Privacy
Last updated: 15 July 2026
1. Controller and data protection officer
The controller responsible for processing personal data on this website is:
CompLeadly OHG
Hauptstr. 26
51465 Bergisch Gladbach
Germany
Phone: +49 2202 1860373
Email: info@compleadly.de
Our data protection officer is:
Smart DSGVO GmbH
Maik Becker
Fuggerstr. 9
41468 Neuss
Germany
Phone: +49 2131 52688 80
Email: info@smart-dsgvo.de
2. General information
Purposes, legal bases and recipients
We process personal data only where necessary to provide and secure the website, handle enquiries and applications, send our newsletter or act on your consent. The relevant legal bases include Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract and pre-contractual steps), Art. 6(1)(c) GDPR (legal obligation) and Art. 6(1)(f) GDPR (legitimate interests). Access to information on your device is also governed by Section 25 TDDDG.
We use processors in particular for hosting, content delivery, object storage, email delivery, CRM and technical communication. They process data only on our instructions and under appropriate agreements. Self-hosted components such as Payload, MongoDB, Redis, Meilisearch and ClamAV are software within our infrastructure and are not separate recipients.
Retention
We retain personal data only for as long as necessary for the relevant purpose. We then delete or anonymise it unless statutory retention duties, the establishment or defence of legal claims, or another lawful reason requires further retention. More specific periods are stated below.
Your rights
Subject to the statutory requirements, you have rights of access, rectification, erasure, restriction and data portability. You may withdraw consent at any time with future effect. Where processing is based on Art. 6(1)(e) or (f) GDPR, you may object on grounds relating to your particular situation. You may object to direct marketing at any time without giving reasons.
You also have the right to lodge a complaint with a data protection authority. Our competent authority is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestr. 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.
Encryption
The website is transmitted using TLS encryption. Nevertheless, no transmission over the internet can be protected completely against access by third parties.
3. Provision, hosting and security
Hosting and content delivery
The website runs on external server infrastructure and is delivered through Cloudflare services. The relevant server and data-centre provider processes, as our processor, IP addresses, connection data, server logs and data submitted through forms. The legal bases are Art. 6(1)(b) GDPR where processing serves pre-contractual steps and otherwise Art. 6(1)(f) GDPR. Our legitimate interest is the secure, fast and reliable provision of our online service.
Cloudflare
We use Cloudflare for DNS, CDN, caching, protection against attacks and automated access, edge functions and – depending on the production configuration – private object storage. The provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; the contracting entity for European customers may be a European Cloudflare company.
Cloudflare processes in particular the IP address, date and time, requested URL, referrer, HTTP headers, browser and device information, and security events. Processing is based on Art. 6(1)(f) GDPR. Our legitimate interests are secure delivery and protection against abuse.
Cloudflare may process data in the United States. Where the recipient is certified under the EU-US Data Privacy Framework, the transfer is based on the European Commission's adequacy decision under Art. 45 GDPR; Standard Contractual Clauses may be used in addition. Further information: Cloudflare Privacy Policy.
Server logs, rate limiting and error reports
For troubleshooting and abuse prevention, we process technical log data such as time, path, HTTP method, request ID, browser information, error messages, performance values and security reports. IP addresses are hashed with a regularly changing salt in our application and rate-limit logic. These hashes are stored temporarily in Redis for rate limiting. Browser security reports may contain the affected URL and technical information about a blocked resource.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests are system stability, troubleshooting and security. Logs are deleted when they are no longer required for these purposes; security-related data may be retained until an investigation and the defence or enforcement of claims have been completed.
Traffic measurement with Umami (cookie-free)
For statistical analysis of website usage we use the open-source analytics software Umami, which we operate ourselves on a server in Germany (asset.complead.ly). Umami works without cookies and stores nothing in your browser. It records pages visited, referrer, browser, operating system, device type, screen size, approximate region of origin, technical performance metrics and interactions with annotated elements (e.g. button clicks). In addition, non-personal session attributes such as the selected language, the selected colour scheme and the status of your cookie choices are recorded. IP addresses are not stored permanently; visitors are not tracked across websites and no data is shared with third parties.
The legal basis is our legitimate interest in statistically analysing and improving our services (Art. 6(1)(f) GDPR). No consent-requiring access to your terminal equipment within the meaning of Section 25 TDDDG takes place. You may object to this processing at any time with effect for the future (Art. 21 GDPR), for example by emailing the address given in section 1.
4. Cookies and browser storage
We use cookies and comparable browser storage such as Local Storage. Storage or access that is not strictly necessary occurs only with your consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR. Necessary storage is based on Section 25(2)(2) TDDDG and, where personal data is involved, the legal bases stated for the respective processing.
You can change your choices at any time under Cookie settings. A detailed and current list of optional services, providers, data categories and storage periods is also available there.
cl_consentandcl_consent_mirror: consent status and technical consent ID, 12 months.promo_variant: assigned promotional/A/B variant, 30 days; set only after marketing consent and deleted when consent is absent or withdrawn.compleadly-theme: display preference explicitly selected by you, until deleted in the browser.cl_contact_wizard: locally stored contact form draft, 24 hours or until successful submission.cl_recent_searchesandcl_recent_visited: recent search terms and opened search results, stored locally until deleted in the browser.cl_newsletter_dismissed_until: suppresses the newsletter prompt, 30 days.cl_newsletter_subscribed: locally remembers a successful subscription until deleted in the browser.cl_promo_dismissed_<slug>: remembers that a specific notice was dismissed until deleted in the browser.
The cl_preview cookie is used only by authorised editors to protect previews of unpublished content and is deleted after a short period or when the preview is closed.
5. Forms and communication
Contact form
When you use the contact form, depending on the selected mode we process your name, email address, company, telephone number, message, type of enquiry, project type, timeframe, company size, language, source page and any attachments you choose to upload. A multi-step form draft is stored exclusively in your browser under cl_contact_wizard for no more than 24 hours.
We store submitted data in our content and administration system. Attachments are placed in private object storage and scanned by our self-hosted ClamAV malware scanner before processing. If the administration system is temporarily unavailable, a submission may be held in private fallback object storage and imported later.
Your name and email address are transmitted to HubSpot to manage the enquiry. The provider is HubSpot Ireland Limited, 2nd Floor, 30 North Wall Quay, Dublin 1, Ireland, with affiliated companies in the United States. The transfer enables structured handling and follow-up. The legal basis is Art. 6(1)(b) GDPR for contract-related enquiries and otherwise Art. 6(1)(f) GDPR. Our legitimate interest is efficient handling. Transfers to the United States may rely on the EU-US Data Privacy Framework adequacy decision and Standard Contractual Clauses. Further information: HubSpot Privacy Policy.
We send acknowledgements and internal notifications through a contracted email provider. If the corresponding production feature is enabled, a notification containing the name and email address may be sent to our responsible team through Slack. The provider is Slack Technologies, LLC, a Salesforce company. The legal basis is Art. 6(1)(b) or (f) GDPR. Further information: Slack Privacy Policy.
We delete contact enquiries after they have been handled and no contractual, evidential or statutory retention reason remains. If an enquiry results in a contract, the necessary data is retained for the applicable commercial and tax retention periods.
Cloudflare Turnstile
The contact and partner forms use Cloudflare Turnstile to prevent automated submissions. When the widget is loaded and verified, Cloudflare processes in particular the IP address, browser and device signals, interaction and security characteristics, and the verification result. Our server sends the generated token and IP address to Cloudflare for verification. The legal bases are Section 25(2)(2) TDDDG and Art. 6(1)(f) GDPR. Our legitimate interest is protecting our forms and systems against spam and abuse. Information about Cloudflare and international transfers is provided in Section 3.
Partner application
For a partner application, we process your name, email address, audience size, selected channels, message and internal application status. The data is stored in our administration system and sent to the responsible team through our contracted email provider. If the corresponding production feature is enabled, an additional Slack notification containing the name and email address may be sent.
The legal basis is Art. 6(1)(b) GDPR where the application initiates a partnership and otherwise Art. 6(1)(f) GDPR. We delete unsuccessful applications once the decision has been completed and no evidential or legal-defence reason remains. If a partnership is established, contractual and statutory retention periods apply.
Newsletter
For the newsletter, we process your email address, language, source page, confirmation status and the dates of confirmation and unsubscription. Registration uses a double opt-in process. The random confirmation token is stored in Redis for seven days. Confirmation and newsletter emails are sent through our contracted email provider. At the current stage, no additional external newsletter contact database such as Brevo or Listmonk is synchronised.
The legal basis for sending the newsletter is your consent under Art. 6(1)(a) GDPR. Registration and confirmation data is retained to demonstrate consent under Art. 6(1)(c) and (f) GDPR. You may unsubscribe using the link in every email. We then process the address only where necessary to demonstrate the previous consent or ensure that the unsubscription is respected.
Email, telephone and WhatsApp
When you contact us by email or telephone, we process your contact details and the content of the communication to deal with your request. The legal basis is Art. 6(1)(b) GDPR for contract-related communication and otherwise Art. 6(1)(f) GDPR.
We also offer voluntary contact through WhatsApp Business. The provider is WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, a Meta group company. In addition to encrypted communication content, WhatsApp processes communication metadata. Use WhatsApp only if you agree to this processing; email, telephone and the contact form are available as alternatives. Further information: WhatsApp Privacy Policy.
6. Search and consent records
Website search
Search terms are sent to our own search API and self-hosted Meilisearch software to display matching content. Recent searches and pages opened from search results may be stored locally in your browser. This local history is not sent to an external search provider. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is making our content easy to find.
Consent records
We keep a consent record to demonstrate your cookie and service choices. It contains the consent ID, time, version of the notice, current and previous choices, language, action and source of the decision, a hash of the IP address, a hash of the user agent and the referrer path on our domain. The record is retained for three years and then deleted automatically. The legal bases are Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR and Art. 6(1)(f) GDPR. Our legitimate interest is demonstrating that consent was properly obtained or withdrawn.
7. Consent-dependent services
Umami session replay and heatmaps (statistics & usage analysis)
With your consent to the “Statistics & usage analysis” category, our self-hosted Umami instance (servers located in Germany) records your visit (session replay) and creates aggregated click and scroll heatmaps from it. Mouse movements, clicks, scrolling behaviour, page navigation and the visible page content are recorded. Input into form fields is technically masked and never recorded. No cookies are set; recording takes place exclusively on our own server and is not shared with third parties. Recordings are automatically deleted after 30 days.
The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR (consent). Without your consent no recording takes place; the script required for this is then not loaded. You can withdraw your consent at any time with effect for the future via the cookie settings — recording then stops immediately.
Meta Pixel and Google Ads
The website is technically prepared to use Meta Pixel and Google Ads conversion tracking. The respective scripts are loaded only where the relevant identifier is enabled in the production environment and you have first consented to the “Marketing and performance measurement” category. Without this consent, these services are not loaded and an existing promo_variant cookie is deleted.
When used, usage, device, browser, referrer and campaign data and online identifiers may be transmitted to Meta Platforms Ireland Limited or Google Ireland Limited and affiliated companies in the United States. The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR. You may withdraw consent at any time through the cookie settings. Provider information: Meta Privacy Policy and Google Privacy Policy.
First-party campaign attribution
After you consent to “Marketing and performance measurement”, we store advertising click identifiers (Google, Meta, LinkedIn, Microsoft and TikTok), UTM parameters, referrer, timestamp and a pseudonymous session ID under compleadly_attribution in Local Storage. When you continue to the CompLeadly app, these campaign parameters are appended to the app URL. When you click a download, the operating system and browser identifier may also be sent to our app backend together with the campaign data. The data expires after no more than twelve months and is deleted when consent is withdrawn. The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
YouTube and Loom
Editorial content may include videos from YouTube in privacy-enhanced mode or Loom. An external iframe is loaded only after you consent to the “External embeds” category. Google Ireland Limited or Loom, Inc. then receives in particular the IP address, browser and device information, the page visited and video usage data and may use cookies or Local Storage. If you are signed in to the provider, the visit may be associated with your account.
The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR. The safeguards described in Section 3 apply to possible transfers to the United States. Provider information: Google Privacy Policy and Loom Privacy Policy.
8. External links and editorial systems
External links and social networks
Our website contains ordinary links to external services, for example LinkedIn, Facebook, Instagram, YouTube, X, ProvenExpert, Trustpilot and WhatsApp. Merely loading our website does not establish a connection to these providers through such links. Only when you click a link does your browser request the external page and transmit your IP address and technical connection data. From that point, the respective provider is responsible for its processing.
AI-assisted editorial translation
Anthropic, PBC, 548 Market Street, San Francisco, CA 94104, USA may be used to translate editorial CMS content. The texts to be translated are transmitted to Anthropic. Form submissions, newsletter data and consent records are not intended for this translation function. Personal content is transmitted only where necessary for the editorial purpose and legally permitted. The legal basis is Art. 6(1)(f) GDPR or, where personal data is involved, the legal basis applicable to the source content. Further information: Anthropic Privacy Policy.
9. International transfers and changes
Some providers may process data outside the European Economic Area. Depending on the recipient, we rely on an adequacy decision under Art. 45 GDPR, in particular the EU-US Data Privacy Framework for certified US organisations, or appropriate safeguards such as the European Commission's Standard Contractual Clauses under Art. 46 GDPR. Despite these safeguards, access by foreign authorities cannot be ruled out completely.
We update this privacy notice when our website, the services used or the legal requirements change. The version published on this page is the applicable version.