Privacy policy

  1. Introduction

    We are pleased that you are visiting our website. We respect your privacy. Data protection and data security when using our website are very important to us. With this privacy policy, we aim to inform you about the extent to which data is collected when using our website and for what purposes we use this data. We also want to provide you with information about your rights in this regard.

  2. General Information

    1. In accordance with Art. 13 of the General Data Protection Regulation (GDPR), we hereby inform you about the collection of personal data when using our website. Personal data includes all data that can be related to you personally, such as your name, address, email addresses, and user behavior.
    2. The data controller pursuant to Art. 4(7) of the EU General Data Protection Regulation (GDPR) is Kapnative GmbH, Goltzstraße 35, 10781 Berlin, Contact Tel: +49-176-32509287, Email:
    3. When you contact us via email or through a contact form, the data you provide (your email address, possibly your name and phone number) will be stored by us to respond to your inquiries. The legal basis for processing this data is our legitimate interest in responding to your request in accordance with Art. 6(1)(f) GDPR. If your contact aims at concluding a contract, an additional legal basis for processing is Art. 6(1)(b) GDPR. We will delete the data collected in this context after storage is no longer necessary, or we will restrict processing if there are statutory retention obligations.
    4. If we use subcontractors for specific functions of our offering or wish to use your data for advertising purposes, we will inform you about the details of these processes below. We will also specify the established criteria for the storage duration.
  3. Your Rights

    1. You have the following rights with respect to your personal data that concern you:
      • Right to Information,
      • Right to Rectification or Deletion,
      • Right to Restrict Processing,
      • Right to Object to Processing,
      • Right to Data Portability.
    2. You also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data by us. You can find the relevant supervisory authority for data protection matters at the following link:
  4. Hosting

    1. The hosting services we utilize are used to provide the following services: infrastructure and platform services, computing capacity, storage space, and database services, security services, as well as technical maintenance services that we use for the purpose of operating this online offering.
    2. In this process, we, or our hosting provider, only process the personal data that your browser transmits to our server.
  5. Visit to the website

    1. When you use the website for purely informational purposes, meaning you do not register or submit data to us through contact forms, we only collect the personal data that your browser transmits to our server. When you want to view our website, we collect the following data, which is technically necessary for us, to display our website to you and ensure its stability and security:
      • IP address,
      • Date and time of the request,
      • Time zone difference from Greenwich Mean Time (GMT),
      • Content of the request (specific page),
      • Access status/HTTP status code,
      • Amount of data transmitted in each case,
      • Website from which the request comes,
      • Browser,
      • Operating system and its interface,
      • Language and version of the browser software..
      We collect and store this data based on our legitimate interest for a limited period to initiate a derivation to personal data in the event of unauthorized access or attempted access to our servers (Art. 6(1)(f) GDPR).
  6. Social Media Presence

    We maintain online presences within social networks to inform active users about our services and to communicate directly with interested parties through these platforms. Currently, we are present on the following networks: Substack ( and LinkedIn ( All our social media channels can only be accessed by visitors to our website through an external link. We do not use plugins or other interfaces on our website that social networks offer for embedding their services on websites. We have no influence on the data collection and its further use by the social networks. Therefore, we have no knowledge of the extent, location, and duration of data storage, the extent to which the networks comply with their deletion obligations, the analysis and links made with the data, and to whom the data is disclosed. We expressly point out that user data (e.g., personal information, IP address) is stored by the operators of the networks in accordance with their data usage policies and used for business purposes. We process the data of users in our social media presences to the extent that they contact us and communicate with us, for example, through comments or direct messages. The legal basis for processing user data is Art. 6(1)(b) and (f) GDPR.

    1. Substack:

      Within our online offering, no functions and content from the Substack service, provided by Substack Inc., 111 Sutter St 7th Floor, San Francisco, United States, are integrated. Substack channels can only be accessed via an external link. If visitors to our website are members of the Substack platform, Substack may associate the visit to the social media channel with the user's profile there, provided that the user visits the BSI Twitter profile while logged in. We would like to point out that we have no influence on the content and scope of data collected by Substack. For further information regarding this, we refer to Substack's privacy policy:

    2. LinkedIn

      Within our online offering, no functions and content from the LinkedIn service, provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, are integrated. LinkedIn channels can only be accessed via an external link. We would like to point out that we have no influence on the content and scope of data collected by LinkedIn. For further information regarding this, we refer to LinkedIn's privacy policy:

  7. Applications

    You can apply to our company electronically, for example, via email or a web form. Please note that unencrypted emails are not transmitted securely.

    Your information will be used for processing your application and making a decision regarding the establishment of an employment relationship. The legal basis is § 26(1) in conjunction with § 26(8) sentence 2 of the German Federal Data Protection Act (BDSG). Furthermore, your personal data may be processed if necessary to defend against legal claims asserted in connection with the application process. The legal basis for this is Art. 6(1) sentence 1 lit. f GDPR. The processing also serves our legitimate interests.

    If an employment relationship is established between you and us, we may further process the personal data you have already provided to us for the purposes of the employment relationship in accordance with § 26(1) BDSG, provided that this is necessary for the performance or termination of the employment relationship or for the exercise or fulfilment of rights and obligations of the employee representation arising from a law or a collective agreement, works agreement, or service agreement.

    Your application data will not be processed beyond the purposes described above. Your personal data will be deleted no later than 6 months after the conclusion of the application process, unless there are other legitimate interests on our part that oppose deletion or you have provided consent for a longer storage period. Other legitimate interests in this sense may include, for example, an obligation to provide evidence in a procedure under the General Act on Equal Treatment (AGG).

  8. General Newsletter Information

    1. You can subscribe to a newsletter on our website, through which we will inform you about our company's activities, current information about our services, special offers, promotions, and events. The content of each newsletter is briefly described during the registration process. The legal basis for sending the respective newsletter is your consent pursuant to Art. 6(1) sentence 1 lit. a GDPR in conjunction with § 7(2) No. 3 UWG or the legal permission according to § 7(3) UWG.
    2. For newsletter registration, we use the double-opt-in procedure. This means that after your registration, we will send you an email to the provided email address, asking for confirmation that you wish to receive the newsletter. If you do not confirm your registration, your information will be automatically deleted after 3 days.
    3. Mandatory information for receiving the newsletter includes your email address, salutation, and last name. Providing additional data is voluntary, and this data is used to address you personally. After your confirmation, we will store your email address for the purpose of sending the newsletter until you revoke your consent. We also store your current IP address at the time of registration, the time of registration, and the confirmation for up to three years after registration (statute of limitations). The purpose of this procedure is to be able to prove your registration in case of doubt and to potentially clarify any misuse of your personal data. The legal basis for logging the registration is our legitimate interest according to Art. 6(1) sentence 1 lit. f GDPR in proving a previously given consent, also see Art. 7(1) GDPR.
    4. You can revoke your consent for receiving the newsletter and unsubscribe at any time. You can declare your revocation by clicking on the link provided in each newsletter email or by sending an email to
    5. Newsletter Tracking: We would like to inform you that when we send the newsletter, we evaluate your user behaviour to determine if and when the newsletter was opened. Technical information such as browser type, time of opening, and IP address are transmitted in this process. With the data obtained in this way, we create a user profile in order to tailor the newsletter to your individual interests. We record when you read our newsletters, which links you click on, and deduce your personal interests from this information. We link this data with actions you take on our website. The legal basis for this data processing is your consent, Art. 6(1) sentence 1 lit. a GDPR. You can revoke your consent for tracking at any time with future effect by clicking on the separate link provided in each email. Such tracking is also not possible if you have deactivated the display of images by default in your email program. In this case, the newsletter will not be displayed completely, and you may not be able to use all functions. If you manually display the images, the above-mentioned tracking will take place. The tracking information is stored for as long as you have subscribed to the newsletter. After unsubscribing, the data is anonymized and used for purely statistical purposes. The data you have provided to us for the purpose of newsletter subscription will be stored by us until you unsubscribe from the newsletter, and will be deleted after unsubscribing. Data that has been stored for other purposes with us remains unaffected by this.
  9. Google Analytics

    Our website uses Google Analytics, a web analytics service provided by Google Inc. ('Google'). For this web analytics service, Google Analytics uses so-called 'cookies', which are text files stored on your computer that enable an analysis of your use of the website. The information generated by the cookie about your use of our website is usually transmitted to a Google server in the USA and stored there. If IP anonymization is activated on our website, your IP address will be shortened by Google within the member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted. In exceptional cases, the full IP address may be transmitted to a Google server in the USA and then shortened there. Google may use this information, which is stored, to evaluate your use of the website and to compile reports on website activity for us as the website provider. The IP address transmitted by your browser as part of Google Analytics is not merged with other Google data. If you do not want this analysis to take place during your visit to our website, you can prevent the storage or installation of cookies by adjusting your browser software settings accordingly. However, we would like to inform you that in this case, you may not be able to use all the functions of our website to their full extent. By using this website, you consent to the processing of data about you by Google in the manner and for the purposes set out above. You can also prevent Google from collecting and processing data generated by the cookie and related to your use of the website by downloading and installing the browser plugin available at the following link:


    We use 'Google reCAPTCHA' (hereinafter 'reCAPTCHA') on our websites. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ('Google').

    reCAPTCHA is used to check whether data input on our websites (e.g., in a contact form) is done by a human or by an automated program. To do this, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis starts automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various information (e.g., IP address, duration of the website visit, or mouse movements made by the user). The data collected during the analysis is forwarded to Google.

    The reCAPTCHA analyses run entirely in the background. Website visitors are not notified that an analysis is taking place.

    The data processing is based on Art. 6(1) lit. f GDPR. The website operator has a legitimate interest in protecting its web offerings from abusive automated spying and spam.

    For more information about Google reCAPTCHA and Google's privacy policy, please refer to the following links: and

  11. Cookies

    1. In addition to the data mentioned above, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard drive and are associated with the browser you are using, allowing certain information to be transmitted to the entity that sets the cookie (in this case, us). They serve to make the overall internet offering more user-friendly and effective.
    2. We only use essential cookies that are necessary for the functionality of our website and without which the functionality of our website would be limited.

Each month, you'll receive Kapnative updates about new partners and features - straight to your inbox.