Privacy Policy

Personalrampe Digital

Privacy Policy

Personalrampe Digital

Provider: Luis Moretto, An der Windecke 9, 58300 Wetter

Data protection email: privacy@personalrampe.de

1. General

In case of discrepancies between the English and German versions of this Privacy Policy, the German version shall prevail.

We take the protection of your personal data seriously. This Privacy Policy applies to the use of our website and our SaaS platform "Personalrampe Digital" (hereinafter "Platform") and informs you about the nature, scope and purpose of personal data we collect, use and process.

Controller within the meaning of the General Data Protection Regulation (GDPR):

Luis Moretto
An der Windecke 9, 58300 Wetter
Email: privacy@personalrampe.de

For employee data processed on behalf of our corporate customers, we act as a data processor; in this case the respective corporate customer is the Controller.

2. Data We Process

2.1 Marketing Website (non-logged-in visitors)

When you visit our website, the following technical data is automatically transmitted:

  • IP address (anonymised where technically feasible),
  • Date and time of access,
  • URL accessed,
  • Referrer URL,
  • Browser type and operating system.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and stable website operation).

Retention period: 7 days (server logs), then automatic deletion.

2.2 Account Registration (Company Administrators)

When registering as a company administrator for the Platform, we collect:

  • Name and professional email address,
  • Company name and address,
  • Password (stored as bcrypt hash, never in plain text),
  • Time of registration.

Legal basis: Art. 6(1)(b) GDPR (contract performance).

2.3 Employee Data in Personnel Files (processed on behalf of our customers)

The core function of the Platform is the digitisation, structuring and AI-supported analysis of personnel files on behalf of our corporate customers. Depending on which documents the Customer uploads, we may process in particular:

  • Identification and contact data: first and last name, internal employee ID, date of birth, address, contact details (if contained in the file),
  • Employment data: position, organisational unit, employment start and end dates, working time model, contract amendments,
  • Remuneration data: salary, bonus, allowances, bank details (IBAN), pension information (if contained in the file),
  • Performance and behaviour data: performance reviews, development meetings, warnings, feedback,
  • Absence data: sickness notifications, medical certificates, parental leave, other leave records,
  • Other HR-relevant documents that the Customer stores in personnel files.

The concrete content depends exclusively on the documents the Customer uploads.

For this processing we act as a data processor pursuant to Art. 28 GDPR. The Controller is the respective corporate customer. A Data Processing Agreement (DPA) must be concluded prior to use.

2.4 OCR, Structuring and AI-Based Processing

  1. OCR and text extraction

    • Uploaded PDFs are processed via OCR to extract text and layout information.
  2. Structuring and rule-based analysis

    • Extracted text is structured and stored in our database.
  3. AI-supported insights and summaries

    • We use AI models (e.g. Microsoft Azure OpenAI) to summarise content or make it searchable.
  4. "Deep AI Analysis" feature

    • Optional feature, explicitly marked in the user interface and must be actively enabled by the Customer.

2.5 AI Assistant Chat

The Platform provides an AI assistant chat for HR users. We record:

  • Chat prompts and model responses,
  • Technical metadata (timestamp, user ID, model used).

2.6 Transactional Email Communication

For sending transactional emails (account creation, invitations, notifications, password reset) we use a third-party email service provider (Mailgun, EU region).

2.7 Audit Log (User Action Logging)

The Platform maintains a complete audit log of all data changes. Each time a record is created, modified or deleted, the following is automatically logged:

  • Who performed the action (user ID, name, role),
  • What was changed (action type: create / update / delete, affected table and record ID),
  • When (timestamp),
  • From where (IP address of the user).

2.8 Contract Conclusion and Consent Logging

When accepting the Terms of Service, Privacy Policy and DPA (click-wrap), the following is stored:

  • Timestamp of acceptance,
  • IP address of the user,
  • Browser user agent,
  • Version of documents accepted,
  • Confirmation of signing authority (for DPA).

2.9 Payment Processing

Payments are processed via Dodo Payments Limited, 3rd Floor Crown House, 151 High Road, Loughton IG10 4LG, United Kingdom, VAT: 495 1783 48. Billing contact details, such as name, address, and purchase history, are transmitted. No employee data is transmitted to payment providers.

3. Service Providers (Sub-Processors)

We use sub-processors with whom DPAs have been concluded (e.g. Vercel Inc., Supabase Inc., Microsoft Azure, Mailgun, Upstash).

4. Your Rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21). Contact us at privacy@personalrampe.de. (Note for employees of our customers: Please direct requests regarding your employee data to your employer).