbH Omniturm, Neue Mainzer Straße 52-58, 60311 Frankfurt am Main Germany

Represented by its management.

Email: hello@datargo.com Data protection enquiries: hello@datargo.com

For further mandatory information (commercial register, VAT identification number, authorised representatives) please refer to the legal notice (Impressum) .

(2) This privacy policy concerns the website operated under the contact details set out above. For linked third-party offerings, the respective bodies named there are responsible (see Section 9).

3. Data protection officer

We have not appointed a data protection officer, as there is no statutory obligation to do so under Section 36 BDSG. Please direct any enquiries and concerns regarding data protection to privacy@datargo.com .

4. Principles of our data processing

(1) Processing in the EU. The personal data processed in connection with the visit to and use of this website is processed exclusively within the European Union; this website is hosted in Frankfurt am Main. An exception applies to payment processing in connection with the chargeable use of our services (see paragraph 3).

(2) No third-country transfer. A transfer of personal data to a third country (a state outside the EU or the EEA) or to an international organisation does not take place in connection with the visit to the website. Should such a transfer become necessary in the future, it will only take place under the conditions of Art. 44 et seq. GDPR (for example an adequacy decision or appropriate safeguards) and will be disclosed in this policy.

(3) Payment processing and data transfer to third countries. The infrastructure used to operate this website and the service providers deployed in this context are established in the European Union and are not subject to any obligation to surrender data under the US CLOUD Act. For the processing of payments in connection with the chargeable use of our services, we use the payment service provider Stripe (Stripe, LLC, USA); in this respect, Datargo GmbH acts as an independent controller. The associated transfer of personal data (in particular payment and invoicing data) to the USA is safeguarded by the EU-US Data Privacy Framework (adequacy decision of the European Commission pursuant to Art. 45 GDPR); in addition, Standard Contractual Clauses pursuant to Implementing Decision (EU) 2021/914 are in place. Stripe, LLC is certified under the EU-US Data Privacy Framework. The legal basis for payment processing is Art. 6 (1) lit. b GDPR (performance of the contract).

(4) Data minimisation and purpose limitation. We collect and process personal data only insofar as this is necessary to achieve the respective purpose, and we delete it as soon as the purpose ceases to apply and no statutory retention obligations preclude deletion (see Section 8).

(5) Data security. We take appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect the data processed by us against loss, manipulation and unauthorised access. This website is delivered via an encrypted connection (TLS); you can recognise an existing encryption by the address bar of your browser. Our security measures are continuously adapted in line with technical developments.

5. Processing when visiting the website (server logs and hosting)

(1) Description and data categories. When this website is accessed, your end device automatically transmits data to the server for technical reasons, which is temporarily stored in a log file (server log file). The following is recorded in particular:

Data categoryExample
IP address of the requesting end device(shortened or anonymised, insofar as sufficient for the purpose)
Date and time of accesstimestamp of the request
Accessed resourceURL, file name, volume of data transferred
Status messageHTTP status code (e.g. success or error)
Referrerpreviously visited page, if transmitted
Browser and system informationbrowser type, version, operating system

(2) Purpose. The processing serves the technical delivery of the website, ensuring stable and secure operation, detecting and averting attacks and misuse, and investigating and tracing security incidents.

(3) Legal basis. Art. 6 (1) lit. f GDPR. Our legitimate interest lies in the secure, stable and functional provision of this website.

(4) Recipients / processors. A hosting service provider is engaged with operating the infrastructure as a processor pursuant to Art. 28 GDPR within the EU (Frankfurt am Main).

(5) Storage period. The log data is stored for a period of a maximum of 7 days, in justified security cases up to 90 days, and is subsequently deleted. Individual records are stored for a longer period only insofar as this is necessary to investigate a specific security incident; in this case, the affected data is exempt from the regular deletion until the matter has been conclusively clarified.

(6) This data is not combined with other data sources for the purpose of identifying individual persons.

6. Making contact (form and email)

(1) Description. If you contact us via a contact form, by email or via the “Arrange a conversation” function, we process the information you transmit in order to handle and respond to your enquiry and for any follow-up questions.

(2) Data categories. We process in particular your name, your contact details (e.g. email address, telephone number, company), the content of your message and any further information you provide voluntarily. Mandatory information is marked as such; without it we may not be able to process your enquiry, or not in full.

(3) Purpose and legal basis.

ConstellationLegal basis
Enquiry aimed at initiating or performing a contract (e.g. pilot, offer, demo)Art. 6 (1) lit. b GDPR (pre-contractual measures)
General enquiry without direct contractual relationArt. 6 (1) lit. f GDPR (legitimate interest in handling enquiries)

(4) Recipients / processors. As a rule, data is only passed on to the internally responsible bodies for processing. Insofar as an email or CRM service provider is engaged as a processor, this takes place exclusively within the EU.

(5) Bot protection. Before submission, we use a computational task solved locally in your browser to check that the submission is not automated. Details and legal basis: Section 7 paragraph 5.

(6) Storage period. We store your information until your enquiry has been conclusively processed and there is no longer any reason for further retention. You may object to further storage or request deletion at any time, insofar as no statutory retention obligations preclude this. Enquiries of relevance under commercial or tax law are stored within the scope of the statutory retention periods (see Section 8).

7. Cookies, local storage and bot protection

(1) Use. We use exclusively technically necessary cookies and comparable technologies (such as local storage in the browser). No consent is required for these under section 25(2) no. 2 TDDDG.

(2) Purposes. We store only what is required to operate the website, in particular your choice of language version and display mode (light or dark) as well as security-related information. The legal basis for the processing is Art. 6(1)(f) GDPR.

(3) No tracking or marketing cookies. No cookies or comparable technologies are set for analytics, tracking or advertising purposes. No third-party services are embedded on this website.

(4) Management via your browser. You can prevent cookies from being stored in your browser settings or delete cookies already stored; the full functionality of the website may be limited as a result.

(5) Protection against automated submissions (bot check). Forms on this website, as well as the registration and sign-in forms of our product interfaces, are protected against automated abuse. To this end, our server issues your browser a computational task (a “proof of work”) which your browser solves locally; only the result of that computation is transmitted to us together with the form.

  • Triggered only by your use. The computation starts only once you actually use the form (first keystroke or submission), not when the page is loaded.
  • No access to your device. No information is stored on your terminal equipment and no information stored there is read. Only your device’s computing power is used, typically for a fraction of a second.
  • No third-party service. The check runs entirely on our own infrastructure. No captcha or bot-protection provider is embedded; in particular, no IP address is transmitted to third parties.

Insofar as this constitutes access within the meaning of section 25 TDDDG at all, it does not require consent under section 25(2) no. 2 TDDDG, because it is strictly necessary in order to provide the use of the form that you have expressly requested. The legal basis for the processing is Art. 6(1)(f) GDPR; our legitimate interest lies in preventing automated bulk submissions, in particular the mass triggering of emails to third-party addresses.

8. Storage period and deletion (general)

(1) Unless an express storage period is stated in this privacy policy, personal data is deleted as soon as the purpose of its processing ceases to apply and no statutory retention obligations preclude deletion.

(2) Statutory retention obligations arise in particular from the German Commercial Code (Section 255 HGB) and the German Fiscal Code (Section 145 AO) and amount to up to ten years depending on the type of document. During the running of such periods, the processing of the affected data is restricted.

9. External links

This website may contain links to external third-party websites. We have no influence over their content and data processing; the respective provider there is responsible for these. The data protection notices of the respective linked website apply.

10. Your rights as a data subject

You have the following rights vis-a-vis Datargo with regard to the personal data concerning you:

(1) Right of access (Art. 15 GDPR). You have the right to obtain confirmation as to whether we process data concerning you, as well as to obtain information about this data and the information referred to in Art. 15 GDPR (such as purposes, categories, recipients, storage period) and a copy of the data.

(2) Rectification (Art. 16 GDPR). You have the right to request the rectification of inaccurate data as well as the completion of incomplete data concerning you.

(3) Erasure (Art. 17 GDPR). You have the right to request the erasure of data concerning you, provided that one of the grounds referred to in Art. 17 GDPR applies and no statutory retention obligations preclude it.

(4) Restriction of processing (Art. 18 GDPR). You have the right, under the conditions of Art. 18 GDPR, to request the restriction of the processing of data concerning you.

(5) Data portability (Art. 20 GDPR). Insofar as the processing is based on consent or contract and is carried out by automated means, you have the right to receive the data concerning you in a structured, commonly used and machine-readable format or to request its transmission to another controller, where technically feasible.

(6) Objection (Art. 21 GDPR). You have the right, on grounds relating to your particular situation, to object at any time to processing of data concerning you that is based on Art. 6 (1) lit. f GDPR. We will then no longer process the data, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

(7) Withdrawal of consent given (Art. 7 (3) GDPR). You have the right to withdraw a consent given at any time with effect for the future. The lawfulness of the processing carried out up to the withdrawal remains unaffected.

(8) Exercising your rights. To exercise your rights, an informal notice to the contact details named under Section 2 (or Section 3) is sufficient. The exercise of your rights is, as a rule, free of charge for you.

11. Note on product use

(1) Insofar as Datargo processes personal data within the scope of the contractual provision of one of its products on behalf of and in accordance with the instructions of a business customer, that business customer is the controller and Datargo is the processor within the meaning of Art. 28 GDPR.

(2) The details, including the data processing agreement and the sub-processors engaged, are governed by the terms of the respective product. They are published on that product’s own website.

12. Obligation to provide data

The provision of personal data is not required by law or contract in the context of merely visiting the website. When making contact, however, the provision of the information marked as required in each case is necessary in order to process your enquiry or to initiate a contract. Without this information, we may not be able to provide the relevant service.

13. No automated decision-making

Automated decision-making in individual cases, including profiling within the meaning of Art. 22 (1) and (4) GDPR, does not take place in the context of visiting the website.

14. Right to lodge a complaint with a supervisory authority

(1) Without prejudice to any other administrative or judicial remedy, you have the right under Art. 77 GDPR to lodge a complaint with a supervisory authority, in particular in the Member State of your place of residence, your place of work or the place of the alleged infringement, if you consider that the processing of data concerning you infringes the GDPR.

(2) The supervisory authority responsible for Datargo is:

The Hesse Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, HBDI) Postal address: Postfach 31 63, 65021 Wiesbaden Street address: Gustav-Stresemann-Ring 1, 65189 Wiesbaden Telephone: +49 611 1408-0 Email: poststelle@datenschutz.hessen.de Website: datenschutz.hessen.de

Datargo GmbH is established in Hesse (registering court: Friedberg Local Court / Amtsgericht Friedberg); the competent supervisory authority is therefore the aforementioned Hesse Commissioner for Data Protection and Freedom of Information.

15. Changes to this privacy policy

We adapt this privacy policy as soon as changes to the data processing operations we carry out or to the legal framework make this necessary. The current version published on this website applies in each case.

Last updated: July 2026.

Authoritative language version

This document is provided in German, English and French. The English and French versions are translations provided solely for convenience. The German version is authoritative and solely binding in the event of any dispute or any difference of interpretation or translation.

Datargo Datargo

Datargo GmbH, Frankfurt am Main. We build and operate our own software products on our own infrastructure in the European Union.

EU hosting, Frankfurt GDPR-native Made in Germany
Products
  • Perstat
  • NextPKI
  • Databurg
  • sqlclient
  • FoldMail
  • Claro
Company
  • Contact
  • Careers
  • Blog
  • Status page
Legal
  • Imprint
  • Privacy
© 2026 Datargo GmbH. All rights reserved.
Germany · English

Datargo® and Databurg® are registered trademarks of Datargo GmbH. All other product names, logos, and trademarks mentioned are the property of their respective owners.