This is an English translation for convenience. The legally binding version is the German original.

1. General information and scope

1.1 Introduction

We are pleased about your visit to our website and thank you for your interest in HeroChat GmbH. The protection of your personal data is of particular importance to us. This Privacy Policy provides comprehensive information about the processing of personal data when using our online services, including our website, mobile applications, digital services and all associated functionalities.

1.2 Definitions

Personal data is all information relating to an identified or identifiable natural person. This includes in particular:

  • Identification data (name, address, date of birth)
  • Contact data (e-mail address, telephone number)
  • Technical data (IP address, device identifiers)
  • Usage data (visit times, pages accessed)
  • Contract data (orders, payment information)

1.3 Scope

This Privacy Policy applies to:

  • Our website www.herochat.de
  • All subdomains and associated services
  • Mobile applications of HeroChat
  • Interactions via social media channels
  • E-mail communication and newsletters
  • All further digital touchpoints with HeroChat

1.4 Data security

We employ technical and organizational security measures in accordance with the state of the art in order to protect your data against unauthorized access, loss, destruction or alteration. Our security measures include:

  • SSL/TLS encryption for all data transmissions
  • Regular security audits and penetration tests
  • Access controls and authorization concepts
  • Encrypted data storage
  • Regular backups and contingency plans

2. Controller and Data Protection Officer

2.1 Controller

HeroChat GmbH
Rykestraße 26
10405 Berlin
Germany

Commercial register: HRB 153798 B
Register court: Local Court of Berlin (Charlottenburg)
VAT ID: DE91358721

Represented by:
Christian Klöwer (Managing Director)

Contact details:
Telephone: +49 (0) 30 92 108 711
E-mail: info@herochat.de
Website: www.herochat.de

2.2 Data Protection Officer

You can reach our company Data Protection Officer at:

  • E-mail: datenschutz@herochat.de
  • By post: to the address stated above with the addition “Data Protection Officer”

3. Data collection when visiting the website

3.1 Automatic data collection

Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing computer. The following data is collected in this process:

Technical access data:

  • IP address (anonymized by truncating the last octets)
  • Date and time of access
  • Time zone difference from Greenwich Mean Time (GMT)
  • Content of the request (specific page)
  • Access status/HTTP status code
  • Volume of data transferred in each case
  • Website from which the request originates (referrer)
  • Browser identifier (user agent string)
  • Operating system and its interface
  • Language and version of the browser software

Extended log data:

  • Time spent on individual pages
  • Order of the pages accessed
  • Search terms used in the internal search
  • Download activities
  • Interactions with embedded elements

3.2 Purposes of processing

The temporary storage of this data is necessary for:

  • The technical provision of the website
  • Ensuring system security
  • Optimizing website performance
  • Creating anonymized statistics
  • Detecting and defending against cyberattacks
  • Error diagnosis and remediation

3.3 Legal basis

The processing is carried out on the basis of our legitimate interest in a technically error-free and optimized provision of our services (Art. 6 (1) (f) GDPR).

3.4 Storage period

The data is stored for the duration of the respective session. IP addresses are anonymized immediately after collection. Log files are automatically deleted after an analysis and security period of no more than 7 days, unless security-relevant incidents require longer retention.

4. Contact and communication

4.1 Contact form

On our website we offer you the possibility to contact us via a form provided. The following data is collected in this process:

Mandatory information:

  • First and last name
  • E-mail address
  • Subject of the inquiry
  • Message text

Optional information:

  • Telephone number for callbacks
  • Company/organization
  • Position within the company
  • Preferred contact time
  • Areas of interest

4.2 E-mail communication

When you contact us directly by e-mail, we process:

  • Your e-mail address
  • The time of the message
  • The information contained in the e-mail
  • Attachments and their metadata

4.3 Contact by telephone

When you contact us by telephone, we collect:

  • Your telephone number
  • Date and time of the call
  • Call notes taken by our staff
  • Agreed follow-up measures

4.4 Chat functions

Insofar as we offer chat functions, the following is collected:

  • Chat history
  • Timestamps of the messages
  • Technical connection data
  • Files transmitted, if any

4.5 Purposes of processing

The processing of your contact data is carried out for the following purposes:

  • Handling your inquiries
  • Provision of requested services
  • Sending informational material
  • Scheduling appointments
  • Quality assurance and training
  • Legal documentation

4.6 Legal bases

  • Initiation or performance of a contract (Art. 6 (1) (b) GDPR)
  • Legitimate interest in customer service (Art. 6 (1) (f) GDPR)
  • Consent for optional information (Art. 6 (1) (a) GDPR)

4.7 Storage period

Contact inquiries are deleted after complete processing and expiry of any warranty periods:

  • General inquiries: 6 months
  • Contract-relevant communication: 10 years (statutory retention period)
  • Support inquiries: 2 years after completion

5. Customer account and contract data

5.1 Registration and account management

To make full use of our services, you can create a personal customer account. As part of the registration and subsequent use, we process:

Basic data:

  • First and last name
  • E-mail address

Access data:

  • Username
  • Encrypted password
  • Two-factor authentication (optional)

Company data (for business customers):

  • Company name and legal form
  • Commercial register number
  • VAT ID
  • Contact persons and their functions
  • Industry and number of employees

5.2 Contract data

When contracts for our services are concluded, we collect:

Contract information:

  • Subject matter and scope of the contract
  • Contract term
  • Notice periods
  • Agreed conditions
  • Supplementary agreements

Service data:

  • Booked packages and options
  • Usage statistics
  • Consumption data
  • Support inquiries and their handling

5.3 Payment data

For the processing of payments we process:

  • Selected payment method
  • Billing address
  • For direct debit: IBAN and BIC
  • For credit card: encrypted card data
  • Payment history
  • Dunning status

5.4 Profiling and customer segmentation

To improve our services, we may create customer profiles:

  • Usage behavior and preferences
  • Purchase history
  • Areas of interest
  • Communication preferences
  • Customer satisfaction ratings

5.5 Data sources

In addition to the data collected directly from you, we may obtain information from the following sources:

  • Public registers (e.g. the commercial register)
  • Credit agencies (after prior notification)
  • Social media profiles (where linked)
  • Partner companies (with your consent)

6. Newsletter and direct marketing

6.1 Newsletter subscription

When you subscribe to our newsletter, we process:

Upon subscription:

  • E-mail address
  • Time of subscription
  • IP address at subscription
  • Confirmation of the double opt-in
  • Preferred subject areas

When sending the newsletter:

  • Open rates
  • Click behavior
  • Unsubscriptions
  • Bounces and delivery errors

6.2 Personalization

We may personalize newsletters based on:

  • Previous open and click behavior
  • Purchased products or services
  • Specified areas of interest
  • Demographic characteristics
  • Region

6.3 Marketing automation

As part of our marketing activities, we use automated systems:

  • Welcome e-mail series
  • Birthday greetings
  • Reactivation campaigns
  • Event-based messages
  • Transactional e-mails

6.4 Advertising to existing customers

We inform existing customers about:

  • New products and features
  • Updates and improvements
  • Special offers and discounts
  • Events and webinars
  • Industry news and trends

6.5 Right to object

You can object to receiving advertising at any time:

  • Unsubscribe link in every e-mail
  • E-mail to abmeldung@herochat.de
  • Adjustment in your account settings
  • By post to our business address

7. AI technologies and automated processing

7.1 Use of AI systems

HeroChat uses modern AI technologies to optimize our services:

Chatbot functionalities:

  • Automated initial responses
  • Categorization of inquiries
  • Sentiment analysis
  • Speech recognition and processing
  • Multilingual support

Process optimization:

  • Prediction of customer concerns
  • Automatic ticket assignment
  • Prioritization of inquiries
  • Quality assurance of responses

7.2 Data usage for AI

For AI systems we use:

  • Anonymized conversation histories
  • Aggregated usage patterns
  • Publicly available training data
  • Synthetic data sets

We do NOT use:

  • Personal customer data for general AI training
  • Individual conversation content without anonymization
  • Sensitive personal information
  • Data from Google Workspace APIs for AI development

7.3 Automated decision-making

In certain areas we use automated procedures:

  • Spam filtering
  • Fraud detection
  • Initial categorization of inquiries
  • Risk assessment for payments

You have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you.

8. Cookies and tracking technologies

8.1 Detailed cookie information

Necessary cookies (essential cookies):
These cookies are essential for the basic functions of our website:

  • Session cookie: Stores your session data during the visit
    • Name: PHPSESSID
    • Purpose: Session management
    • Storage period: Until the browser is closed
  • Load-balancing cookie: Ensures optimal server utilization
    • Name: lb_cookie
    • Purpose: Server optimization
    • Storage period: 24 hours
  • Security cookie: Protects against cross-site request forgery
    • Name: csrf_token
    • Purpose: Security
    • Storage period: 2 hours

Functional cookies:
These cookies enable extended functions:

  • Language settings: Stores your preferred language
    • Name: lang_preference
    • Purpose: Multilingualism
    • Storage period: 1 year
  • Layout settings: Remembers your display preferences
    • Name: ui_settings
    • Purpose: User experience
    • Storage period: 6 months

Analytics cookies:
With your consent, we use the following analytics cookies:

  • Google Analytics:
    • _ga: Distinguishing users (2 years)
    • _gid: Distinguishing users (24 hours)
    • _gat: Throttling the request rate (1 minute)
    • ga: Session status (2 years)
  • Hotjar:
    • hjSessionUser: User ID (365 days)
    • hjSession: Session data (30 minutes)
    • _hjFirstSeen: First contact (session)

Marketing cookies:
For personalized advertising we use:

  • Google Ads:
    • NID: User preferences (6 months)
    • CONSENT: Cookie consent (20 years)
    • 1P_JAR: Optimization (1 month)
  • Facebook Pixel:
    • _fbp: Facebook Browser ID (3 months)
    • fr: Encrypted Facebook ID (3 months)
    • tr: Conversion tracking (session)
  • LinkedIn Insight Tag:
    • bcookie: Browser ID (2 years)
    • li_gc: Guest consent (2 years)
    • lidc: Routing (24 hours)

8.2 Further tracking technologies

Local Storage:

  • Storage of user settings
  • Cache for frequently used data
  • Offline functionalities

Session Storage:

  • Temporary data storage
  • Interim storage of form data
  • Navigation states

Browser fingerprinting:
We do NOT use browser fingerprinting and reject this practice.

8.3 Cookie management

You can manage cookies in various ways:

Browser settings:

  • Chrome: chrome://settings/cookies
  • Firefox: about:preferences#privacy
  • Safari: Settings > Privacy
  • Edge: edge://settings/privacy

Cookie banner:
Via our cookie banner you can:

  • Accept all cookies
  • Allow only necessary cookies
  • Make an individual selection
  • Change settings at any time

Opt-out options:

9. Social media and external services

9.1 Social media presences

LinkedIn:

  • Company page: linkedin.com/company/herochat
  • Responsibility: Jointly with LinkedIn Ireland
  • Data processing: Insights, interactions, advertising
  • Opt-out: linkedin.com/psettings/advertising

Twitter/X:

  • Profile: twitter.com/herochat
  • Responsibility: Jointly with Twitter International
  • Data processing: Analytics, promoted tweets
  • Privacy: twitter.com/privacy

Instagram:

  • Account: instagram.com/herochat
  • Responsibility: Jointly with Meta Platforms Ireland
  • Data processing: Insights, stories interactions
  • Settings: instagram.com/accounts/privacy_and_security

Facebook:

  • Fan page: facebook.com/herochat
  • Responsibility: Jointly with Meta Platforms Ireland
  • Page Insights: Anonymized statistics
  • Ads Manager: Audience building

9.2 Embedded content

YouTube videos:

  • Enhanced privacy mode active
  • No cookies before playback
  • Data transfer only upon click
  • Alternative: Local video embedding

Google Maps:

  • Map integration for location display
  • Lazy loading implemented
  • Consent before activation
  • Alternative: Static map images

Social media buttons:

  • No active plugins
  • Shariff solution implemented
  • Privacy-friendly sharing
  • No automatic data transfer

9.3 Content Delivery Networks (CDN)

For faster delivery we use:

  • Cloudflare (data protection-compliant)
  • Local fallback solutions
  • Caching strategies
  • Geoblocking for third countries

9.4 Dialogflow and Google

If you synchronize HeroChat with Dialogflow (https://dialogflow.com/) in order to use the Dialogflow bot, or use Google services such as language translations, we collect the following personal data: refresh token, e-mail address, image, language setting (locale) and profile picture.

By voluntarily providing this account information, you assure us that you are the owner of this personal data or are otherwise authorized to make it available to us. All service data is subject to our technical protective measures, as described in more detail in our Terms of Use.

When using Dialogflow with HeroChat, only the refresh token (an alphanumeric string) is transmitted to our server. No further data is either sent to our server or stored there.

If you do not wish to share or send any data to us, please contact us. We will then provide you with instructions with which you can configure HeroChat so that you can use your own Dialogflow integration.

By using Dialogflow, you also make personal data available to Dialogflow; further information can be found there. https://dialogflow.com/terms

10. International data transfer

10.1 Data transfer to third countries

When using certain services, data may be transferred to countries outside the EU/EEA:

US transfers:

  • Basis: EU-US Data Privacy Framework
  • Additionally: Standard Contractual Clauses
  • Supplementary protective measures
  • Risk assessment carried out

Further third countries:

  • Adequacy decisions observed
  • Standard Contractual Clauses concluded
  • Binding Corporate Rules reviewed
  • Exceptions only with consent

10.2 Protective measures

We implement additional protective measures:

  • Encryption during transmission
  • Pseudonymization where possible
  • Access controls
  • Contractual penalties for breaches
  • Regular audits

11. Data security

11.1 Technical measures

  • AES-256 encryption for data at rest
  • TLS 1.3 for data in transit
  • Web Application Firewall (WAF)
  • DDoS protection
  • Intrusion Detection System (IDS)
  • Regular security updates

11.2 Organizational measures

  • Commitment to data secrecy
  • Regular employee training
  • Clean desk policy
  • Access controls
  • Incident response plan
  • Business continuity management

11.3 Data protection impact assessment

For high-risk processing operations, we carry out data protection impact assessments:

  • Systematic description
  • Risk assessment
  • Remedial measures
  • Consultation of the supervisory authority

12. Your rights as a data subject

12.1 Right of access (Art. 15 GDPR)

You can request confirmation from us as to whether and which personal data we process about you. You receive:

  • A copy of your data
  • The purposes of processing
  • The categories of data
  • Recipients or categories of recipients
  • The envisaged storage period
  • The origin of the data
  • The existence of automated decision-making

Procedure:

  • Request by e-mail or post
  • Identity verification required
  • Response within one month
  • First copy free of charge

12.2 Right to rectification (Art. 16 GDPR)

You can request the rectification of inaccurate data or the completion of incomplete data:

  • Immediate rectification
  • Notification to recipients
  • Confirmation of implementation

12.3 Right to erasure (Art. 17 GDPR)

You can request the erasure of your data if:

  • The purpose no longer applies
  • You withdraw your consent
  • You object
  • Data has been processed unlawfully
  • A legal obligation to erase exists

Exceptions:

  • Statutory retention obligations
  • Legal claims
  • Public interest
  • Archiving purposes

12.4 Right to restriction (Art. 18 GDPR)

You can request restriction in the event of:

  • Contesting the accuracy
  • Unlawful processing
  • No longer needed but retention desired
  • Objection pending verification

12.5 Data portability (Art. 20 GDPR)

You have the right to:

  • A structured, machine-readable format
  • Transfer to another controller
  • Direct transfer where possible
  • Applies to automated processing

12.6 Right to object (Art. 21 GDPR)

General objection:
In the case of processing based on legitimate interests, you can object on personal grounds.

Objection to advertising:
You can object at any time to the use of your data for direct advertising. This also includes profiling for advertising purposes.

12.7 Automated decisions (Art. 22 GDPR)

You have the right not to be subject to solely automated decisions, except in the case of:

  • Performance of a contract
  • Statutory authorization
  • Explicit consent

12.8 Withdrawal of consent

You can withdraw consent given at any time:

  • Possible without any particular form
  • Effect ex nunc
  • Previous processing remains lawful
  • By e-mail, post or in account settings

13. Protection of minors

13.1 Age restrictions

  • Our services are directed at persons aged 16 and over
  • Legal capacity required
  • For minors: consent of the legal guardians
  • Age verification at registration

13.2 Protective measures

  • No targeted marketing to minors
  • Particular care in data processing
  • Erasure upon becoming aware of minority
  • Information about data protection rights

14. Right to complain and enforcement of rights

14.1 Supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority:

Competent authority:
Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59-61
10555 Berlin
Telephone: +49 30 13889-0
Fax: +49 30 13889-201
E-mail: mailbox@datenschutz-berlin.de
Website: www.datenschutz-berlin.de

Alternative authorities:
You can also contact the supervisory authority of your place of residence or place of work.

14.2 Judicial remedy

In addition to lodging a complaint, the following legal remedies are available to you:

  • Action against the supervisory authority
  • Action against the controller
  • Claims for damages
  • Representation by data protection associations

15. Data protection in the context of job applications

15.1 Applicant data

For applications submitted via our careers portal, we process:

  • Contact data
  • Curriculum vitae
  • Certificates and qualifications
  • Cover letter
  • References
  • Salary expectations

15.2 Purposes of processing

  • Assessment of suitability
  • Communication during the application process
  • Scheduling appointments
  • Travel expense reimbursement
  • Talent pool (with consent)

15.3 Erasure periods

  • In the event of rejection: 6 months (AGG period)
  • Talent pool: 2 years
  • In the event of hiring: transfer to the personnel file

16. Changes to the Privacy Policy

16.1 Updates

This Privacy Policy is reviewed regularly and adapted as necessary:

  • In the event of legislative changes
  • In the event of new services or features
  • In the event of changed processing operations
  • Following notices from supervisory authorities

16.2 Notification of changes

We notify significant changes through:

  • Notice on the website
  • E-mail to registered users
  • In-app notifications
  • Renewed consent request where necessary

16.3 Versioning

  • Current version: 2.0
  • As of: January 2025
  • Last change: Expansion of the cookie information
  • Archive of previous versions available

17. Glossary and explanations of terms

Anonymization: Alteration of personal data in such a way that it can no longer be attributed to a person.

Data processing (on behalf of a controller): Processing of data by a service provider on behalf of the controller.

Legitimate interest: Justification for data processing where the interests of the controller prevail.

Cookie: Small text file stored on the end device when visiting a website.

Third country: A state outside the EU and the EEA.

Consent: A freely given, informed and unambiguous indication of wishes.

Personal data: All information relating to an identified or identifiable person.

Profiling: Automated processing to evaluate personal aspects.

Pseudonymization: Processing in which data can no longer be attributed without additional information.

Controller: The body that decides on the purposes and means of data processing.

18. Contact and further information

If you have any questions about data protection or the exercise of your rights, please contact us:

Data protection contact:

  • E-mail: datenschutz@herochat.de
  • Telephone: +49 30 92 108 711
  • Post: HeroChat GmbH, Datenschutz, Rykestraße 26, 10405 Berlin

Response times:

  • Simple inquiries: 3-5 working days
  • Requests for access: max. 1 month
  • Urgent cases: 24-48 hours

This Privacy Policy was last updated on 09 February 2026.