GDPR Compliant

GDPR Compliant

Privacy Policy

Privacy Policy

§ 1 Controller and Contact

1.1 The controller responsible for the processing of personal data on this website and within the Pakera platform is:

1.1 The controller responsible for the processing of personal data on this website and within the Pakera platform is:

Pakera AI Packaging Optimization GmbH
Brunnenweg 35
83666 Waakirchen, Germany
Email: info@pakera.com
Phone: +49 8021 2089090
Website: www.pakera.com
Managing Directors: Thomas Goldhofer, Ali Yelsali

Pakera AI Packaging Optimization GmbH
Brunnenweg 35
83666 Waakirchen, Germany
Email: info@pakera.com
Phone: +49 8021 2089090
Website: www.pakera.com
Managing Directors: Thomas Goldhofer, Ali Yelsali

1.2 For all data protection-related enquiries, please contact our Data Protection Officer at: privacy@pakera.com

1.3 Our Privacy Policy can be downloaded here.

1.2 For all data protection-related enquiries, please contact our Data Protection Officer at: privacy@pakera.com

1.3 Our Privacy Policy can be downloaded here.

§ 2 General Information on Data Processing

We process personal data only to the extent necessary to provide a fully functional website and our SaaS platform Pakera, as well as our content and services, or where another legal basis exists. Pakera is intended exclusively for businesses (B2B).

The legal bases for processing are, in particular:

  • Art. 6(1)(b) GDPR – Performance of a contract and pre-contractual measures (e.g., registration, provision of services, billing);

  • Art. 6(1)(c) GDPR – Compliance with legal obligations (e.g., retention requirements under commercial and tax law);

  • Art. 6(1)(f) GDPR – legitimate interests (e.g., security, operations, audience measurement, direct marketing in the B2B sector);

  • Art. 6(1)(a) GDPR – Consent (e.g., non-essential cookies, certain analytics/marketing tools, newsletters).

To the extent that we use non-essential cookies or comparable technologies, this is based on your consent pursuant to Section 25(1) of the German Telemedia Act (TDDDG) in conjunction with Article 6(1)(a) of the GDPR.

§ 3 Provision of the Website and Server Log Files

Each time you visit our website, our system automatically collects data and information about the device used to access the site, including, in particular, the IP address, the date and time of access, the page or file accessed, the amount of data transferred, the referrer URL, the browser type and version, and the operating system.

This data is stored in log files to ensure the delivery of the website, the stability and security of the system, and error analysis. The legal basis is Article 6(1)(f) of the GDPR. The log files are deleted after 30 days, unless they are required for security purposes for a longer period.

The platform’s core functions are hosted in Germany. A data processing agreement is in place with the hosting provider.

Each time you visit our website, our system automatically collects data and information about the device used to access the site, including, in particular, the IP address, the date and time of access, the page or file accessed, the amount of data transferred, the referrer URL, the browser type and version, and the operating system.

This data is stored in log files to ensure the delivery of the website, the stability and security of the system, and error analysis. The legal basis is Article 6(1)(f) of the GDPR. The log files are deleted after 30 days, unless they are required for security purposes for a longer period.

The platform’s core functions are hosted in Germany. A data processing agreement is in place with the hosting provider.

§ 4 Login, Registration, Customer Account, and Use of the Platform

Registration is required to use Pakera (beyond the limited use available without registration). In connection with registration and during use, we process, in particular, your name, business email address, password (encrypted), phone number, address, job title, company name, industry, company size, company website, sales channel of the initial contact (e.g., LinkedIn, YouTube), and—for paid subscriptions—the VAT ID number, as well as usage, log, and device/browser data. During registration, authentication data (e.g., email, login credentials, security features) is processed.

Purposes: Provision and management of the account, authentication, performance of contractual services, user and rights management, security, and billing.

Legal basis: Art. 6(1)(b) and (f) of the GDPR. To the extent that processing takes place in a third country, it is safeguarded by appropriate measures such as EU Standard Contractual Clauses and/or, where applicable, the EU-U.S. Data Privacy Framework.

Content on the Platform (Processing on Behalf of a Client): We process uploaded content, including CAD data, documents, entries, comments, and approval data, on behalf of the respective client based on the Data Processing Agreement (DPA). The respective client is the data controller for this. Customer content is not used to train AI models. During the approval process, you can send a secure link (with an OTP) to internal and/or external individuals. In doing so, we process the data required for delivery (e.g., email address) as well as any comments submitted.

Login & Security: Hanko (Hanko GmbH) is used to ensure the necessary security during login.

Legal basis: Art. 6(1)(b) and (c) of the GDPR. Hanko’s privacy policy applies in addition.

Registration is required to use Pakera (beyond the limited use available without registration). In connection with registration and during use, we process, in particular, your name, business email address, password (encrypted), phone number, address, job title, company name, industry, company size, company website, sales channel of the initial contact (e.g., LinkedIn, YouTube), and—for paid subscriptions—the VAT ID number, as well as usage, log, and device/browser data. During registration, authentication data (e.g., email, login credentials, security features) is processed.

Purposes: Provision and management of the account, authentication, performance of contractual services, user and rights management, security, and billing.

Legal basis: Art. 6(1)(b) and (f) of the GDPR. To the extent that processing takes place in a third country, it is safeguarded by appropriate measures such as EU Standard Contractual Clauses and/or, where applicable, the EU-U.S. Data Privacy Framework.

Content on the Platform (Processing on Behalf of a Client): We process uploaded content, including CAD data, documents, entries, comments, and approval data, on behalf of the respective client based on the Data Processing Agreement (DPA). The respective client is the data controller for this. Customer content is not used to train AI models. During the approval process, you can send a secure link (with an OTP) to internal and/or external individuals. In doing so, we process the data required for delivery (e.g., email address) as well as any comments submitted.

Login & Security: Hanko (Hanko GmbH) is used to ensure the necessary security during login.

Legal basis: Art. 6(1)(b) and (c) of the GDPR. Hanko’s privacy policy applies in addition.

§ 5 Payment Processing

Payments are processed via Stripe (Stripe Payments Europe, Ltd.). For paid bookings, the data required for payment (e.g., name, billing information, VAT ID, payment method information) is processed. Payment method data is processed directly by Stripe; we do not store complete payment data.

Legal basis: Article 6(1)(b) and (c) of the GDPR. Stripe’s privacy policy applies in addition.

DATEV Interface: Fizard (Fizard GmbH) is used for the automated processing of payments and transactions. For transactions involving fees, the data required for payment (e.g., name, billing information, VAT ID, payment method information) is processed. Payment method data is processed directly by Fizard; we do not store complete payment data.

Legal basis: Art. 6(1)(b) and (c) of the GDPR. Fizard’s privacy policy applies in addition.

Accounting: We use DATEV eG (Germany) for invoicing and accounting.

Legal basis: Art. 6(1)(b) and (c) of the GDPR. DATEV’s privacy policy applies in addition.

Payments are processed via Stripe (Stripe Payments Europe, Ltd.). For paid bookings, the data required for payment (e.g., name, billing information, VAT ID, payment method information) is processed. Payment method data is processed directly by Stripe; we do not store complete payment data.

Legal basis: Article 6(1)(b) and (c) of the GDPR. Stripe’s privacy policy applies in addition.

DATEV Interface: Fizard (Fizard GmbH) is used for the automated processing of payments and transactions. For transactions involving fees, the data required for payment (e.g., name, billing information, VAT ID, payment method information) is processed. Payment method data is processed directly by Fizard; we do not store complete payment data.

Legal basis: Art. 6(1)(b) and (c) of the GDPR. Fizard’s privacy policy applies in addition.

Accounting: We use DATEV eG (Germany) for invoicing and accounting.

Legal basis: Art. 6(1)(b) and (c) of the GDPR. DATEV’s privacy policy applies in addition.

§ 6 Support

For support requests submitted via our internal ticket system, by email, or by phone, we process the data you provide (e.g., name, contact information, content of the request, and any attached screenshots) to address your inquiry.

Legal basis: Art. 6(1)(b) and (f) of the GDPR.

For support requests submitted via our internal ticket system, by email, or by phone, we process the data you provide (e.g., name, contact information, content of the request, and any attached screenshots) to address your inquiry.

Legal basis: Art. 6(1)(b) and (f) of the GDPR.

§ 7 Cookies and Similar Technologies

We use cookies and similar technologies. Technically necessary cookies are required for the operation of the website/platform (legal basis: § 25(2) TDDDG, Art. 6(1)(f) GDPR). We use non-essential cookies as well as analytics and marketing technologies only with your consent via our consent management system (Section 25(1) TDDDG, Article 6(1)(a) GDPR). You may revoke your consent at any time with future effect via the consent management system. Further information can be found in the consent management system.

Cookies: To obtain, manage, and document your consent to the use of non-essential cookies and similar technologies, as well as to control your cookie settings, we use the consent management system “Cookiebot by Usercentrics.”

Legal basis: Article 6(1)(b) and (c) of the GDPR. Cookiebot’s privacy policy applies in addition.

We use cookies and similar technologies. Technically necessary cookies are required for the operation of the website/platform (legal basis: § 25(2) TDDDG, Art. 6(1)(f) GDPR). We use non-essential cookies as well as analytics and marketing technologies only with your consent via our consent management system (Section 25(1) TDDDG, Article 6(1)(a) GDPR). You may revoke your consent at any time with future effect via the consent management system. Further information can be found in the consent management system.

Cookies: To obtain, manage, and document your consent to the use of non-essential cookies and similar technologies, as well as to control your cookie settings, we use the consent management system “Cookiebot by Usercentrics.”

Legal basis: Article 6(1)(b) and (c) of the GDPR. Cookiebot’s privacy policy applies in addition.

§ 8 Web Analytics, Tracking, and Marketing

To the extent that the following services process personal data and are not strictly technically necessary, we use them only on the basis of your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). For services provided by U.S. providers, data may be transferred to the United States, protected by EU Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework.

  • Google Analytics 4 (GA4) (Google, LLC) – Audience/usage analysis;
    Google Tag Manager – Tag management (does not process personal data itself, but loads tags);

  • Google Search Console – Analysis of visibility in Google Search;

  • Google Ads – conversion tracking and advertising;

  • Microsoft Clarity – Reach/usage analysis;
    Legal basis: Art. 6(1)(b) and (c) of the GDPR. Google’s privacy policy applies in addition.

  • Framer (Framer B.V.) – Website hosting – reach and usage analysis;
    Legal basis: Art. 6(1)(b) and (c) of the GDPR. Framer’s privacy policy applies in addition.

  • LinkedIn (LinkedIn, Inc.) (Insight Tag / Conversion Tracking) – Reach and conversion measurement;
    Legal basis: Art. 6(1)(b) and (c) of the GDPR. LinkedIn’s privacy policy applies in addition.

  • YouTube (Insight Tag / Conversion Tracking) – Reach and conversion measurement;
    Legal basis: Art. 6(1)(b) and (c) of the GDPR. Google’s privacy policy applies in addition.

  • Facebook (Meta Platforms, Inc.) (Insight Tag / Conversion Tracking) – Reach and conversion measurement;
    Legal basis: Art. 6(1)(b) and (c) of the GDPR. Facebook’s privacy policy applies in addition.

  • X (X Corp.) (Insight Tag / Conversion Tracking) – Reach and conversion measurement;
    Legal basis: Article 6(1)(b) and (c) of the GDPR. The X’s privacy policy apply in addition.

  • PostHog (PostHog, Inc.) – usage analytics;
    Legal basis: Art. 6(1)(b) and (c) of the GDPR. PostHog’s privacy policy applies in addition.

  • Tella (Tella HQ, Inc.) – Video content management – Reach/usage analysis;
    Legal basis: Article 6(1)(b) and (c) of the GDPR. Tella’s privacy policy applies in addition.

  • HubSpot (HubSpot Germany GmbH) – CRM – reach/usage analysis, newsletters;
    Legal basis: Art. 6(1)(b) and (c) of the GDPR. HubSpot’s privacy policy applies in addition.

§ 9 Appointment Scheduling and Webinars

  • HubSpot (HubSpot Germany GmbH): Online appointment scheduling; the data provided for scheduling appointments is processed.
    Legal basis: Art. 6(1)(b) and (c) of the GDPR. HubSpot’s privacy policy applies in addition.

  • Livestorm SAS: Conducting webinars/online meetings; participation and contact data are processed.
    Legal basis: Art. 6(1)(b) and (c) of the GDPR. Livestorm’s privacy policy applies in addition.

For services provided by U.S. providers, data may be transferred to the United States, protected by EU Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework.

§ 10 Direct Marketing, Newsletters, and Sales Outreach (B2B)

In a B2B context, we contact potential business customers for promotional purposes and may send newsletters. The legal basis is—depending on the circumstances—your consent (Art. 6(1)(a) GDPR; for email marketing, § 7 UWG) or our legitimate interest in direct marketing (Art. 6(1)(f) GDPR), subject to statutory limitations. To organize sales and campaigns, we use, among other things:

  • FooMonk LLC (Instantly) – sales outreach (email) and newsletter distribution;
    Legal basis: Art. 6(1)(b) and (c) of the GDPR. Instantly’s privacy policy applies in addition.

  • HubSpot (HubSpot Germany GmbH) – CRM, customer and prospect management;
    Legal basis: Art. 6(1)(b) and (c) of the GDPR. HubSpot’s privacy policy applies in addition.

  • Social networks (e.g., LinkedIn, YouTube, Facebook, Reddit, Quora) for marketing purposes (see Section 8 for links).

  • Brevo GmbH – Transactional emails
    Legal basis: Art. 6(1)(b) and (c) of the GDPR. Brevo’s privacy policy applies in addition.

Right to Object: You may object at any time to the processing of your data for direct marketing purposes (Article 21(2) of the GDPR); thereafter, your data will no longer be processed for these purposes. You may withdraw any consent you have given at any time with future effect.

§ 11 Security (Captcha, DDoS Protection)

To protect against misuse and attacks, we implement security measures, which may include a CAPTCHA service, such as hCaptcha/Cloudflare Turnstile, and DDoS protection via OVHCloud and/or Cloudflare.

Legal basis: Art. 6(1)(f) of the GDPR (security and operations). When using service providers outside the EU, data is transferred on the basis of appropriate safeguards, secured by EU Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework. Cloudflare’s Privacy Policy

To protect against misuse and attacks, we implement security measures, which may include a CAPTCHA service, such as hCaptcha/Cloudflare Turnstile, and DDoS protection via OVHCloud and/or Cloudflare.

Legal basis: Art. 6(1)(f) of the GDPR (security and operations). When using service providers outside the EU, data is transferred on the basis of appropriate safeguards, secured by EU Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework. Cloudflare’s Privacy Policy

§ 12 Recipients and Processors

We disclose personal data only to the extent permitted by law (e.g., to fulfill a contract, to comply with legal obligations, with consent, or based on legitimate interests). Service providers engaged to process data on our behalf are bound by data processing agreements (Art. 28 GDPR).

We disclose personal data only to the extent permitted by law (e.g., to fulfill a contract, to comply with legal obligations, with consent, or based on legitimate interests). Service providers engaged to process data on our behalf are bound by data processing agreements (Art. 28 GDPR).

§ 13 Transfers to Third Countries

Pakera is operated in Germany. Some of the additional services and service providers mentioned above may transfer data to third countries (in particular the U.S.). In such cases, we ensure an adequate level of data protection, in particular through an adequacy decision by the European Commission (e.g., the EU-U.S. Data Privacy Framework, if certified) and/or through EU Standard Contractual Clauses along with supplementary safeguards (Art. 44 et seq. GDPR).

Pakera is operated in Germany. Some of the additional services and service providers mentioned above may transfer data to third countries (in particular the U.S.). In such cases, we ensure an adequate level of data protection, in particular through an adequacy decision by the European Commission (e.g., the EU-U.S. Data Privacy Framework, if certified) and/or through EU Standard Contractual Clauses along with supplementary safeguards (Art. 44 et seq. GDPR).

§ 14 Retention Period

We store personal data only for as long as is necessary for the respective purposes or as required by statutory retention obligations. In particular:

  • Project history of unregistered users: No storage

  • Project history of users registered for free: 30 days, followed by automatic deletion

  • Project history for the “Pro” plan: 180 days, followed by automatic deletion

  • Project history for Business and Enterprise plans: Permanent storage or until the end of the subscription;

  • Customer data after the end of the contract: Immediate, irrevocable deletion, except for support tickets and data required to be retained by law;

  • Accounting/invoicing data: in accordance with commercial and tax law retention periods (typically 6 or 10 years).

§ 15 Your Rights as a Data Subject

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing (Art. 21 GDPR). You may withdraw any consent you have given at any time with future effect (Art. 7(3) GDPR).

To exercise your rights, please contact: privacy@pakera.com

To the extent that we process data on behalf of a client (content on the platform), please direct your request to the respective client as the data controller.

Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority. The competent authority includes the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach.

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing (Art. 21 GDPR). You may withdraw any consent you have given at any time with future effect (Art. 7(3) GDPR).

To exercise your rights, please contact: privacy@pakera.com

To the extent that we process data on behalf of a client (content on the platform), please direct your request to the respective client as the data controller.

Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority. The competent authority includes the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach.

§ 16 No Automated Decision-Making

There is no exclusively automated decision-making with legal effects within the meaning of Article 22 of the GDPR.

There is no exclusively automated decision-making with legal effects within the meaning of Article 22 of the GDPR.

§ 17 Changes to This Privacy Policy

§ 17 Changes to This Privacy Policy

We will update this Privacy Policy as necessary due to changes in the legal landscape, technical developments, or changes in our data processing practices. The most current version, as published on our website, applies.

We will update this Privacy Policy as necessary due to changes in the legal landscape, technical developments, or changes in our data processing practices. The most current version, as published on our website, applies.

Last updated: September 2026

Last updated: September 2026