Privacy Policy

Last updated: November 4, 2025

Qommerce.ai is a brand operated by Qommerce GmbH. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services, in compliance with the General Data Protection Regulation (GDPR) and other applicable EU data protection laws.

1. Data Controller

Qommerce GmbH

Finksweg 51
21129 Hamburg
Germany

2. Information We Collect

2.1 Personal Data You Provide

We collect information that you voluntarily provide to us when you:

  • Register for an account
  • Use our services
  • Subscribe to our newsletter
  • Fill out contact forms
  • Attend our events or webinars
  • Communicate with us

This information may include:

  • Name and surname
  • Email address
  • Company name and job title
  • Phone number
  • Business address
  • Industry and interest areas
  • Any other information you choose to provide

2.2 Automatically Collected Information

When you access our website, we automatically collect certain information:

  • IP address
  • Browser type and version
  • Operating system
  • Referring URLs
  • Pages visited and time spent on pages
  • Device information
  • Cookies and similar tracking technologies

2.3 Business Client Data

If you are a business client using our services, we may process:

  • Sales and market data
  • Customer behavior insights
  • Competitive intelligence data
  • Other business analytics data as part of our services

3. Legal Basis for Processing (GDPR)

We process your personal data based on the following legal grounds:

Consent (Article 6(1)(a) GDPR)

For marketing communications, cookies, and newsletter subscriptions where you have given explicit consent.

Contract Performance (Article 6(1)(b) GDPR)

To provide our services, manage your account, and fulfill our contractual obligations.

Legitimate Interests (Article 6(1)(f) GDPR)

For analytics, fraud prevention, network security, and improving our services.

Legal Obligation (Article 6(1)(c) GDPR)

To comply with applicable laws, regulations, and legal processes.

4. How We Use Your Information

We use the collected information for the following purposes:

  • Service Delivery: To provide, maintain, and improve our platform and services
  • Customer Support: To respond to your inquiries and provide technical support
  • Account Management: To manage your account and provide personalized experiences
  • Communications: To send you updates, newsletters, and marketing communications (with your consent)
  • Analytics: To understand usage patterns and improve our services
  • Security: To protect against fraud, unauthorized access, and security threats
  • Legal Compliance: To comply with legal obligations and enforce our terms
  • Business Operations: To conduct internal research, analytics, and business intelligence

5. Data Sharing and Disclosure

We may share your information with:

5.1 Service Providers

We work with third-party service providers who assist us in:

  • Cloud hosting and infrastructure (e.g., AWS, Google Cloud)
  • Analytics and performance monitoring
  • Customer relationship management (e.g., HubSpot)
  • Email delivery and marketing automation
  • Payment processing

All service providers are contractually bound to protect your data and comply with GDPR requirements.

5.2 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity.

5.3 Legal Requirements

We may disclose your information when required by law, court order, or government request.

5.4 With Your Consent

We may share information for other purposes with your explicit consent.

6. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs): We use EU-approved SCCs with our data processors
  • Adequacy Decisions: We transfer data to countries with EU adequacy decisions
  • Additional Security Measures: We implement supplementary measures to ensure data protection

7. Your Rights Under GDPR

As a data subject in the EU, you have the following rights:

Right to Access

Request a copy of your personal data we hold

Right to Rectification

Correct inaccurate or incomplete data

Right to Erasure

Request deletion of your personal data

Right to Restriction

Limit how we use your data

Right to Data Portability

Receive your data in a structured format

Right to Object

Object to processing based on legitimate interests

Right to Withdraw Consent

Withdraw consent for data processing

Right to Lodge a Complaint

File a complaint with your data protection authority

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month.

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:

  • Account Data: Retained while your account is active and for 6 months after account closure
  • Marketing Data: Retained until you unsubscribe or withdraw consent
  • Business Records: Retained for 7 years to comply with legal and tax obligations
  • Analytics Data: Anonymized and retained for statistical purposes
  • Legal Hold: Data may be retained longer if required by law or legal proceedings

9. Security Measures

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit and at rest
  • Access controls and authentication
  • Regular security assessments and audits
  • Employee training on data protection
  • Incident response procedures
  • Regular backups and disaster recovery plans

10. Cookies and Tracking Technologies

We use cookies and similar technologies. For detailed information, please see our Cookie Policy.

11. Children's Privacy

Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us immediately.

12. Changes to This Privacy Policy

We may update this Privacy Policy periodically. We will notify you of material changes by:

  • Posting the updated policy on our website
  • Updating the "Last Updated" date
  • Sending email notifications for significant changes

Your continued use of our services after changes constitutes acceptance of the updated policy.

13. Contact Us

For questions, concerns, or to exercise your rights regarding your personal data, please contact us:

Email: [email protected]

Data Protection Officer: Available upon request

Response Time: We aim to respond within 30 days

14. Supervisory Authority

You have the right to lodge a complaint with your local data protection authority if you believe we have not complied with applicable data protection laws.