Privacy Policy
Data Protection at a Glance
Date: 19 July 2026
Version: Privacy-Policy-2026-07-19
General Information
The following information provides a simple overview of what happens to your personal data when you visit this website.
Personal data is any data by which you can be personally identified.
Detailed information on data protection can be found in the Privacy Policy set out below.
Data Collection on This Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find the operator’s contact details in the section “Information on the Controller”.
How do we collect your data?
Some of your data is collected when you provide it to us. This may, for example, include data you enter in a contact form or when booking an appointment.
Other data is collected automatically by our IT systems when you visit the website or after you have given your consent. This primarily includes technical data, such as your internet browser, operating system or the time at which a page is accessed. This data is collected automatically as soon as you enter this website.
What do we use your data for?
Some data is collected to ensure that the website is provided without errors.
We process other data in particular to handle enquiries, carry out free and paid website analyses, create and provide digital reports, process orders, payments, invoices and support requests and, subject to your consent, analyse usage behaviour and carry out marketing activities.
Automated analysis methods and AI-supported systems may be used for website analyses. In addition to the data you provide, technically and publicly accessible content from the website you specify may also be processed.
What rights do you have regarding your data?
You have the right at any time and free of charge to obtain information about the origin, recipients and purpose of your stored personal data.
You also have the right to request correction or deletion of this data.
If you have given consent to data processing, you may withdraw this consent at any time with effect for the future.
You also have the right, under certain circumstances, to request restriction of the processing of your personal data.
Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
You may contact us at any time regarding this or any other questions concerning data protection.
Analysis Tools and Third-Party Tools
When you visit this website, your browsing behaviour may be statistically evaluated. This is done primarily using analysis and tracking programs. We also use tools for appointment booking, error analysis, newsletter distribution, CRM systems and social media analysis.
Detailed information on these tools can be found in the following sections of this Privacy Policy.
Hosting and Technical Infrastructure
We use various hosting, cloud and infrastructure services to operate our website, portal and analysis platform.
External Hosting (Vercel)
We use Vercel to host and deliver our website and parts of our portal.
In particular, the following data may be processed: IP address, URL accessed, time of access, browser and device information, referrer, technical log data and data transmitted via the website or portal.
The processing is carried out to provide, secure and stabilise our online services and, where a contractual relationship or steps prior to entering into a contract are concerned, to take pre-contractual steps and perform the contract. The legal bases are Art. 6(1)(b) and (f) GDPR.
The provider is Vercel Inc., USA. Insofar as data is processed outside the European Economic Area, the transfer takes place in compliance with the statutory requirements governing transfers to third countries.
Google Cloud, Firebase and Firestore
We use services provided through the Google Cloud and Firebase platforms to operate our analysis platform and to store leads, analysis requests, reports, orders, payment statuses, consent and legal-text evidence, support cases and technical process and audit data.
These services include in particular Google Cloud Platform, Firebase, Firestore, Cloud Functions, Cloud Run, Cloud Storage, Cloud Tasks, Pub/Sub, Secret Manager and other services required for technical operation.
The following data may in particular be processed:
- contact and customer data,
- submitted website URLs,
- analysis and report data,
- payment and order statuses,
- tax and invoice information,
- legal-text versions and timestamps,
- support and communication data,
- technical log, job, security and audit data.
The legal bases are Art. 6(1)(b) GDPR for steps prior to entering into a contract and performance of a contract, Art. 6(1)(c) GDPR for statutory evidence obligations and Art. 6(1)(f) GDPR for security, stability, error analysis and prevention of misuse.
Strapi, Cloud Storage and Cloud SQL
We use a self-hosted Strapi content management system to manage and provide website, product and legal-text content. Content and media files may be stored in Google Cloud Storage and databases within the Google Cloud infrastructure.
In addition to public website content, account data of authorised editors and technical log data may also be processed. The legal basis is Art. 6(1)(f) GDPR.
General Information and Mandatory Disclosures
Data Protection
We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this Privacy Policy.
When you use this website, various personal data is collected. This Privacy Policy explains which data we collect and what we use it for. It also explains how and for what purpose this is done.
Please note that data transmission over the internet, for example when communicating by email, may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.
Information on the Controller
The controller within the meaning of the General Data Protection Regulation is:
Christian Salat
trading under the business name prokodo
Fritz-Erler-Straße 24b
81737 Munich
Germany
Telephone: +49 (0) 89 244 119 790
Email: info@prokodo.com
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.
Storage Period
Unless a more specific storage period is stated in this Privacy Policy, your personal data will remain with us until the purpose for the data processing no longer applies.
The following storage principles generally apply to the principal analysis and contractual processes:
- Free reports and access links: generally for up to twelve months from provision, unless earlier deletion is requested and there are no legitimate grounds for further storage.
- Lead and contact data that does not result in a business relationship: generally for up to twelve months after the last relevant contact or analysis, unless an objection or deletion request has been made.
- Paid reports: online access is deactivated twelve months after provision. This does not necessarily result in immediate deletion of the report record. Report content is subsequently deleted or anonymised as soon as no statutory, contractual or legitimate retention grounds remain.
- Order, contract, invoice, payment and tax data: stored in accordance with statutory commercial and tax-law retention obligations.
- Legal-text, consent and evidence data: stored for as long as required to meet legal evidence obligations or to establish, exercise or defend legal claims.
- Webhook, audit, security and error logs: stored only for as long as required for operational security, troubleshooting, prevention of misuse or legal defence.
- Support requests: stored until finally processed and thereafter within the scope of statutory or legitimate retention periods.
- Statutory retention obligations and the establishment, exercise or defence of legal claims remain unaffected.
If you make a legitimate deletion request or withdraw consent to data processing, your data will be deleted unless we have other legally permissible grounds for storage, for example tax-law or commercial-law retention periods. In the latter case, deletion takes place once those grounds no longer apply.
General Information on the Legal Bases for Data Processing on This Website
If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR where special categories of data within the meaning of Art. 9(1) GDPR are processed.
If you have consented to the storage of cookies or access to information on your terminal device within the meaning of § 25 TDDDG, the processing is additionally carried out on the basis of § 25(1) TDDDG.
If your data is required to perform a contract or take steps prior to entering into a contract, we process your data on the basis of Art. 6(1)(b) GDPR.
Where we are subject to legal obligations, processing is carried out on the basis of Art. 6(1)(c) GDPR.
In other cases, processing may be based on our legitimate interests under Art. 6(1)(f) GDPR, in particular for IT security, error analysis, prevention of misuse, improvement of our services, permissible B2B direct marketing and communication with existing customers.
Recipients of Personal Data
In the course of our business activities, we work with various external service providers, such as IT service providers, hosting providers, CRM providers, newsletter services and tracking and analysis tools.
Personal data is transferred only where:
- this is necessary to perform a contract under Art. 6(1)(b) GDPR,
- we are legally obliged to do so under Art. 6(1)(c) GDPR,
- a legitimate interest exists under Art. 6(1)(f) GDPR, or
- consent has been given under Art. 6(1)(a) GDPR.
Where external service providers process personal data on our behalf, we engage them on the basis of a contract or another permissible legal instrument under Art. 28 GDPR.
Transfers of Data to Third Countries
Some of the service providers we use, or their subprocessors, process personal data outside the European Union or the European Economic Area.
Data is transferred to a third country only if the statutory requirements of Art. 44 et seq. GDPR are met. Depending on the recipient, the transfer may in particular be based on:
- an adequacy decision of the European Commission,
- valid certification under the EU-US Data Privacy Framework,
- standard contractual clauses approved by the European Commission,
- supplementary technical and organisational safeguards, or
- a statutory derogation for specific individual cases.
The service providers involved in a specific processing operation are identified in the following sections of this Privacy Policy.
Further information about the safeguards used in each case may be requested from info@prokodo.com.
Withdrawal of Your Consent to Data Processing
Many data-processing operations are possible only with your express consent. You may withdraw consent already given at any time with effect for the future.
The lawfulness of processing carried out before the withdrawal remains unaffected by the withdrawal.
Right to Object Under Art. 21 GDPR
You have the right, on grounds relating to your particular situation, to object at any time to the processing of your personal data based on Art. 6(1)(e) or (f) GDPR. This also applies to profiling based on those provisions.
Where your personal data is processed for direct-marketing purposes, you have the right to object at any time to such processing.
Further details are set out in Art. 21 GDPR.
Right to Lodge a Complaint with the Competent Supervisory Authority
In the event of infringements of the GDPR, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement.
The data protection supervisory authority generally responsible for non-public bodies in Bavaria is:
Bavarian State Office for Data Protection Supervision – BayLDA
Promenade 18
91522 Ansbach
Germany
Irrespective of this, you may also contact a data protection supervisory authority at your habitual residence, place of work or the place of the alleged infringement.
Right to Data Portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract provided to you or to a third party in a commonly used, machine-readable format under Art. 20 GDPR.
Access, Rectification, Erasure and Restriction
Within the framework of the applicable statutory provisions, you have the right at any time and free of charge to obtain information about your stored personal data under Art. 15 GDPR, the right to rectification under Art. 16 GDPR, erasure under Art. 17 GDPR and restriction of processing under Art. 18 GDPR. You may contact us at any time regarding this or any other questions concerning personal data.
SSL or TLS Encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL or TLS encryption.
You can recognise an encrypted connection by “https://” and the padlock symbol in your browser’s address bar.
Objection to Advertising Emails
We object to the use of contact data published as part of our legal notice obligations for sending advertising that has not been expressly requested. We reserve the right to take legal action in the event of unsolicited advertising information being sent.
Data Collection on This Website
Consent Management
We use our own consent-management solution to allow you to select and subsequently change optional statistics, analysis and marketing services.
The consent categories you select are stored in a technically required cookie. In particular, the cookie contains information about which categories you have accepted or rejected. The storage period is generally six months.
The processing is carried out to store your selection, technically implement the decision you have made and avoid requesting it again whenever a page is accessed.
The legal bases are Art. 6(1)(c) GDPR insofar as the storage is required to meet data-protection evidence obligations, and Art. 6(1)(f) GDPR on the basis of our legitimate interest in user-friendly and legally compliant management of your selection. Access to the cookie required to store your selection is based on § 25(2) TDDDG.
Consent-dependent analysis and marketing services are activated only in accordance with the categories you have selected. You can change or withdraw your selection at any time through the cookie settings.
Technically required services and separately described security, error-analysis and operational services may be used independently of marketing or analysis consent where another statutory legal basis exists.
Cookies, Local Storage and Session Storage
Our website uses cookies and comparable storage technologies such as Local Storage and Session Storage.
Technically required cookies and storage may in particular serve the following purposes:
- storing your consent selection,
- storing language and display preferences,
- security and prevention of misuse,
- resuming an analysis process that has already been started,
- reopening a free report that has already been generated,
- associating an order process after returning from the payment service provider,
- storing an order access token during the browser session,
- providing personal report access.
In particular, we use:
- “cookie_settings” to store your consent selection, generally for six months,
- “theme_mode” to store your display preference, generally for one year,
- Session Storage entries to resume and associate a paid order process until the end of the relevant browser session,
- Local Storage entries to resume and reopen a free report until the entry is deleted or the report access expires.
- Technically required storage takes place on the basis of Art. 6(1)(b) or (f) GDPR and § 25(2) TDDDG.
Campaign and Attribution Information
Where you have given consent, we may process campaign and attribution information such as UTM parameters, referrers, Google click identifiers and analytics client IDs in a cookie or browser storage. This information is used to attribute website visits, enquiries and orders to marketing campaigns. The storage period is generally up to 90 days or, for Session Storage entries, until the end of the browser session.
The legal bases are Art. 6(1)(a) GDPR and § 25(1) TDDDG. Consent may be withdrawn at any time through the cookie settings.
Statistics, analysis and marketing cookies or comparable technologies requiring consent are used only after you have given your consent. The legal bases are Art. 6(1)(a) GDPR and § 25(1) TDDDG.
You may change or withdraw your selection at any time through the cookie settings. You may also delete cookies and locally stored information through your browser settings. Deleting technically required storage may mean that order processes already started or stored report access can no longer be reopened automatically.
Server, Application and Security Logs
When our website, portal or analysis platform is accessed, our hosting and infrastructure service providers automatically process technical log data.
This may in particular include:
- IP address,
- date and time of the request,
- URL accessed,
- referrer URL,
- browser type and browser version,
- operating system and device type,
- HTTP status code,
- volume of data transferred,
- technical request and response information,
- error, security and event data,
- job, webhook and process identifiers.
The processing is carried out to provide our systems securely and without technical errors, analyse errors, defend against attacks and misuse and ensure the traceability of technical processes.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest consists in the security, stability, absence of errors and prevention of misuse of our technical systems.
Where log data is required to carry out an analysis, order or support process, the processing is additionally based on Art. 6(1)(b) GDPR.
Log data is deleted or anonymised as soon as it is no longer required for the stated purposes and no statutory or legitimate retention grounds prevent this.
Free Website Analysis and Free Report
When you start a free website analysis, we process the website URL you provide and technical and publicly accessible content from the relevant website.
An analysis may initially be started without providing an email address. Where you later provide contact details, request that the report be sent to you or unlock further report content, we additionally process in particular:
- name,
- email address,
- telephone number, where provided,
- company,
- interests, objectives or project data provided,
- time and status of the analysis,
- delivery and unlock status.
The following data may in particular be processed as part of the website analysis:
- the submitted domain and technically discoverable URLs,
- publicly accessible HTML and text content,
- page titles, metadata and headings,
- structured data and markup,
- links and selected technical headers,
- performance, SEO, accessibility, content, UX and conversion signals,
- publicly visible names, roles and business contact details,
- information about the website technology used,
- findings, assessments, summaries and recommendations generated from this data.
Technical access is generally limited to publicly accessible content. Password-protected or internal areas are not specifically analysed.
The processing is carried out to perform the free website analysis requested by you on the basis of Art. 6(1)(b) GDPR.
Where personal data relating to other persons is publicly accessible on the analysed website, processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest consists in the technical performance of the analysis product requested by the user, quality assurance and creation of a meaningful report.
The Free Report is provided through an individual access link. This link contains a secret access element and must be treated as confidential. Persons who obtain access to the link may generally access the report without an additional user account.
Free reports and the associated access links are generally retained for up to twelve months from provision. Thereafter, access is deactivated and the report data is deleted or anonymised, unless statutory or legitimate storage grounds prevent this.
Contact details that have not resulted in a business relationship are generally stored for up to twelve months after the last relevant contact or analysis, unless an objection or deletion request has been made and there are no other legitimate grounds for further storage.
Paid Website Potential Analysis and Paid Report
When you order a paid Website Potential Analysis, we process the data required for the order, performance of the contract, payment processing, analysis and provision of the report.
This may in particular include:
- name and email address,
- company and billing address,
- declaration as to whether the order is placed as a consumer or entrepreneur,
- country and VAT identification number,
- submitted website or domain,
- booked product, price and currency,
- payment, authorisation, charge, refund and dispute status,
- tax and invoice information,
- payment service provider references,
- versions of the General Terms and Conditions, Privacy Policy and withdrawal documents displayed and incorporated,
- times of the order, display of legal texts, consent, authorisation and provision,
- technical analysis, draft and report data,
- report access, access status and expiry date,
- delivery, invoice and support status,
- audit, webhook and reconciliation data.
An order process is created before you are redirected to the payment service provider. The analysis begins after successful completion of the checkout and confirmed payment authorisation. The final charge is made only once a report that is contractually deliverable within the scope of the booked product has been created.
The processing is carried out to take steps prior to entering into a contract and to perform the contract on the basis of Art. 6(1)(b) GDPR.
Invoice, tax and legally required evidence data is additionally processed on the basis of Art. 6(1)(c) GDPR.
We process audit, security, misuse, webhook, refund, dispute and reconciliation data on the basis of Art. 6(1)(f) GDPR. Our legitimate interest consists in secure and traceable payment and contract processing, troubleshooting, avoiding duplicate charges and establishing or defending legal claims.
Personal online access to the Paid Report is available for twelve months from provision. After expiry, access is deactivated.
Deactivation of access does not necessarily result in immediate deletion of the report record. Report, order and evidence data may be stored beyond this period insofar as this is required for performance of the contract, troubleshooting, legal defence or statutory retention obligations.
Personal Data on Analysed Websites
Websites submitted by users or customers may contain publicly visible personal data.
This may, for example, include:
- names of authors, employees, managing directors or contacts,
- professional roles and team profiles,
- business email addresses and telephone numbers,
- photographs and profile information,
- customer comments and testimonials,
- information in legal notice, careers, blog or contact sections,
- other publicly published website content.
This data is not specifically collected on the basis of the identity of the persons concerned. However, it may be temporarily collected, analysed or processed as part of analysis results and reports during technical access to the website.
We do not intend to specifically analyse special categories of personal data within the meaning of Art. 9 GDPR, children’s data or extensive patient, applicant, employee or comparably sensitive data.
Users and customers may submit websites or areas containing such data for analysis only after prior consultation with prokodo.
Where personal data is not collected directly from the data subject, it generally originates from:
- the publicly accessible website specified by the user or customer,
- publicly accessible company websites,
- legal notice, careers, blog and contact pages,
- publicly accessible search results,
- business directories and research sources,
- specialised company and B2B data providers.
The processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interests consist in performing and improving our website-analysis products, quality assurance, company research and establishing B2B business relationships.
Where required by law, we additionally provide data subjects with the information under Art. 14 GDPR at the time of the first communication or within the statutory period. Statutory exceptions to the individual duty to provide information remain unaffected.
Contact Form
If you send us enquiries through the contact form, the information you provide, including the contact details you enter, such as name, email address and telephone number, is stored by us for the purpose of processing the enquiry and in case of follow-up questions.
The legal bases are:
- Art. 6(1)(b) GDPR where the enquiry relates to a contractual relationship or steps prior to entering into a contract,
- Art. 6(1)(f) GDPR based on our legitimate interest in efficiently processing enquiries,
- Art. 6(1)(a) GDPR where consent is requested.
The data remains with us until the purpose no longer applies or you request deletion. Statutory retention periods remain unaffected.
Telephone Verification Using Twilio Verify
For certain contact or project enquiries, we may verify the telephone number provided using Twilio Verify.
In particular, the following data may be processed:
- telephone number,
- verification code,
- time and status of the verification,
- technical request and security data.
The processing is carried out to process the enquiry and prevent automated or abusive submissions.
The legal bases are Art. 6(1)(b) GDPR where verification is required for a pre-contractual enquiry, and Art. 6(1)(f) GDPR. Our legitimate interest consists in securing our contact processes and preventing misuse.
The provider is a company within the Twilio group. Depending on the processing context, data may also be processed outside the European Economic Area.
IP and Misuse Checks Using MaxMind
To detect automated, abusive or fraudulent contact enquiries, we may check IP addresses and technical request data using MaxMind.
In particular, the following data may be processed:
- IP address,
- approximate geographical assignment,
- network and provider information,
- risk and reputation characteristics,
- technical request information.
The processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest consists in the security of our systems, defending against automated attacks and preventing abusive contact enquiries.
The provider is MaxMind, Inc., USA. Where data is transferred to the USA, this is done in compliance with the statutory requirements of Art. 44 et seq. GDPR.
Enquiries by Email or Telephone
If you contact us by email or telephone, we process your enquiry and the associated personal data to handle your request and for possible follow-up questions.
This may in particular include your name, contact details, the content and time of the communication and contract, order, report or support references.
The processing is carried out on the basis of Art. 6(1)(b) GDPR where the enquiry relates to a contract or steps prior to entering into a contract, and otherwise on the basis of Art. 6(1)(f) GDPR due to our legitimate interest in efficiently processing enquiries.
The data is deleted as soon as it is no longer required for processing and no statutory or legitimate retention grounds prevent this.
Appointment Booking via Calendly
On our website, we offer you the option of booking appointments online. For this purpose, we use the Calendly service provided by Calendly LLC, 271 17th St NW, Ste 1000, Atlanta, GA 30363, USA.
When you book an appointment via Calendly, the data you enter, such as your name, email address and appointment topic, is transmitted to and processed by Calendly. Technical data such as your IP address, browser and device information and time zone may also be processed.
The data is processed for appointment scheduling and management on the basis of Art. 6(1)(b) GDPR in connection with a contract or steps prior to entering into a contract.
Insofar as Calendly uses cookies or tracking, this takes place only with your consent under Art. 6(1)(a) GDPR and § 25 TDDDG.
As Calendly is based in the USA, data may be transferred to the USA. Such transfers take place on the basis of standard contractual clauses under Art. 46 GDPR. A residual risk of access by US authorities cannot be completely excluded.
Use of Artificial Intelligence and OpenAI
We use AI-supported systems in particular for the following processes:
- creating and drafting Free and Paid Report content,
- evaluating and structuring technical analysis results,
- generating recommendations for action, Work Orders and implementation guidance,
- classifying and prioritising technical signals,
- company and lead research,
- assisting with the processing of enquiries.
For this purpose, we use in particular API services provided by OpenAI.
For customers based in the European Economic Area, the contracting party for OpenAI business and API services is generally:
OpenAI Ireland Limited
1st Floor, The Liffey Trust Centre
117–126 Sheriff Street Upper
Dublin 1, D01 YC43
Ireland
Depending on the processing operation, the following data in particular may be transmitted to OpenAI:
- submitted website URLs,
- selected technical findings and metrics,
- structured analysis and context data,
- limited excerpts from publicly accessible website content,
- publicly visible company and business contact data,
- search and research results,
- contents of enquiries where AI is used for processing.
For Free and Paid Reports, we generally transmit selected evidence, signal and context data required for the analysis. Complete raw website content is not transmitted to the AI provider in every processing step.
For company and lead research, limited publicly accessible text excerpts, search results and business company and contact data may be processed.
The processing is carried out to perform the requested analysis and fulfil the contract on the basis of Art. 6(1)(b) GDPR.
Where publicly accessible third-party data, company research or the improvement and quality assurance of our services is concerned, the processing is carried out on the basis of Art. 6(1)(f) GDPR.
An individual manual review of every automatically generated report does not necessarily take place.
As part of the website analyses described, we do not make decisions based solely on automated processing that produce legal effects concerning a data subject or similarly significantly affect them.
Insofar as OpenAI processes data on our behalf, it is engaged on the basis of a data processing agreement. Transfers to third countries take place in compliance with Art. 44 et seq. GDPR.
Google PageSpeed Insights and Lighthouse Data
We use Google PageSpeed Insights and the Lighthouse data made available through it for technical performance analysis.
The publicly accessible URL to be analysed is transmitted to Google.
Google may in particular process the following data:
- the URL to be analysed,
- IP and technical request data relating to our systems,
- time and parameters of the analysis,
- technical performance and diagnostic data.
We receive from Google in particular metrics and diagnostic data relating to loading times, Core Web Vitals, rendering, resource usage and technical optimisation opportunities.
The processing is carried out to perform the website analysis requested by the user on the basis of Art. 6(1)(b) GDPR.
Where the URL or analysed website contains personal data relating to third parties, the processing is additionally carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest consists in technically creating the requested report.
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Data may also be processed outside the European Economic Area by companies within the Google group.
Stripe Checkout, Stripe Tax, Payment Processing and Invoices
We use Stripe Checkout, Stripe Tax and Stripe invoicing functions for paid website analyses.
Depending on the specific service and processing operation, the following Stripe companies may in particular be involved:
- Stripe Payment Europe, Limited, Ireland,
- Stripe Technology Company, Limited, Ireland,
- other regulated or technical companies within the Stripe group.
The following data in particular may be transmitted to or collected by Stripe as part of the checkout and payment process:
- name and email address,
- billing address and country,
- company and VAT identification number,
- product, price, currency and tax amount,
- payment method and payment status,
- authorisation, charge, refund and dispute data,
- checkout, customer, PaymentIntent, charge, refund and invoice references,
- IP address, browser, device, security and fraud-prevention data.
Complete card data is generally collected directly by Stripe and is not stored in our own systems.
Stripe is used in particular to:
- provide the checkout,
- authorise the payment amount,
- execute the final charge after successful report creation,
- process taxes and VAT information,
- take VAT identification numbers and tax information into account,
- process refunds and payment disputes,
- provide electronic invoice and payment documents.
The processing is carried out on the basis of Art. 6(1)(b) GDPR for contract and payment processing, Art. 6(1)(c) GDPR for tax-law and invoicing obligations and Art. 6(1)(f) GDPR for fraud prevention, security, refunds, reconciliation and dispute handling.
Depending on the respective processing operation, Stripe may act as a processor, independent controller or jointly with other Stripe companies.
Insofar as data is processed outside the European Economic Area, the transfer takes place in compliance with Art. 44 et seq. GDPR.
Sending Transactional, Report and Support Emails via AWS SES
We use Amazon Simple Email Service – AWS SES – to send transactional emails.
The provider for AWS accounts maintained in Europe is generally:
Amazon Web Services EMEA SARL
38 Avenue John F. Kennedy
L-1855 Luxembourg
The following messages in particular may be sent via AWS SES:
- Free Report notifications,
- order and authorisation confirmations,
- report-provision emails,
- invoice emails,
- notifications concerning failed analyses or released authorisations,
- refund and support messages.
The following data in particular is processed:
- email address,
- name, where available,
- language,
- order, report or support reference,
- report or invoice link,
- time and status of delivery,
- message content,
- technical delivery and error messages,
- provider message identifiers.
The processing is carried out to perform the contract on the basis of Art. 6(1)(b) GDPR.
For support, security and error communications, the processing is additionally carried out on the basis of Art. 6(1)(f) GDPR.
Where legally required invoice or contract information is sent, the processing is also carried out on the basis of Art. 6(1)(c) GDPR.
Insofar as data is processed outside the European Economic Area, the transfer takes place in compliance with Art. 44 et seq. GDPR.
HubSpot CRM System
We use the HubSpot CRM system, a service provided by HubSpot Ireland Limited, 2nd Floor, 30 North Wall Quay, Dublin 1, Ireland, to manage contacts, track communications, send certain emails and, where applicable, evaluate interactions.
Data processed may include:
- contact details such as name, email address and telephone number,
- information concerning enquiries and interests,
- communication content and times,
- website activity where you have given consent, including tracking cookies.
The legal bases are:
- Art. 6(1)(b) GDPR for steps prior to entering into a contract and performance of a contract,
- Art. 6(1)(f) GDPR based on our interest in efficiently organising our business and communication processes,
- Art. 6(1)(a) GDPR insofar as tracking and marketing functions are based on consent.
HubSpot may transfer data to third countries, in particular the USA. Where such a transfer takes place, we base it on EU standard contractual clauses under Art. 46 GDPR. A residual risk of access by foreign authorities cannot be completely excluded.
Company Research, Data Enrichment and External Research Providers
To research, supplement and quality-check business company and contact data and to supplement website reports, we may use publicly accessible sources and specialised search, crawling, market and B2B data providers.
These may in particular include:
- Serper,
- Firecrawl,
- DataForSEO,
- Apollo,
- Lusha,
- People Data Labs,
- Dropcontact,
- RocketReach,
- Hunter,
- ZeroBounce,
- publicly accessible company websites,
- legal notice, careers and contact pages,
- search results,
- industry and company directories,
- publicly accessible company and register information.
Serper, Firecrawl and DataForSEO may in particular be used to supplement Free or Paid Reports with search, market, keyword or publicly accessible website information.
Apollo, Lusha, People Data Labs, Dropcontact, RocketReach, Hunter and ZeroBounce may in particular be used to research or supplement business company, contact-person and contact data or to check its business reachability.
Depending on the use case, the following data in particular may be processed:
- company name and domain,
- industry and company size,
- location and business address,
- publicly named employees and contacts,
- professional role and employer,
- business email address,
- business telephone number,
- publicly accessible company and website information,
- search terms and research parameters,
- email validation and reachability status,
- source, currency and confidence of the data.
The processing serves:
- to supplement and quality-check lead and company data,
- to identify appropriate business contacts,
- to verify business reachability,
- to create company, market and search information,
- to supplement Free and Paid Reports,
- to establish B2B business relationships.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests consist in data quality, improving our analysis products, researching business contacts and establishing B2B business relationships.
The processing is not intended to research private contact details for consumer advertising.
Data subjects may object at any time to the processing of their personal data for direct-marketing purposes. Following an objection, the data will no longer be used for direct marketing.
Where personal data was not collected directly from the data subject, we inform the data subject in accordance with Art. 14 GDPR unless a statutory exception to the individual duty to provide information applies.
The providers may process data outside the European Economic Area. Where required, transfers to third countries take place in compliance with Art. 44 et seq. GDPR.
As the activation and specific selection of individual providers may depend on the purpose of the analysis, availability, data situation and technical configuration, not every provider listed is used in every process.
Jira Cloud and Optional Report Exports
Where a customer expressly activates and authorises a corresponding export function, selected report content may be transferred to Jira Cloud.
The following data in particular may be processed:
- Jira site and project information,
- OAuth and connection data,
- selected findings,
- task and measure descriptions,
- acceptance criteria,
- priorities, labels and roadmap information,
- report, project and user references,
- technical status and error data.
The transfer takes place only after express authorisation by the customer.
The legal basis is Art. 6(1)(b) GDPR insofar as the export function forms part of the product used by the customer or a separately selected function.
Where security, audit and error data is processed, this is additionally based on Art. 6(1)(f) GDPR.
The provider is a company within the Atlassian group. Depending on the Atlassian region selected by the customer and the technical processing, data may also be processed outside the European Economic Area.
Jira Cloud is not a necessary component of creating and providing the website report.
Newsletters and Mailings via Mailchimp
If you subscribe to our newsletter, your data is processed for delivery and evaluation of the newsletter.
For delivery, we use Mailchimp, a service provided by Intuit Inc., 2700 Coast Ave, Mountain View, CA 94043, USA, or the competent European entity.
Data processed:
- email address,
- name, where applicable,
- time of registration and, where used, the time and evidence of double opt-in confirmation,
- information on opens and click behaviour through tracking pixels and individual links.
The legal basis is your consent under Art. 6(1)(a) GDPR and § 25 TDDDG. You may withdraw consent at any time with effect for the future, for example through the unsubscribe link in the newsletter.
Mailchimp may transfer data to the USA. The legal basis is standard contractual clauses under Art. 46 GDPR. A residual risk of access by US authorities cannot be excluded.
Error and Performance Monitoring with Bugsnag
We use Bugsnag, a service provided by the SmartBear group, to identify, analyse and remedy technical errors.
The following data in particular may be processed:
- error messages and stack traces,
- URLs and technical routes accessed,
- time of the error,
- browser type and browser version,
- operating system and device type,
- technical request and response data,
- IP address or technical information derived from it, depending on configuration,
- technical user, session or process identifiers,
- information about the state of the application when the error occurred.
The processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest consists in the security, stability, absence of errors and technical improvement of our website and applications.
We limit the data transmitted to Bugsnag to the information required for error analysis, stability and security. Depending on the affected application, the error context and the respective technical configuration, it cannot be completely excluded that URLs, technical identifiers or other error-context data may relate to a person. Form entries and confidential content are not intended to be transmitted to Bugsnag.
Bugsnag is not used for advertising or marketing purposes.
Where Bugsnag or integrated components store information on your terminal device or access such information and this storage is not strictly necessary, this takes place only with your consent under § 25(1) TDDDG.
Processing outside the European Economic Area cannot be excluded. Transfers to third countries take place in compliance with Art. 44 et seq. GDPR.
Analysis and Marketing Tools
Vercel Web Analytics
We use Vercel Web Analytics to statistically evaluate and improve our website.
The following data in particular may be processed:
- page path accessed,
- time of page access,
- referrer,
- approximate country or region,
- browser,
- operating system,
- device type,
- technical event and usage data,
- event names defined by us.
According to the provider, Vercel Web Analytics is designed to provide aggregated usage statistics without traditional persistent third-party tracking cookies.
The processing is carried out on the basis of Art. 6(1)(f) GDPR insofar as the analysis is performed without storage or identification requiring consent. Our legitimate interest consists in statistically evaluating and improving our online service.
Where information is stored on or read from your terminal device in the specific implementation, or where personal usage analysis goes beyond this, processing takes place only with your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG.
The provider is Vercel Inc., USA. Insofar as data is processed outside the European Economic Area, the transfer takes place in compliance with Art. 44 et seq. GDPR.
Microsoft Clarity
Where you have consented to statistics and analysis functions, we use Microsoft Clarity to better understand use of our website and improve usability.
Clarity may in particular process the following data:
- page views,
- click and scroll behaviour,
- mouse and touch interactions,
- session sequences,
- browser, device and operating-system information,
- approximate geographical information,
- referrer and URLs accessed,
- technical event and performance data.
Input fields and sensitive content are masked or excluded from recording insofar as this can be technically configured.
The legal basis is your consent under Art. 6(1)(a) GDPR and, insofar as information on your terminal device is accessed, § 25(1) TDDDG.
Consent may be withdrawn at any time through the cookie settings.
For customers in the European Union, the competent contracting entity is generally Microsoft Ireland Operations Limited, Ireland. Data may also be processed outside the European Economic Area within the Microsoft group. Transfers to third countries take place in compliance with Art. 44 et seq. GDPR.
Google Tag Manager
We use Google Tag Manager provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, for the technical management and control of integrated tags and events.
Technical connection data may be processed when Tag Manager is loaded. Tag Manager also receives event and context data transferred by our website to the data layer.
The additional data processed depends on the services and tags activated through Tag Manager.
Analysis and marketing tags requiring consent are activated only in accordance with the selection you make in consent management. Before corresponding consent is given, the relevant Consent Mode categories are generally set to “denied”.
The legal basis for technical management is Art. 6(1)(f) GDPR. Our legitimate interest consists in the efficient, secure and consistent management of integrated services.
For analysis and marketing tags requiring consent, the legal bases are Art. 6(1)(a) GDPR and § 25(1) TDDDG.
Data may also be processed outside the European Economic Area within the Google group. Transfers to third countries take place in compliance with Art. 44 et seq. GDPR.
Google Analytics
We use Google Analytics 4, a web-analysis service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Where you have consented to the use of statistics and analysis services, the following data in particular may be processed:
- pages accessed and events,
- session duration and interactions,
- referrer and campaign information,
- browser, device and operating-system information,
- approximate location,
- a randomly generated client ID,
- event and conversion data defined by us.
Google Analytics may use its own cookies, in particular the “_ga” cookie, to recognise browsers. Such an analytics cookie is set only if corresponding consent has been given.
For access from the European Union, Switzerland and the United Kingdom, Google uses the IP address during data collection to derive approximate location information. According to Google, the IP address is discarded before the analytics data is logged or stored.
We use Google Consent Mode. If consent to analytics storage has been denied, no analytics cookies are set or read. Depending on the Consent Mode configuration used, limited signals may be transmitted to Google without cookies and without a persistent user identifier. These may in particular include consent status, basic technical information and aggregatable event information.
Processing using cookies and persistent identifiers takes place exclusively on the basis of your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG. You may withdraw your consent at any time through the cookie settings.
Insofar as data is processed outside the European Economic Area within the Google group, the transfer takes place in compliance with Art. 44 et seq. GDPR.
Google Ads & Google Conversion-Tracking
We use Google Ads to advertise our services in Google Search and within the Google advertising network and to evaluate the success of our advertising campaigns.
Where you have given consent, Google and we may determine whether certain actions are taken after an advertisement is clicked, for example starting a website analysis, submitting an enquiry or completing an order.
The following data in particular may be processed:
- Google click identifiers and campaign information,
- pages accessed,
- conversion events,
- time and value of a conversion,
- browser, device and technical information,
- cookie and analytics identifiers.
Advertising and conversion cookies and personal or pseudonymous attribution take place only with your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG.
If consent is denied, no advertising cookies requiring consent are set. Depending on the Consent Mode configuration used, limited signals may be transmitted to Google without cookies and used for aggregated conversion modelling. These signals are not used by prokodo to create remarketing lists or individual advertising profiles.
You may withdraw consent at any time through the cookie settings.
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Transfers to third countries within the Google group take place in compliance with Art. 44 et seq. GDPR.
Google Ads Remarketing
Our website uses Google Ads Remarketing functions. These allow us to target users who have previously visited our website on other websites within the Google advertising network with interest-based advertising.
For this purpose, Google uses cookies or comparable technologies. The legal basis is your consent under Art. 6(1)(a) GDPR and § 25 TDDDG.
LinkedIn and LinkedIn Insight Tag
LinkedIn Insight Tag
Our website uses the LinkedIn Insight Tag, a service provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.
With the Insight Tag, we can track the behaviour of visitors who reached our website through LinkedIn advertisements, including conversion tracking, reach measurement and retargeting.
Data collected:
- truncated IP address,
- device and browser characteristics,
- page views,
- referrer URL,
- timestamps.
The data is transmitted to LinkedIn and, depending on the technical configuration, pseudonymised, aggregated or linked with existing LinkedIn account data. If you are logged in to LinkedIn, LinkedIn may associate the processing with your LinkedIn account.
The legal basis is your consent under Art. 6(1)(a) GDPR and § 25 TDDDG.
You may withdraw your consent at any time and adjust the corresponding advertising settings in your LinkedIn profile.
LinkedIn Profile / Company Page
We maintain a profile or company page on LinkedIn to communicate with customers, prospective customers, business partners and applicants and to provide information about our services.
When you visit our LinkedIn page, personal data is processed by LinkedIn and, where applicable, by us.
In this respect, we are often joint controllers with LinkedIn under Art. 26 GDPR, in particular in relation to “Page Insights”. LinkedIn provides the corresponding information.
Primary responsibility for processing your data on LinkedIn lies with LinkedIn. You may exercise your rights, including access and erasure, both against LinkedIn and against us.
Social Media Profiles in General
In addition to LinkedIn, we may maintain other profiles on social networks and platforms, such as Meta, Instagram and X, to communicate with users active there and inform them about our company.
When the respective networks are accessed, the terms and privacy information of the respective operators apply.
We process your data if you communicate with us through these platforms, for example through messages, comments or likes.
The legal basis is Art. 6(1)(b) GDPR in connection with steps prior to entering into a contract or a contractual relationship, or Art. 6(1)(f) GDPR for our public presence and communication with the public.
Processing on Behalf of Business Customers
As part of a website analysis, personal data publicly accessible on the website specified by the business customer may be processed.
Whether prokodo acts as an independent controller or as a processor for the business customer depends in particular on the specific content, purposes, instructions and usage scenarios.
Insofar as prokodo processes personal data exclusively on behalf of and in accordance with documented instructions from a business customer and the requirements of Art. 28 GDPR are met, prokodo and the business customer enter into a data processing agreement before the corresponding processing begins.
prokodo makes the agreement available to the business customer during the pre-contractual process or upon request.
The agreement governs in particular:
- the subject matter and duration of processing,
- the nature and purpose of processing,
- categories of personal data and data subjects,
- the customer’s rights to issue instructions,
- confidentiality and technical and organisational measures,
- engagement of additional processors,
- assistance with data-subject rights,
- deletion and return of data,
- audit and evidence obligations.
Insofar as prokodo processes data for its own purposes, in particular for contract processing, billing, prevention of misuse, product improvement or its own company and lead research, such processing does not take place exclusively on behalf of the customer.
Language Versions of the Website
Our website may be available in multiple languages, including German and, where applicable, English.
Where you select another language version, we process the corresponding setting, for example through a cookie or browser setting.
The legal basis is Art. 6(1)(f) GDPR based on our legitimate interest in user-friendly presentation of our online service.
Currency and Amendment of This Privacy Policy
This Privacy Policy applies from** 19 July 2026**. The continued development of our website, analysis products and technical service providers may require this Privacy Policy to be amended. The current version is available on this website.




