This English version is provided for convenience. In case of any discrepancy, the German version is legally binding.
Privacy policy
Pentalink Consulting GmbH · Last updated: January 2025
1. Controller
The controller responsible for data processing on this website and in the course of our business activities is:
Pentalink Consulting GmbHKastanienweg 6a
18437 Stralsund
Commercial register: HRB 22928, Amtsgericht Stralsund
Managing Director: Sascha Lübow-Westendorf
Phone: +49 (0) 1515 745 2094
Email: info@pentalink.de
Website: https://pentalink.de
2. General information on data processing
2.1 Scope of processing
We process personal data of our users and business partners only insofar as this is necessary to provide our services, to fulfil contractual or legal obligations, or on the basis of your consent.
2.2 Legal bases
Personal data are processed on the basis of the EU General Data Protection Regulation (GDPR):
- Art. 6 (1)(a) GDPR: consent of the data subject
- Art. 6 (1)(b) GDPR: processing for the performance of a contract or in order to take steps prior to entering into a contract
- Art. 6 (1)(c) GDPR: processing for compliance with legal obligations
- Art. 6 (1)(f) GDPR: processing for the purposes of legitimate interests, unless such interests are overridden by the interests or fundamental rights of the data subject
2.3 Erasure of data and storage period
We store personal data only for as long as is necessary to fulfil the respective purpose or as statutory retention periods apply. Once the purpose no longer applies or the statutory periods have expired, the data are erased.
Statutory retention periods:
- Business letters, contracts: 6 years (§ 257 HGB, German Commercial Code)
- Accounting records, invoices: 10 years (§ 147 AO, German Fiscal Code)
3. Data processing on our website
3.1 Provision of the website and creation of log files
Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing device. The following data are collected:
- IP address of the user
- Date and time of access
- Pages and files accessed
- Amount of data transferred
- Notification of successful retrieval
- Browser type and version
- Operating system of the user
- Referrer URL (previously visited page)
Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in the provision and security of the website)
Storage period: The data are erased as soon as they are no longer required to achieve the purpose for which they were collected. As a rule, this is the case after 7 days.
3.2 Hosting
Our website is hosted by the following provider:
Railway CorporationSan Francisco, CA, USA
Railway processes, on our behalf, the data technically required to provide the website — in particular the server log files referred to in section 3.1 — on the basis of a data processing agreement (DPA) pursuant to Art. 28 GDPR. Further information can be found in Railway’s privacy policy: https://railway.com/legal/privacy
Transfer of data to third countries: Railway processes data in the USA. The transfer takes place on the basis of appropriate safeguards pursuant to Art. 46 GDPR (EU standard contractual clauses) or an adequacy decision (EU-US Data Privacy Framework).
3.3 Contact form and contact by email
Our website offers the possibility of contacting us via the contact form provided or by email. If you use the contact form or send us an email, the data you provide will be stored. Data processed:
- Name
- Email address
- Telephone number (optional)
- Content of the message
- Time of contact
Legal basis:
- Art. 6 (1)(a) GDPR where consent has been given
- Art. 6 (1)(b) GDPR for enquiries relating to the initiation of a contract
- Art. 6 (1)(f) GDPR for general enquiries (legitimate interest in communication)
Storage period: The data are erased as soon as they are no longer required to process your enquiry, but in any event not before the expiry of statutory retention periods.
3.4 Cookies
Our website uses cookies. Cookies are small text files that are stored on your device and contain certain information for exchange with our system. We use:
a) Strictly necessary cookies
These cookies are strictly required for the operation of the website.
Legal basis: Art. 6 (1)(f) GDPR (legitimate interest)
b) Analytics and marketing cookies
These cookies serve to measure reach, analyse user behaviour and improve our website, and are also used for marketing purposes.
Legal basis: Art. 6 (1)(a) GDPR (consent via the cookie banner)
Cookie management: You can adjust your cookie settings at any time via our cookie banner or block cookies in your browser settings. Please note that the functionality of the website may be limited if cookies are deactivated.
3.5 Website analytics and tracking (Google services)
For the purposes of reach measurement and the evaluation of our marketing measures, we use services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Without your consent given via our cookie banner, no cookies are set for analytics or marketing purposes and no data suitable for identifying you or your device are processed. Technically, the Google tags are loaded on every page, but by default they run in Google Consent Mode with storage deactivated (“denied”). In this state, only anonymised, cookieless signals (without an identifier of your device) may be transmitted to Google, which serve exclusively for aggregated, statistical measurements. Only after you have given your express consent via the cookie banner does Google set cookies and process data for the purposes set out below.
a) Google Analytics 4
We use Google Analytics 4 (measurement ID: G-Q9GSJ918FE) for the statistical analysis of the use of our website (e.g. pages accessed, length of visit, approximate origin). Cookies and similar technologies are used for this purpose; the usage data collected are generally processed in pseudonymised form.
b) Google Tag Manager
We use Google Tag Manager (container ID: GTM-KVTT6PFL) to manage and trigger tags (including analytics and conversion tags for advertising campaigns). The Tag Manager itself does not set any analytics cookies, but it controls the triggering of the aforementioned services depending on your consent.
Consent Mode v2: We have implemented Google Consent Mode v2. The choice you make via the cookie banner is transmitted to Google and determines whether Google may set cookies and process data for the purposes of analytics (analytics_storage) and advertising (ad_storage, ad_user_data, ad_personalization). Until consent is given, these purposes are set to “denied” by default.
Legal basis: Art. 6 (1)(a) GDPR (consent) and § 25 (1) TDDDG (storage of, or access to, information on the terminal equipment).
Transfer of data to third countries: When Google services are used, personal data may be transferred to Google LLC in the USA. The transfer takes place on the basis of the EU standard contractual clauses pursuant to Art. 46 GDPR and the EU-US Data Privacy Framework. Further information can be found in Google’s privacy policy: policies.google.com/privacy.
Storage period: The cookies set by Google Analytics have a limited lifetime (generally up to 24 months) and are then deleted automatically.
Withdrawal: You may withdraw any consent given at any time with effect for the future via the cookie banner; thereafter, no further data will be transmitted to Google.
3.6 Contact form and appointment booking (Fillout)
We use the Fillout service for our contact form and online appointment booking. The provider is Fillout, Inc., USA. When you complete the form or book an appointment, the data you enter are transmitted to Fillout and processed there on our behalf.
Legal basis: Art. 6 (1)(b) GDPR (initiation/performance of a contract) or Art. 6 (1)(a) GDPR (consent). Processing takes place on the basis of a data processing agreement (DPA) pursuant to Art. 28 GDPR.
Transfer of data to third countries: Fillout processes data in the USA; the transfer takes place on the basis of appropriate safeguards pursuant to Art. 46 GDPR or the EU-US Data Privacy Framework. Further information: fillout.com/legal/privacy-policy.
3.7 Fonts
To ensure a consistent display of fonts, this website uses locally hosted web fonts (Montserrat, Inter). The font files are delivered directly from our server; no connection to third-party servers (e.g. Google Fonts) is established and your IP address is not transmitted to third parties for this purpose.
Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in a consistent and appealing presentation of our offering).
4. Data processing in connection with our services
4.1 B2B contract processing
In the course of our business relationships with corporate customers, we process personal data for the initiation, performance and administration of contracts. Data processed:
- Company name, address
- Name and contact details of contact persons
- Billing information
- Contract data and service descriptions
- Email and project communication
- Technical access credentials (by agreement)
Legal basis: Art. 6 (1)(b) GDPR (performance of a contract) and Art. 6 (1)(c) GDPR (statutory retention obligations)
Storage period: Until the end of the business relationship and thereafter in accordance with statutory retention periods (see section 2.3).
4.2 Project data and system access
In the course of our consulting and development services, we are in some cases granted access to customer systems, data and infrastructure. Processing takes place exclusively on behalf of the customer and in accordance with the customer’s instructions.
Legal basis: Art. 6 (1)(b) GDPR (performance of a contract)
Processing on behalf of a controller: Where we process personal data on behalf of the customer, a separate data processing agreement (DPA) pursuant to Art. 28 GDPR is concluded.
4.3 Newsletter and marketing communications
We send newsletters and marketing emails only to recipients who have subscribed to them or with whom we already have a business relationship. Data processed:
- Email address
- Name (optional)
- Time of subscription
- IP address at the time of subscription (for evidentiary purposes)
Legal basis:
- Art. 6 (1)(a) GDPR (consent)
- Art. 6 (1)(f) GDPR in the case of existing customers (legitimate interest in direct marketing of our own products/services)
Unsubscribing: You can unsubscribe from the newsletter at any time via the unsubscribe link contained in every email or by sending a message to info@pentalink.de.
5. Data processing in web applications
We develop and operate web applications for B2B customers and, in some cases, for end users. Data processing in these applications depends on the respective purpose of use.
5.1 B2B applications
In the case of applications used exclusively by corporate customers, data processing takes place in the context of the performance of a contract or as processing on behalf of a controller.
Legal basis: Art. 6 (1)(b) GDPR (performance of a contract) or Art. 28 GDPR (processing on behalf of a controller)
5.2 End-user applications
Where we provide applications for end users, those users are informed by means of a separate, application-specific privacy policy, which is made available on first use or during registration.
Minimum age: Our services are not directed at minors under the age of 16. We do not knowingly process data of persons under the age of 16. Should we become aware that a minor has provided data, such data will be erased without undue delay.
6. Use of third-party providers and tools
6.1 Cloud services and software tools
To provide our services, we use various cloud services, project management tools, CRM systems and software solutions. These providers process data on our behalf on the basis of data processing agreements (DPAs) pursuant to Art. 28 GDPR. Typical categories of tools used:
- Cloud storage and hosting services
- Project management and collaboration tools
- CRM and marketing automation systems
- Development and analytics platforms
- Communication and email services
Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in efficient business operations) or Art. 6 (1)(b) GDPR (performance of a contract)
6.2 Subcontractors
In providing our services, we in some cases engage qualified subcontractors. They are contractually obliged to comply with data protection regulations.
Legal basis: Art. 6 (1)(b) GDPR (performance of a contract)
6.3 Transfer of data to third countries
Some of the service providers we use process data in countries outside the European Union (third countries). Such transfers take place only if:
- an adequacy decision of the EU Commission exists (e.g. for Switzerland), or
- EU standard contractual clauses pursuant to Art. 46 (2)(c) GDPR have been agreed, or
- other appropriate safeguards pursuant to Art. 46 GDPR are in place
7. AI-supported tools
In the course of our services, we use AI-supported tools to increase efficiency (e.g. for code generation, data analysis, documentation). They are used subject to professional review and responsibility.
When processing customer data by means of AI services, we take into account the nature and sensitivity of the data as well as applicable data protection regulations. Data requiring particular protection are processed only after consultation with the customer.
Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in efficient service provision) or Art. 6 (1)(b) GDPR (performance of a contract)
8. Your rights as a data subject
You have the following rights vis-à-vis us with regard to the personal data concerning you:
8.1 Right of access (Art. 15 GDPR)
You have the right to obtain information about the personal data processed by us.
8.2 Right to rectification (Art. 16 GDPR)
You have the right to request the rectification of inaccurate data or the completion of incomplete data.
8.3 Right to erasure (Art. 17 GDPR)
You have the right to request the erasure of your personal data, provided that the legal requirements are met and no statutory retention obligations preclude this.
8.4 Right to restriction of processing (Art. 18 GDPR)
You have the right to request the restriction of processing of your personal data where the legal requirements are met.
8.5 Right to data portability (Art. 20 GDPR)
You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format.
8.6 Right to object (Art. 21 GDPR)
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1)(f) GDPR (data processing on the basis of a balancing of interests).
Objection to direct marketing: Where your personal data are processed for the purposes of direct marketing, you have the right to object at any time. This also applies to profiling to the extent that it is related to such direct marketing.
8.7 Withdrawal of consent (Art. 7 (3) GDPR)
Where processing is based on your consent, you have the right to withdraw that consent at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
8.8 Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
You have the right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data. The competent supervisory authority for Mecklenburg-Western Pomerania is:
Der Landesbeauftragte für Datenschutz und Informationsfreiheit Mecklenburg-Vorpommern (State Commissioner for Data Protection and Freedom of Information of Mecklenburg-Western Pomerania)Werderstraße 74a
19055 Schwerin
Phone: 0385 59494-0
Email: info@datenschutz-mv.de
Website: https://www.datenschutz-mv.de
9. Data security
We use technical and organisational security measures to protect your data against accidental or intentional manipulation, loss or destruction and against access by unauthorised persons. Our security measures include, among others:
- Encrypted data transmission (SSL/TLS)
- Access restrictions and authorisation concepts
- Regular security updates
- Confidentiality obligations for employees and subcontractors
- Regular data backups
Our security measures are continuously improved in line with technological developments.
10. Changes to this privacy policy
We reserve the right to amend this privacy policy in order to adapt it to changes in the legal situation or in the event of changes to our services or to our data processing. The current version can always be found on our website.
This privacy policy was last updated: January 2025
11. Contact
If you have any questions about data protection or wish to exercise your rights, please contact:
Pentalink Consulting GmbHKastanienweg 6a
18437 Stralsund
Email: info@pentalink.de
Phone: +49 (0) 1515 745 2094 ← Back to home page