This is an English translation for convenience. The legally binding version is the German original.
1. General information and scope
1.1 Introduction
We are pleased about your visit to our website and thank you for your interest in HeroChat GmbH. The protection of your personal data is of particular importance to us. This Privacy Policy provides comprehensive information about the processing of personal data when using our online services, including our website, mobile applications, digital services and all associated functionalities.
1.2 Definitions
Personal data is all information relating to an identified or identifiable natural person. This includes in particular:
- Identification data (name, address, date of birth)
- Contact data (e-mail address, telephone number)
- Technical data (IP address, device identifiers)
- Usage data (visit times, pages accessed)
- Contract data (orders, payment information)
1.3 Scope
This Privacy Policy applies to:
- Our website www.herochat.de
- All subdomains and associated services
- Mobile applications of HeroChat
- Interactions via social media channels
- E-mail communication and newsletters
- All further digital touchpoints with HeroChat
1.4 Data security
We employ technical and organizational security measures in accordance with the state of the art in order to protect your data against unauthorized access, loss, destruction or alteration. Our security measures include:
- SSL/TLS encryption for all data transmissions
- Regular security audits and penetration tests
- Access controls and authorization concepts
- Encrypted data storage
- Regular backups and contingency plans
2. Controller and Data Protection Officer
2.1 Controller
HeroChat GmbH
Rykestraße 26
10405 Berlin
Germany
Commercial register: HRB 153798 B
Register court: Local Court of Berlin (Charlottenburg)
VAT ID: DE91358721
Represented by:
Christian Klöwer (Managing Director)
Contact details:
Telephone: +49 (0) 30 92 108 711
E-mail: info@herochat.de
Website: www.herochat.de
2.2 Data Protection Officer
You can reach our company Data Protection Officer at:
- E-mail: datenschutz@herochat.de
- By post: to the address stated above with the addition “Data Protection Officer”
3. Data collection when visiting the website
3.1 Automatic data collection
Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing computer. The following data is collected in this process:
Technical access data:
- IP address (anonymized by truncating the last octets)
- Date and time of access
- Time zone difference from Greenwich Mean Time (GMT)
- Content of the request (specific page)
- Access status/HTTP status code
- Volume of data transferred in each case
- Website from which the request originates (referrer)
- Browser identifier (user agent string)
- Operating system and its interface
- Language and version of the browser software
Extended log data:
- Time spent on individual pages
- Order of the pages accessed
- Search terms used in the internal search
- Download activities
- Interactions with embedded elements
3.2 Purposes of processing
The temporary storage of this data is necessary for:
- The technical provision of the website
- Ensuring system security
- Optimizing website performance
- Creating anonymized statistics
- Detecting and defending against cyberattacks
- Error diagnosis and remediation
3.3 Legal basis
The processing is carried out on the basis of our legitimate interest in a technically error-free and optimized provision of our services (Art. 6 (1) (f) GDPR).
3.4 Storage period
The data is stored for the duration of the respective session. IP addresses are anonymized immediately after collection. Log files are automatically deleted after an analysis and security period of no more than 7 days, unless security-relevant incidents require longer retention.
4. Contact and communication
4.1 Contact form
On our website we offer you the possibility to contact us via a form provided. The following data is collected in this process:
Mandatory information:
- First and last name
- E-mail address
- Subject of the inquiry
- Message text
Optional information:
- Telephone number for callbacks
- Company/organization
- Position within the company
- Preferred contact time
- Areas of interest
4.2 E-mail communication
When you contact us directly by e-mail, we process:
- Your e-mail address
- The time of the message
- The information contained in the e-mail
- Attachments and their metadata
4.3 Contact by telephone
When you contact us by telephone, we collect:
- Your telephone number
- Date and time of the call
- Call notes taken by our staff
- Agreed follow-up measures
4.4 Chat functions
Insofar as we offer chat functions, the following is collected:
- Chat history
- Timestamps of the messages
- Technical connection data
- Files transmitted, if any
4.5 Purposes of processing
The processing of your contact data is carried out for the following purposes:
- Handling your inquiries
- Provision of requested services
- Sending informational material
- Scheduling appointments
- Quality assurance and training
- Legal documentation
4.6 Legal bases
- Initiation or performance of a contract (Art. 6 (1) (b) GDPR)
- Legitimate interest in customer service (Art. 6 (1) (f) GDPR)
- Consent for optional information (Art. 6 (1) (a) GDPR)
4.7 Storage period
Contact inquiries are deleted after complete processing and expiry of any warranty periods:
- General inquiries: 6 months
- Contract-relevant communication: 10 years (statutory retention period)
- Support inquiries: 2 years after completion
5. Customer account and contract data
5.1 Registration and account management
To make full use of our services, you can create a personal customer account. As part of the registration and subsequent use, we process:
Basic data:
- First and last name
- E-mail address
Access data:
- Username
- Encrypted password
- Two-factor authentication (optional)
Company data (for business customers):
- Company name and legal form
- Commercial register number
- VAT ID
- Contact persons and their functions
- Industry and number of employees
5.2 Contract data
When contracts for our services are concluded, we collect:
Contract information:
- Subject matter and scope of the contract
- Contract term
- Notice periods
- Agreed conditions
- Supplementary agreements
Service data:
- Booked packages and options
- Usage statistics
- Consumption data
- Support inquiries and their handling
5.3 Payment data
For the processing of payments we process:
- Selected payment method
- Billing address
- For direct debit: IBAN and BIC
- For credit card: encrypted card data
- Payment history
- Dunning status
5.4 Profiling and customer segmentation
To improve our services, we may create customer profiles:
- Usage behavior and preferences
- Purchase history
- Areas of interest
- Communication preferences
- Customer satisfaction ratings
5.5 Data sources
In addition to the data collected directly from you, we may obtain information from the following sources:
- Public registers (e.g. the commercial register)
- Credit agencies (after prior notification)
- Social media profiles (where linked)
- Partner companies (with your consent)
6. Newsletter and direct marketing
6.1 Newsletter subscription
When you subscribe to our newsletter, we process:
Upon subscription:
- E-mail address
- Time of subscription
- IP address at subscription
- Confirmation of the double opt-in
- Preferred subject areas
When sending the newsletter:
- Open rates
- Click behavior
- Unsubscriptions
- Bounces and delivery errors
6.2 Personalization
We may personalize newsletters based on:
- Previous open and click behavior
- Purchased products or services
- Specified areas of interest
- Demographic characteristics
- Region
6.3 Marketing automation
As part of our marketing activities, we use automated systems:
- Welcome e-mail series
- Birthday greetings
- Reactivation campaigns
- Event-based messages
- Transactional e-mails
6.4 Advertising to existing customers
We inform existing customers about:
- New products and features
- Updates and improvements
- Special offers and discounts
- Events and webinars
- Industry news and trends
6.5 Right to object
You can object to receiving advertising at any time:
- Unsubscribe link in every e-mail
- E-mail to abmeldung@herochat.de
- Adjustment in your account settings
- By post to our business address
7. AI technologies and automated processing
7.1 Use of AI systems
HeroChat uses modern AI technologies to optimize our services:
Chatbot functionalities:
- Automated initial responses
- Categorization of inquiries
- Sentiment analysis
- Speech recognition and processing
- Multilingual support
Process optimization:
- Prediction of customer concerns
- Automatic ticket assignment
- Prioritization of inquiries
- Quality assurance of responses
7.2 Data usage for AI
For AI systems we use:
- Anonymized conversation histories
- Aggregated usage patterns
- Publicly available training data
- Synthetic data sets
We do NOT use:
- Personal customer data for general AI training
- Individual conversation content without anonymization
- Sensitive personal information
- Data from Google Workspace APIs for AI development
7.3 Automated decision-making
In certain areas we use automated procedures:
- Spam filtering
- Fraud detection
- Initial categorization of inquiries
- Risk assessment for payments
You have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you.
8. Cookies and tracking technologies
8.1 Detailed cookie information
Necessary cookies (essential cookies):
These cookies are essential for the basic functions of our website:
- Session cookie: Stores your session data during the visit
- Name: PHPSESSID
- Purpose: Session management
- Storage period: Until the browser is closed
- Load-balancing cookie: Ensures optimal server utilization
- Name: lb_cookie
- Purpose: Server optimization
- Storage period: 24 hours
- Security cookie: Protects against cross-site request forgery
- Name: csrf_token
- Purpose: Security
- Storage period: 2 hours
Functional cookies:
These cookies enable extended functions:
- Language settings: Stores your preferred language
- Name: lang_preference
- Purpose: Multilingualism
- Storage period: 1 year
- Layout settings: Remembers your display preferences
- Name: ui_settings
- Purpose: User experience
- Storage period: 6 months
Analytics cookies:
With your consent, we use the following analytics cookies:
- Google Analytics:
- _ga: Distinguishing users (2 years)
- _gid: Distinguishing users (24 hours)
- _gat: Throttling the request rate (1 minute)
- ga: Session status (2 years)
- Hotjar:
- hjSessionUser: User ID (365 days)
- hjSession: Session data (30 minutes)
- _hjFirstSeen: First contact (session)
Marketing cookies:
For personalized advertising we use:
- Google Ads:
- NID: User preferences (6 months)
- CONSENT: Cookie consent (20 years)
- 1P_JAR: Optimization (1 month)
- Facebook Pixel:
- _fbp: Facebook Browser ID (3 months)
- fr: Encrypted Facebook ID (3 months)
- tr: Conversion tracking (session)
- LinkedIn Insight Tag:
- bcookie: Browser ID (2 years)
- li_gc: Guest consent (2 years)
- lidc: Routing (24 hours)
8.2 Further tracking technologies
Local Storage:
- Storage of user settings
- Cache for frequently used data
- Offline functionalities
Session Storage:
- Temporary data storage
- Interim storage of form data
- Navigation states
Browser fingerprinting:
We do NOT use browser fingerprinting and reject this practice.
8.3 Cookie management
You can manage cookies in various ways:
Browser settings:
- Chrome: chrome://settings/cookies
- Firefox: about:preferences#privacy
- Safari: Settings > Privacy
- Edge: edge://settings/privacy
Cookie banner:
Via our cookie banner you can:
- Accept all cookies
- Allow only necessary cookies
- Make an individual selection
- Change settings at any time
Opt-out options:
- Google Analytics: https://tools.google.com/dlpage/gaoptout
- Facebook: https://www.facebook.com/ads/settings
- LinkedIn: https://www.linkedin.com/psettings/advertising
9. Social media and external services
9.1 Social media presences
LinkedIn:
- Company page: linkedin.com/company/herochat
- Responsibility: Jointly with LinkedIn Ireland
- Data processing: Insights, interactions, advertising
- Opt-out: linkedin.com/psettings/advertising
Twitter/X:
- Profile: twitter.com/herochat
- Responsibility: Jointly with Twitter International
- Data processing: Analytics, promoted tweets
- Privacy: twitter.com/privacy
Instagram:
- Account: instagram.com/herochat
- Responsibility: Jointly with Meta Platforms Ireland
- Data processing: Insights, stories interactions
- Settings: instagram.com/accounts/privacy_and_security
Facebook:
- Fan page: facebook.com/herochat
- Responsibility: Jointly with Meta Platforms Ireland
- Page Insights: Anonymized statistics
- Ads Manager: Audience building
9.2 Embedded content
YouTube videos:
- Enhanced privacy mode active
- No cookies before playback
- Data transfer only upon click
- Alternative: Local video embedding
Google Maps:
- Map integration for location display
- Lazy loading implemented
- Consent before activation
- Alternative: Static map images
Social media buttons:
- No active plugins
- Shariff solution implemented
- Privacy-friendly sharing
- No automatic data transfer
9.3 Content Delivery Networks (CDN)
For faster delivery we use:
- Cloudflare (data protection-compliant)
- Local fallback solutions
- Caching strategies
- Geoblocking for third countries
9.4 Dialogflow and Google
If you synchronize HeroChat with Dialogflow (https://dialogflow.com/) in order to use the Dialogflow bot, or use Google services such as language translations, we collect the following personal data: refresh token, e-mail address, image, language setting (locale) and profile picture.
By voluntarily providing this account information, you assure us that you are the owner of this personal data or are otherwise authorized to make it available to us. All service data is subject to our technical protective measures, as described in more detail in our Terms of Use.
When using Dialogflow with HeroChat, only the refresh token (an alphanumeric string) is transmitted to our server. No further data is either sent to our server or stored there.
If you do not wish to share or send any data to us, please contact us. We will then provide you with instructions with which you can configure HeroChat so that you can use your own Dialogflow integration.
By using Dialogflow, you also make personal data available to Dialogflow; further information can be found there. https://dialogflow.com/terms
10. International data transfer
10.1 Data transfer to third countries
When using certain services, data may be transferred to countries outside the EU/EEA:
US transfers:
- Basis: EU-US Data Privacy Framework
- Additionally: Standard Contractual Clauses
- Supplementary protective measures
- Risk assessment carried out
Further third countries:
- Adequacy decisions observed
- Standard Contractual Clauses concluded
- Binding Corporate Rules reviewed
- Exceptions only with consent
10.2 Protective measures
We implement additional protective measures:
- Encryption during transmission
- Pseudonymization where possible
- Access controls
- Contractual penalties for breaches
- Regular audits
11. Data security
11.1 Technical measures
- AES-256 encryption for data at rest
- TLS 1.3 for data in transit
- Web Application Firewall (WAF)
- DDoS protection
- Intrusion Detection System (IDS)
- Regular security updates
11.2 Organizational measures
- Commitment to data secrecy
- Regular employee training
- Clean desk policy
- Access controls
- Incident response plan
- Business continuity management
11.3 Data protection impact assessment
For high-risk processing operations, we carry out data protection impact assessments:
- Systematic description
- Risk assessment
- Remedial measures
- Consultation of the supervisory authority
12. Your rights as a data subject
12.1 Right of access (Art. 15 GDPR)
You can request confirmation from us as to whether and which personal data we process about you. You receive:
- A copy of your data
- The purposes of processing
- The categories of data
- Recipients or categories of recipients
- The envisaged storage period
- The origin of the data
- The existence of automated decision-making
Procedure:
- Request by e-mail or post
- Identity verification required
- Response within one month
- First copy free of charge
12.2 Right to rectification (Art. 16 GDPR)
You can request the rectification of inaccurate data or the completion of incomplete data:
- Immediate rectification
- Notification to recipients
- Confirmation of implementation
12.3 Right to erasure (Art. 17 GDPR)
You can request the erasure of your data if:
- The purpose no longer applies
- You withdraw your consent
- You object
- Data has been processed unlawfully
- A legal obligation to erase exists
Exceptions:
- Statutory retention obligations
- Legal claims
- Public interest
- Archiving purposes
12.4 Right to restriction (Art. 18 GDPR)
You can request restriction in the event of:
- Contesting the accuracy
- Unlawful processing
- No longer needed but retention desired
- Objection pending verification
12.5 Data portability (Art. 20 GDPR)
You have the right to:
- A structured, machine-readable format
- Transfer to another controller
- Direct transfer where possible
- Applies to automated processing
12.6 Right to object (Art. 21 GDPR)
General objection:
In the case of processing based on legitimate interests, you can object on personal grounds.
Objection to advertising:
You can object at any time to the use of your data for direct advertising. This also includes profiling for advertising purposes.
12.7 Automated decisions (Art. 22 GDPR)
You have the right not to be subject to solely automated decisions, except in the case of:
- Performance of a contract
- Statutory authorization
- Explicit consent
12.8 Withdrawal of consent
You can withdraw consent given at any time:
- Possible without any particular form
- Effect ex nunc
- Previous processing remains lawful
- By e-mail, post or in account settings
13. Protection of minors
13.1 Age restrictions
- Our services are directed at persons aged 16 and over
- Legal capacity required
- For minors: consent of the legal guardians
- Age verification at registration
13.2 Protective measures
- No targeted marketing to minors
- Particular care in data processing
- Erasure upon becoming aware of minority
- Information about data protection rights
14. Right to complain and enforcement of rights
14.1 Supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority:
Competent authority:
Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59-61
10555 Berlin
Telephone: +49 30 13889-0
Fax: +49 30 13889-201
E-mail: mailbox@datenschutz-berlin.de
Website: www.datenschutz-berlin.de
Alternative authorities:
You can also contact the supervisory authority of your place of residence or place of work.
14.2 Judicial remedy
In addition to lodging a complaint, the following legal remedies are available to you:
- Action against the supervisory authority
- Action against the controller
- Claims for damages
- Representation by data protection associations
15. Data protection in the context of job applications
15.1 Applicant data
For applications submitted via our careers portal, we process:
- Contact data
- Curriculum vitae
- Certificates and qualifications
- Cover letter
- References
- Salary expectations
15.2 Purposes of processing
- Assessment of suitability
- Communication during the application process
- Scheduling appointments
- Travel expense reimbursement
- Talent pool (with consent)
15.3 Erasure periods
- In the event of rejection: 6 months (AGG period)
- Talent pool: 2 years
- In the event of hiring: transfer to the personnel file
16. Changes to the Privacy Policy
16.1 Updates
This Privacy Policy is reviewed regularly and adapted as necessary:
- In the event of legislative changes
- In the event of new services or features
- In the event of changed processing operations
- Following notices from supervisory authorities
16.2 Notification of changes
We notify significant changes through:
- Notice on the website
- E-mail to registered users
- In-app notifications
- Renewed consent request where necessary
16.3 Versioning
- Current version: 2.0
- As of: January 2025
- Last change: Expansion of the cookie information
- Archive of previous versions available
17. Glossary and explanations of terms
Anonymization: Alteration of personal data in such a way that it can no longer be attributed to a person.
Data processing (on behalf of a controller): Processing of data by a service provider on behalf of the controller.
Legitimate interest: Justification for data processing where the interests of the controller prevail.
Cookie: Small text file stored on the end device when visiting a website.
Third country: A state outside the EU and the EEA.
Consent: A freely given, informed and unambiguous indication of wishes.
Personal data: All information relating to an identified or identifiable person.
Profiling: Automated processing to evaluate personal aspects.
Pseudonymization: Processing in which data can no longer be attributed without additional information.
Controller: The body that decides on the purposes and means of data processing.
18. Contact and further information
If you have any questions about data protection or the exercise of your rights, please contact us:
Data protection contact:
- E-mail: datenschutz@herochat.de
- Telephone: +49 30 92 108 711
- Post: HeroChat GmbH, Datenschutz, Rykestraße 26, 10405 Berlin
Response times:
- Simple inquiries: 3-5 working days
- Requests for access: max. 1 month
- Urgent cases: 24-48 hours
This Privacy Policy was last updated on 09 February 2026.