Privacy Policy (GDPR)
Effective: 30 September 2026
This Privacy Policy explains how Firmendata UG (haftungsbeschränkt) processes personal data when you use our website and services, and what personal data about natural persons named in public registers (for example managing directors, shareholders, and beneficial owners) we process as part of our service.
1. Controller
Controller (data controller) under Art. 4(7) GDPR:
Firmendata UG (haftungsbeschränkt)
c/o Ersin Bayraktar
Pistoriusstraße 102A
13086 Berlin
Germany
Managing Directors: Julian Lenz, Ersin Bayraktar
General contact: [email protected]
2. Data Protection Officer
We are currently not legally required to appoint a Data Protection Officer. For all privacy related questions, please contact us using the contact details above.
3. Categories of Data About You
Depending on how you use our website and services, we may process the following categories of data about you (the visitor or registered user):
- Usage data: IP address, date and time of access, requested pages, referrer URL, device information, browser information.
- Account data: name, email address, sign-up date/time, most recent login date/time.
- Contact data: email address and the content of your message when you contact us.
- Security and anti-abuse signals: technical signals used to protect our contact form and platform against automated abuse.
- Billing and subscription data: name, billing address, country, selected plan, subscription status, Stripe customer identifier, invoice records. Card details themselves are processed by Stripe and never stored on our systems.
- Developer / API access data: issued API keys, per-key request counts, credit consumption, and rate-limit windows. Used to operate the public REST API and the MCP server and to display usage in your account.
- Watchlist data: the companies you have added to your watchlist and the notifications you have received. This reveals what entities you are tracking.
- Subscription / webhook configuration data: webhook destination URLs you configure for the Subscriptions & Events feature, plus delivery logs of payloads we send to those URLs.
- Search query data: the search terms and filter parameters you submit (which may, depending on what you search for, include personal identifiers such as the name of a board member or shareholder you are looking for). Search queries are stored linked to your account for analytics, rate-limiting, and abuse prevention; their retention follows the server-log retention in Section 17.
We do not intentionally process special categories of personal data about you under Art. 9 GDPR.
4. Personal Data About Persons Named in Public Registers
Our core service makes publicly filed German company-register data available to our users. Some of that data necessarily identifies natural persons. We process such data as a controller under Art. 4(7) GDPR.
Affected data subjects are persons named in public registers in connection with a German company, in particular:
- Managing directors, board members, supervisory-board members, authorised representatives (Prokuristen), liquidators.
- Shareholders of GmbHs and UGs named in the Liste der Gesellschafter (Gesellschafterliste).
- Ultimate beneficial owners we identify by computing the ownership chain ourselves from publicly filed Gesellschafterlisten and other register filings under §3 GwG. We do not currently ingest data from the Transparency Register (Transparenzregister).
- Persons named in published insolvency notices (Insolvenzbekanntmachungen).
- Persons named as contact persons or authorised signatories on awarded EU public-procurement notices.
Depending on the underlying public source, the data may include:
- First and last name; in some cases historical name variants.
- Role within the company and the period during which the role was held.
- Place of residence at the municipality level only. We do not store or publish full street addresses of natural persons.
- Date of birth, where it appears in publicly filed Gesellschafterlisten (cf. §40 GmbHG) for shareholders of GmbHs and UGs.
- Share count, share percentage, and share class (for shareholders).
We obtain this data exclusively from publicly accessible sources made available by law. The principal sources are:
- Unternehmensregister and Handelsregister (HRA / HRB / GnR / PR / VR / GsR), including filed documents (Aktueller Abdruck, Chronologischer Abdruck, Gesellschaftsvertrag / Satzung, Anmeldung, Musterprotokoll, Liste der Gesellschafter).
- pages.privacyPolicy.s4.sourceBundesanzeiger
- GLEIF Legal Entity Identifier (LEI) database.
- TED (Tenders Electronic Daily) — EU public-procurement notices.
- Insolvenzbekanntmachungen (the official Insolvency Notices portal).
Legal basis: our processing is based on Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest is to provide business-intelligence services on German companies to support due diligence, anti-money-laundering (KYC/AML), credit assessment, M&A research, journalistic research, and other lawful business purposes. We have carried out a balancing test; the relevant data has been published by the German legislator in registers specifically intended for inspection by interested third parties.
Purposes: enabling our users to search, view, analyse and download German company data; producing aggregated industry and regional statistics; computing ownership graphs and ultimate-beneficial-owner reports for KYC purposes; generating AI summaries (see Section 13).
Information under Art. 14 GDPR: Because we do not obtain this data directly from the data subject but from public registers, we provide this Privacy Policy in fulfilment of our information obligation under Art. 14 GDPR. To the extent that providing individual notice to each data subject would prove impossible or would involve disproportionate effort given the volume of register entries, we rely on the exemption in Art. 14(5)(b) GDPR and make the required information available here.
Your rights as a data subject named in our records: you may exercise the rights described in Section 21 (access, rectification, erasure, restriction, objection) against us with respect to data about you that we hold. Please use the contact details in Section 1 and identify the company entry concerned.
Right to object (Art. 21 GDPR): you have the right to object at any time, on grounds relating to your particular situation, to our processing of personal data about you that is based on Art. 6(1)(f) GDPR. If you object, we will no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
Note on rectification: where the underlying public register is corrected, we incorporate the correction at our next scheduled re-fetch of that entry, or earlier on request.
5. Purposes and Legal Bases
Beyond the register-data processing described in Section 4, we process personal data about you for the following purposes and on the following legal bases:
- Providing the website and ensuring security and stability (Art. 6(1)(f) GDPR; legitimate interest).
- Providing our services and authentication (Art. 6(1)(b) GDPR; contract or pre-contractual measures).
- Administering paid plans, subscription billing, invoicing, and payment processing (Art. 6(1)(b) GDPR; contract).
- Operating the public REST API and the MCP server, including rate-limiting, credit accounting, and abuse prevention (Art. 6(1)(b) GDPR for contract performance and Art. 6(1)(f) GDPR for security).
- Responding to inquiries (Art. 6(1)(b) GDPR if related to pre-contractual measures, otherwise Art. 6(1)(f) GDPR).
- Website analytics (Art. 6(1)(a) GDPR; consent, where cookies or similar technologies are used).
- Compliance with legal obligations, including statutory retention requirements under the German Commercial Code (HGB) and the Fiscal Code (AO) (Art. 6(1)(c) GDPR).
Where we rely on consent, you can withdraw it at any time with effect for the future.
6. Cookies and Consent Management
We use Klaro (an open-source consent management tool, https://klaro.org) to record and manage your choices regarding optional technologies (for example analytics). You can change or withdraw your consent at any time via the cookie settings on our website.
Strictly necessary technologies may be used without consent where permitted by applicable law (for Germany, in particular the rules on access to and storage of information on end-user devices).
7. Hosting and Infrastructure (Hetzner)
Our website, application servers, primary database, and object storage for register documents (e.g. PDFs of register extracts and shareholder lists) are hosted on infrastructure provided by Hetzner Online GmbH (Germany). In the course of hosting, Hetzner may process personal data (for example IP addresses in server logs, and the contents of the database and stored documents) on our behalf.
- Purpose: reliable and secure operation of our website, services, and document store.
- Legal basis: Art. 6(1)(f) GDPR.
- Processing arrangement: we have concluded a data processing agreement with Hetzner as required by Art. 28 GDPR.
8. Content Delivery and Proxy Services (Cloudflare)
We use Cloudflare as a reverse proxy and caching layer to improve performance and help protect our website against common network attacks. When you access our website, Cloudflare necessarily receives technical connection data, including IP address and request metadata.
- Purpose: performance optimization, reliability, and security.
- Legal basis: Art. 6(1)(f) GDPR.
- Processing arrangement: we have concluded a data processing agreement with Cloudflare (Art. 28 GDPR).
- International transfers: Cloudflare is headquartered in the United States. Depending on how the service is provided, personal data may be transferred to the United States or other countries. We rely on appropriate safeguards for international transfers (for example, Standard Contractual Clauses) and, where applicable, adequacy frameworks.
9. Spam and Abuse Prevention on the Contact Form (Cloudflare Turnstile)
To protect our contact form from automated abuse, we use Cloudflare Turnstile. Turnstile processes technical signals (such as IP address, browser characteristics, and interaction timing) to distinguish humans from bots. Depending on the configuration, Turnstile may also use strictly necessary cookies or tokens for security purposes.
- Purpose: prevention of spam and abuse, protection of our infrastructure.
- Legal basis: Art. 6(1)(f) GDPR.
- Device storage / cookies: where strictly necessary security tokens are used, this is based on the applicable rules for strictly necessary technologies.
- International transfers: see Section 8.
10. Authentication and User Accounts (Auth0)
We use Auth0 for authentication and user management. Auth0 stores and processes data required for login and account management. According to our current setup, Auth0 stores the following account data:
- Name
- Email address
- Sign-up date/time
- Most recent login date/time
- Purpose: authentication, account security, and access control.
- Legal basis: Art. 6(1)(b) GDPR (contract or pre-contractual measures) and Art. 6(1)(f) GDPR (security).
- Processing arrangement: we use Auth0 under a data processing agreement.
- International transfers: we use an Auth0 EU tenant; user authentication data is therefore primarily processed in the European Union. Underlying support and engineering activities by Okta, Inc. (the US parent of Auth0) may incidentally involve access to data from the United States. Such access is covered by Standard Contractual Clauses and, where applicable, adequacy frameworks.
11. Payment Processing (Stripe)
For paid plans, payment processing is carried out by Stripe Payments Europe Limited (Ireland), with sub-processors in the Stripe group including Stripe, Inc. (United States). Stripe acts as a separate data controller for parts of the payment processing (in particular for fraud prevention and regulatory compliance) and as our processor for other parts of the transaction.
Data received by Stripe: name, billing email address, billing address, country, payment method information (Stripe stores the card data itself; we receive only a token, the last 4 digits, and the card brand for display on invoices), transaction amount, currency, and subscription identifiers.
- Purpose: processing of subscription payments and refunds, prevention of payment fraud, generation of invoices.
- Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) GDPR (legal obligations, including tax and anti-money-laundering rules).
- Processing arrangement: we use Stripe under Stripe's Data Processing Agreement (Art. 28 GDPR) for the parts where Stripe acts as our processor.
- International transfers: while Stripe Payments Europe Limited is based in Ireland, group sub-processors are located in the United States and other countries. We rely on appropriate safeguards for international transfers (Standard Contractual Clauses) and, where applicable, adequacy frameworks.
Stripe's own Privacy Policy at stripe.com applies to Stripe's processing as a separate controller.
Stripe Tax: where applicable to your transaction (in particular for VAT obligations on cross-border EU sales), Stripe collects and remits VAT and may share tax-relevant transaction data with the competent tax authorities in fulfilment of statutory tax obligations (Art. 6(1)(c) GDPR).
12. Transactional Email (Microsoft Azure Communication Services)
We use Microsoft Azure Communication Services Email, with Microsoft Ireland Operations Limited (Dublin, Ireland) as processor, to send transactional messages from mail.firmendata.com. Auth0 account emails, including login, verification and password-reset messages, are sent through the same Azure service. Microsoft processes recipient email addresses, message subjects and contents, and delivery metadata. Data stored at rest by the service is stored in Germany, the resource's data location.
Categories of emails we send via Azure Communication Services:
- Account-related messages (welcome, email verification, password reset, security alerts).
- Subscription and billing notifications (renewal reminders, invoices, payment failure notices).
- Watchlist notifications about companies you track.
- Subscription / event notifications generated by the Subscriptions & Events feature where you have opted to receive them via email instead of a webhook.
- Purpose: delivering transactional emails required to operate the service and the subscriptions you have configured.
- Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in security notifications).
- Processing arrangement: Microsoft Ireland Operations Limited acts as our processor under the Microsoft Products and Services Data Protection Addendum (DPA, Art. 28 GDPR).
- International transfers: Microsoft's group includes entities outside the EU/EEA, in particular in the United States, that may access data for technical operation and support. Any transfers are covered, as applicable, by the EU-US Data Privacy Framework (Microsoft is certified) and Standard Contractual Clauses.
13. AI-Generated Insights
Some tool responses (in particular within the company-detail view) include short AI-generated summaries describing publicly available information about the company. These summaries may incidentally include personal data about persons named in the underlying public register (see Section 4).
These insights are informational and do not constitute automated individual decision-making with legal or similarly significant effects within the meaning of Art. 22 GDPR. They are not used for credit decisions, employment decisions, or other automated decisions that would directly affect the data subject.
Provider: to generate the summaries we use large language model APIs operated by third-party providers (currently including Anthropic and OpenAI). The relevant subset of company data is sent to the model provider's API; the provider's contractual terms prohibit the use of such API content to train their models. Each provider acts as our processor for this purpose under their respective data processing agreement.
International transfers: these providers may process the API requests in the United States or other countries. We rely on appropriate safeguards for international transfers (Standard Contractual Clauses) and, where applicable, adequacy frameworks.
If you do not want AI insights computed about a specific entry where you are the data subject, please contact us using the details in Section 1.
14. FirmenData MCP Connector for Claude (Anthropic)
We offer an optional Model Context Protocol (MCP) connector that lets you use FirmenData tools from within Anthropic's Claude product. The connector is opt-in: it is only active if you, as a registered FirmenData user, add it to your Claude account via the Claude connector settings.
How it works: when the connector is active and you ask Claude a question that Claude decides to answer using a FirmenData tool, Claude sends a tool call to our MCP server. The tool call (and the FirmenData response that Claude receives) pass through Anthropic's infrastructure.
Data shared with Anthropic: the contents of your Claude conversations (which may include identifiers such as company names or eu_ids that you have entered), the tool calls Claude makes to FirmenData, and the responses we return — all of which Anthropic processes as a separate controller in order to operate the Claude product.
Your choice: you can disable or remove the FirmenData connector in Claude at any time. Disabling the connector stops all further data flow between Claude and FirmenData.
Anthropic's own Privacy Policy at anthropic.com applies to Anthropic's processing as a separate controller. We do not control how Anthropic stores or uses the contents of your Claude conversations.
15. Website Analytics and Advertising (Google Analytics, Google Ads)
We use Google Analytics to measure basic visitor traffic and to understand how our website is used (for example, page views, session information, approximate location at a coarse level, and device information).
We do not use Google Analytics itself for remarketing or marketing profile building. For how we measure our ads, see the Google Ads section below.
- Purpose: aggregated website usage analysis and improvement.
- Legal basis: your consent (Art. 6(1)(a) GDPR). Where cookies or similar technologies are used, consent is also required under the applicable rules on end-user device access.
- Consent control: Google Analytics is only activated if you consent via our cookie settings.
- International transfers: Google may process data in the United States or other countries. We rely on appropriate safeguards for international transfers (for example Standard Contractual Clauses) and, where applicable, adequacy frameworks.
Google Ads (conversion tracking)
We run ads via Google Ads, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. With your consent, we measure whether a visit through one of our ads leads to a sign-up or a purchase (conversion tracking). For this, Google sets cookies (for example _gcl_au) and processes, among other things, click identifiers, the time and type of the conversion and, for purchases, their value and a transaction identifier; we do not pass on purchase or account data such as your name, email address or payment details. We do not use remarketing or personalized advertising based on your visit.
- Purpose: measuring and optimizing the performance of our ads.
- Legal basis: your consent (Art. 6(1)(a) GDPR) and Section 25(1) TDDDG for access to your device.
- Consent control: Google Ads only loads if you consent under “Marketing” in our cookie settings. We use Google's Consent Mode, which passes your choice on to Google. You can withdraw your consent at any time with effect for the future via the cookie settings.
- International transfers: Google may process data in the United States or other countries, on the basis of the EU-US Data Privacy Framework adequacy decision where Google is certified under it, and Standard Contractual Clauses. More information: https://policies.google.com/privacy and https://business.safety.google/privacy/
16. Contacting Us
When you contact us (for example via contact form or email), we process the data you provide (such as email address and message content) to handle your request.
- Legal basis: Art. 6(1)(b) GDPR if your inquiry relates to a contract or pre-contractual measures, otherwise Art. 6(1)(f) GDPR.
- Retention: we store inquiry data only as long as necessary to handle your request and to meet any legal retention requirements (see Section 18).
17. Server Logs and Their Retention
We store server and application logs (which may include IP addresses) for no longer than 14 days, unless a longer retention is necessary in an individual case (for example, investigating security incidents) or required by law.
Please note that our service providers (for example Cloudflare, Auth0, Stripe, Microsoft (Azure), Google) may apply their own retention periods under their documentation and contractual terms.
18. Retention of Other Categories of Data
Beyond the 14-day server-log retention in Section 17, we apply the following retention periods:
- Account data (name, email, sign-up and login timestamps): for as long as your account exists; after account deletion, we keep minimal records as needed to comply with legal obligations.
- Billing and invoice data: 10 years after the end of the fiscal year, as required by §147 AO and §257 HGB.
- Subscription state (plan, renewal dates, cancellation): for as long as the subscription is active and afterwards for the duration of the billing retention period above.
- Watchlist entries: until you remove them or delete your account.
- API keys: until you revoke them or delete your account.
- API usage counters (per-key request counts and credit spend): up to 90 days at per-day granularity, then deleted automatically.
- Webhook configuration and delivery logs: webhook destinations are kept until you remove them; delivery logs for at most 30 days unless required longer for diagnosing failures.
- Contact inquiries: as long as needed to handle the request and afterwards for ordinary business correspondence retention (typically up to 6 years under HGB / AO where applicable).
- Personal data from public registers (see Section 4): for as long as the entity remains in our index and the underlying data is still publicly available. We re-fetch register data periodically; corrections in the source flow through to our index on the next re-fetch.
19. Recipients of Data
We may share personal data with:
- Processors that support us in providing the service (hosting, CDN/proxy, security, authentication, payment processing, email delivery, analytics, AI summarisation, MCP transport).
- Authorities where we are legally required to disclose information.
- Other FirmenData users with respect to data about persons appearing in the public registers covered by our service (see Section 4) — this is the core purpose of the service.
We do not sell personal data.
20. International Data Transfers
Some of our service providers are located outside the EU/EEA (in particular in the United States). In such cases, we use appropriate safeguards for transfers under Art. 44 et seq. GDPR, such as:
- Standard Contractual Clauses (SCCs)
- Additional technical and organizational measures where appropriate
- Adequacy decisions or recognized frameworks where applicable
21. Your Rights
Under the GDPR, you have the following rights, subject to statutory requirements:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing based on legitimate interests (Art. 21 GDPR)
- Right to withdraw consent at any time (Art. 7(3) GDPR)
To exercise your rights, contact us using the details in Section 1. If you are a data subject named in our register-data index (see Section 4), please identify the company entry concerned.
Response time: we respond to requests under the GDPR without undue delay and at the latest within one month of receipt (Art. 12(3) GDPR). Where requests are particularly complex or numerous, the period may be extended by two further months; we will inform you of any extension and the reasons for it within one month of receipt.
22. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement.
If your main establishment is in Berlin, a relevant authority may be the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
23. Security Measures
We implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
24. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The current version is always available on our website. If changes materially affect you, we will provide appropriate notice.
25. Audience and Children
Our services are directed at business users (B2B). We do not market our services to children. We do not knowingly collect personal data about persons under 16. If you become aware that a child has provided us with personal data, please contact us using the details in Section 1 and we will take appropriate steps to delete it.
This statement concerns data about you as a website visitor or registered user. It does not change the way we process publicly filed register data, where the age of the persons named is determined by the register itself.