Gesellschafter24
Unternehmen finden
Investoren finden
Marktplatz
Experten finden
Magazin
LoginInserieren

Privacy Policy

Status: July 2026 · Version 1 · This English version is a non-binding translation. The German version is legally binding.

We, Gesellschafter24 UG (haftungsbeschränkt), hereby inform you in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR) and § 25 of the German Telecommunications-Digital-Services Privacy Act (TDDDG) about the processing of your personal data and your rights. The Privacy Policy is designed to be transparent so you can clearly identify which data we process, for what purpose, and on what legal basis.

1. Controller and Privacy Contact

Gesellschafter24 UG (haftungsbeschränkt)
Fuhrenkämpe 2, 49716 Meppen, Germany
Authorised managing director: Joel Maximilian Johannes Jahn
Register court: Local court (Amtsgericht) Osnabrück, HRB 223404
General: info@gesellschafter24.de
Privacy: datenschutz@gesellschafter24.de

A data protection officer is currently not required (§ 38 BDSG). For data protection enquiries, please contact the privacy address above directly.

2. Definitions

The terms used in this Privacy Policy (in particular "personal data", "processing", "controller", "processor", "recipient", "consent", "data subject") follow the definitions in Article 4 GDPR. The full text is available in the General Data Protection Regulation of the European Union.

3. Scope

This Privacy Policy applies to the processing of personal data in connection with the use of the Gesellschafter24 platform accessible at www.gesellschafter24.de including all subdomains and any technical deployment domains of our hosting provider through which the platform is delivered. For external websites that we only link to, the privacy notices of the respective providers apply.

4. General Principles and Legal Bases

We process personal data exclusively within the legal framework. The relevant legal bases are in particular:

  • Art. 6 (1) (a) GDPR – consent of the data subject.
  • Art. 6 (1) (b) GDPR – performance of a contract and pre-contractual measures.
  • Art. 6 (1) (c) GDPR – compliance with legal obligations (e.g. tax retention duties).
  • Art. 6 (1) (f) GDPR – legitimate interests, provided that the data subject's interests do not prevail.
  • §§ 25, 26 TDDDG – storage of information in the user's terminal equipment and access to already stored information.

Necessity of provision (Art. 13 (2) (e) GDPR): There is no statutory obligation to provide us with personal data. However, where data is marked as mandatory in forms, its provision is necessary for the conclusion or performance of the respective contract or the use of the respective feature; without this information, we cannot provide the service in question (e.g. no registration without an email address, no contact request without a reply address). Optional information is identifiable as such.

5. Hosting and Technical Infrastructure

5.1 Vercel (Hosting, CDN)

Our website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Vercel operates a global edge network with a focus on European locations (in particular Frankfurt, Dublin), but content may be delivered worldwide as needed.

Upon access to our pages, technically necessary data is automatically transmitted: IP address, browser type and version, operating system, referrer URL, timestamp, paths accessed. The legal basis is Art. 6 (1) (f) GDPR; the legitimate interest lies in the technical provision, security, and optimisation of the platform.

Third-country transfer: Since Vercel Inc. is based in the USA, your data may be processed there. We have concluded a data processing agreement with Vercel under Art. 28 GDPR, which incorporates the EU Commission's Standard Contractual Clauses of 4 June 2021 (Decision (EU) 2021/914). Vercel Inc. is also certified under the EU-US Data Privacy Framework (status to be checked at dataprivacyframework.gov/list). We point out that under the US Cloud Act, US authorities may, under certain conditions, gain access to data held by US providers. Further information is available in the Vercel Privacy Policy.

5.2 Supabase (Database, Authentication, Storage)

For storing account and listing data, authentication, and file uploads (e.g. logos, cover images of advisor profiles) we use Supabase Inc., 970 Toa Payoh North #07-04, Singapore. Operational data processing takes place in the EU region eu-west-1 (Dublin, Ireland).

We have concluded a data processing agreement with Supabase under Art. 28 GDPR. Row-Level Security is used at database level so that each user has access exclusively to their own data and content explicitly made public.

Third-country reference: Even though data processing takes place in the EU, the parent company Supabase Inc. is headquartered outside the EU (or has US subsidiaries). We point out as a precaution that intra-corporate access from the US area cannot theoretically be excluded; contractual safeguards (Standard Contractual Clauses) are in place. Further information is available in the Supabase Privacy Policy.

6. Server Logs and Access Data

When the platform is accessed, technically required access data is recorded in server logs:

  • IP address
  • Date and time of access
  • Name and URL of the file accessed
  • HTTP status code and amount of data transferred
  • Browser type, version, and operating system
  • Referring URL

The legal basis is Art. 6 (1) (f) GDPR; the legitimate interest lies in the security and functionality of the platform and in abuse prevention. Logs are stored for 7 to 30 days, after which they are anonymised or deleted.

7. Cookies and Similar Technologies

We use cookies and comparable technologies (LocalStorage) only to the extent technically required. We do not use a comprehensive tracking infrastructure (e.g. marketing cookies, cross-site tracking).

NameProviderPurposeType / DurationLegal basis
g24_consentGesellschafter24Storage of your cookie preferencesNecessary / 365 daysArt. 6 (1) (f) GDPR; § 25 (2) No. 2 TDDDG
sb-*SupabaseAuthentication / session maintenanceNecessary / 60 min. or until logoutArt. 6 (1) (b) GDPR; § 25 (2) No. 2 TDDDG
LocalStorage languageGesellschafter24Storage of language setting (DE/EN)Necessary / unlimitedArt. 6 (1) (f) GDPR; § 25 (2) No. 2 TDDDG

You can adjust your cookie preferences at any time via the cookie banner, which can be reopened through the corresponding footer link. We do not currently use tracking or marketing cookies; should this change in the future, the relevant cookies will only be set after your express consent.

8. Registration and User Account

When creating a user account, we collect the following data:

  • Email address
  • First and last name
  • Password (stored only as a cryptographic bcrypt hash; the plaintext password is never visible to us)
  • Account type (standard user or advisor) and account role (consumer/business)
  • Optional: company name and VAT identification number (for businesses)

The legal basis is Art. 6 (1) (b) GDPR (performance of a contract). Data is stored as long as your account exists. You can request account deletion at any time in your account settings.

8.1 Login via External Providers (OAuth)

If you log in via external identity services (e.g. Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland), data is exchanged between your browser and the respective provider for authentication. We typically receive your email address, name, and a unique provider identifier. The legal basis is Art. 6 (1) (b) GDPR: the processing is necessary for the performance of the user agreement by means of the authentication method you have chosen yourself. We recommend reviewing the privacy policy of the respective provider.

9. Listings

When creating a listing, we collect and publish the following data:

  • Listing title, description, highlights
  • Company data (industry, location, country, postal code at selectable precision, founding year, company type)
  • Key figures (revenue, EBIT, headcount, asking price)
  • Images (stored in Supabase Storage, region eu-west-1)
  • Listing status, runtime data, plan type

This data is publicly displayed on the platform; postal codes may be obscured at the lister's request ("country only", "first two digits only", or "full"). When the "anonymous listing" feature is selected, the lister's identity is not shown in the public listing display; in case of direct response traffic following a contact request, however, the lister's email address may become known to the requester.

The legal basis is Art. 6 (1) (b) GDPR. The retention period depends on the chosen runtime; after expiry, listings are deactivated. Upon request we delete the listing completely; in backup systems, residual data remains for a maximum of 90 days.

Publication of Platinum listings on social media channels: If you book a Platinum listing, we additionally publish your listing on our social media channels (Instagram and Facebook – each Meta Platforms Ireland Limited, Dublin, Ireland – and LinkedIn – LinkedIn Ireland Unlimited Company, Dublin, Ireland). The data transmitted is the listing content that is public anyway (title, description, key figures, images; for non-anonymous listings, possibly your name or company name). The legal basis is Art. 6 (1) (b) GDPR (performance of the Platinum service booked by you). Posts are labelled as a user listing; the privacy notices of the respective platform operator additionally apply to processing on that platform. Upon your request, we delete the respective post.

10. Advisor Profiles

Advisors create a publicly visible profile. We process:

  • Company name, location, founding year
  • Logo and cover image (bucket "advisor-images")
  • Advisor type (e.g. M&A advisor, auditor, lawyer, tax advisor, management consultant), specialisations, industries, transaction volume
  • Description and highlights
  • Contact data: email, phone, website, LinkedIn, XING profile
  • Verification status, plan type, subscription status, Stripe customer ID, Stripe subscription ID, onboarding date

The legal basis is Art. 6 (1) (b) GDPR. Advisors act in the exercise of their professional activity; publication in the directory serves business initiation. After termination of the subscription, we deactivate the profile; personal profile data is deleted within a 90-day grace period unless statutory retention duties prevail.

Verification process: Before an advisor profile is publicly displayed, we manually review the information provided during onboarding for plausibility; for this purpose, we compare it with publicly available sources (e.g. commercial register, company website, professional directories). We process additional evidence only if we request it from you in individual cases; such documents are stored only until the review is completed and to document the verification decision. The legal bases are Art. 6 (1) (b) GDPR (performance of the subscription contract) and Art. 6 (1) (f) GDPR (legitimate interest in protecting platform users from inaccurate advisor information).

11. Contact Requests Between Users

If you submit a request to a lister via the platform's contact form, we process:

  • Name
  • Email address
  • Phone (optional)
  • Content of your message
  • Listing reference and timestamp of the request

We forward your request via email to the lister, setting your email address as the reply address ("Reply-To"), so that the lister can reply directly to you. As soon as the lister responds, further communication takes place directly between you and the lister outside the platform – we have no influence on this. For the further processing of your contact data, the lister is responsible as a separate data controller within the meaning of the GDPR.

The legal bases are Art. 6 (1) (b) GDPR (initiation of a contract between lister and searcher) and Art. 6 (1) (f) GDPR (legitimate interest in abuse prevention). Request data is stored for 12 months and then anonymised.

12. General Contact Form

You can send us general enquiries via our contact form. We collect name, email address, subject, and message. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in processing enquiries) or Art. 6 (1) (b) GDPR (in case of pre-contractual enquiries). Data is retained for up to 12 months and then deleted unless further correspondence ensues.

13. Payment Processing via Stripe

For processing paid services (listing packages, advisor subscriptions) we use Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland ("Stripe"). Stripe processes your payment data on its own responsibility in accordance with PCI-DSS standards.

From Stripe we receive:

  • Stripe customer ID
  • Stripe subscription ID
  • Payment status, amounts, timestamps, invoice numbers
  • For businesses on request: company and tax data

We do not receive or store card or account data. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract).

Third-country reference: Stripe Inc. (USA) is the parent of Stripe Payments Europe Ltd.; intra-corporate access from the USA cannot be excluded. Contractual safeguards (Standard Contractual Clauses, Data Privacy Framework) are in place.

Tax-relevant data (in particular invoices) is retained in line with statutory retention periods (currently eight years, § 147 AO, § 14b UStG); the legal basis for this is Art. 6 (1) (c) GDPR. Further information is available in the Stripe Privacy Policy.

14. Sending Transactional Emails (Resend)

For sending transactional emails (e.g. confirmations, contact requests, cancellation confirmations, reminders) we use Resend Inc., 2261 Market Street #4493, San Francisco, CA 94114, USA. To deliver messages, Resend processes your email address, name, and the respective message content.

The legal basis is Art. 6 (1) (b) GDPR or Art. 6 (1) (f) GDPR. We have concluded a data processing agreement with Resend.

Third-country reference: Since Resend is based in the USA, a transfer to a third country occurs. Resend Inc. is certified under the EU-US Data Privacy Framework; in addition, the Standard Contractual Clauses of the EU Commission apply (certification status can be checked at dataprivacyframework.gov/list). Logs at Resend are typically stored for 30 days and then deleted.

Our own dispatch log: In addition, we log every automated email dispatch on our own systems. We store the recipient address, the subject, the time and the dispatch status (delivered or failed, including the reason) — but not the content of the message. The purpose is to prove that a message was sent (for example confirmations we are legally required to provide) and to detect and resolve delivery problems. The legal basis is Art. 6 (1) (b) GDPR and Art. 6 (1) (f) GDPR; our legitimate interest lies in the verifiability and reliability of our email dispatch. The log is deleted automatically after 12 months.

15. Newsletter (Currently Inactive)

As soon as we offer a newsletter, the double opt-in procedure applies: you enter your email address and receive a confirmation email with an activation link. Only after clicking this link is your email address added to the distribution list. Date, time, and IP address of registration are stored as evidence of consent. The legal basis is Art. 6 (1) (a) GDPR; you can revoke consent at any time via the unsubscribe link in any newsletter. We maintain a suppression list to prevent re-contacting recipients who have revoked consent (Art. 6 (1) (f) GDPR).

16. Favourites and Watchlists

If you save a listing as a favourite, we process the listing IDs in connection with your account. The legal basis is Art. 6 (1) (b) GDPR. You can remove favourites yourself at any time.

17. External Fonts and Embedded Content

We use the "Inter" font via the next/font module, which integrates fonts locally into our website at build time. There is no live connection to third-party servers (e.g. Google Fonts CDN) on page load; no IP transmission to Google occurs.

All images displayed on the platform – including the industry sample images we provide for listings – are delivered via our own domain or the image optimisation service of our hosting provider (section 5.1). Your browser does not establish a direct connection to servers of external image providers when viewing listings. Tracking scripts, analytics tools, or third-party plugins (e.g. Google Analytics, Meta Pixel, Hotjar, Sentry, Intercom) are not used.

18. Processors Pursuant to Art. 28 GDPR

We use carefully selected processors with whom we have concluded data processing agreements pursuant to Art. 28 GDPR:

ProcessorLocation / data locationFunctionThird-country reference
Supabase Inc.Singapore (HQ); data in Dublin, IrelandDatabase, authentication, file storageindirect (US parent)
Vercel Inc.USAHosting, CDNUSA – SCCs, EU-US DPF
Stripe Payments Europe Ltd.Dublin, IrelandPayment processingindirect (US parent)
Resend Inc.USASending transactional emailsUSA – SCCs, EU-US DPF
Google Ireland Ltd. (with OAuth login)Dublin, IrelandAuthentication ("Login with Google")EU

19. Third-Country Transfers (Art. 44 et seq. GDPR)

To the extent personal data is transferred to countries outside the European Union (so-called third countries), we comply with Art. 44 et seq. GDPR. We take appropriate safeguards for the protection of the data, in particular through:

  • Standard Contractual Clauses of the EU Commission of 4 June 2021 (Decision (EU) 2021/914),
  • Certification of the recipient under the EU-US Data Privacy Framework (where available), to be checked at dataprivacyframework.gov/list,
  • Adequate technical and organisational measures of the recipients.

For transfers to the USA, we point out as a precaution that under the US Cloud Act, US authorities may, under certain conditions, gain access to data held by US providers. Upon request, we provide copies of the agreed Standard Contractual Clauses.

20. Retention Periods and Deletion Concept

We store personal data only for as long as necessary for the respective purpose or as required by statutory retention duties. The following retention periods apply:

Data categoryRetention period
Account master dataUntil account deletion by the user
ListingsUntil expiry or deletion request
Advisor profilesUntil account deletion; 90-day grace period after cancellation
Contact requests12 months, then anonymisation
General contact formUp to 12 months
Reports via the DSA report form12 months after completion of the review
Job applications6 months after completion of the process (longer only with consent)
Invoices, accounting records, Stripe transaction data8 years (§ 147 AO, § 14b UStG); commercial books and annual financial statements: 10 years
Server logs7 to 30 days
BackupsRolling 30 to 90 days
Newsletter (planned)Until unsubscription; suppression list 3 years
Dispatch log for automated emails (recipient address, subject, dispatch status)12 months
Cookie consent record365 days

21. Data Security

We take technical and organisational measures pursuant to Art. 32 GDPR to protect your personal data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorised access by third parties. These include in particular:

  • Encrypted transmission via TLS 1.2 or higher including HTTP Strict Transport Security (HSTS)
  • Password storage as a cryptographic hash (bcrypt) with Supabase Auth
  • Row-Level Security (RLS) at database level: database access is restricted by access policies to the data the signed-in user is authorised to see and to content explicitly made public
  • Separation of service and anonymous keys; private keys server-side only
  • Webhook signature verification for all incoming Stripe events
  • Regular backup creation with at-rest encryption by Supabase
  • Principle of data minimisation – data is collected only where necessary for functionality

Our security measures are regularly reviewed and adapted to the state of the art.

22. Your Rights as a Data Subject

Regarding the personal data we process about you, you have the following rights:

  • Access (Art. 15 GDPR) – you can request information about the data we process about you.
  • Rectification (Art. 16 GDPR) – you can request correction of inaccurate data or completion of incomplete data.
  • Erasure (Art. 17 GDPR) – you can request deletion of your data, provided no statutory retention duties prevail.
  • Restriction (Art. 18 GDPR) – you can request restriction of processing.
  • Data Portability (Art. 20 GDPR) – you can receive your data in a structured, commonly used, and machine-readable format. A self-service feature (JSON export) is available in your dashboard.
  • Objection (Art. 21 GDPR) – you can object to the processing of your data where it is based on legitimate interests.

To exercise your rights, the following channels are open:

  • Dashboard functions for account deletion and data export
  • Email to datenschutz@gesellschafter24.de

We respond to your request without undue delay, in any case within one month of receipt of the request (Art. 12 (3) GDPR).

23. Right to Withdraw Consents

Where processing is based on your consent (Art. 6 (1) (a) GDPR), you can withdraw this consent at any time with future effect. The lawfulness of processing carried out until withdrawal remains unaffected. You can declare the withdrawal informally by email to datenschutz@gesellschafter24.de.

24. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your data infringes the GDPR. In particular, the supervisory authority of your habitual residence or the authority at the registered office of our company is competent.

The supervisory authority responsible for us is:
Der Landesbeauftragte für den Datenschutz Niedersachsen (State Commissioner for Data Protection of Lower Saxony)
Prinzenstraße 5, 30159 Hannover, Germany
lfd.niedersachsen.de
A list of all German supervisory authorities is available at bfdi.bund.de.

25. Automated Decision-Making and Profiling

Automated decision-making within the meaning of Art. 22 GDPR or profiling does not currently take place. In particular, advisor verification and listing moderation are performed manually by our staff. Should we introduce automated decisions in the future, we will inform you in advance separately.

26. Reports of Illegal Content (DSA Report Form)

Via our report form at www.gesellschafter24.de/inhalt-melden you can report allegedly illegal content to us (Art. 16 of Regulation (EU) 2022/2065 – DSA). In doing so, we process: the URL of the reported content, the selected report category, your description, your name and email address, and your declaration that the report is submitted in good faith.

We use this data to review the report, to confirm receipt, and to communicate our reasoned decision (Art. 16, 17 DSA), as well as, where applicable, to inform the content creator about the complaint. We do not disclose your identity to the content creator unless legally required. The legal bases are Art. 6 (1) (c) GDPR (compliance with our DSA obligations) and Art. 6 (1) (f) GDPR (abuse prevention). The data is deleted or anonymised 12 months after completion of the review, unless longer retention is required for legal defence.

27. Job Applications

We accept applications by email to karriere@gesellschafter24.de. We process the applicant data you submit (contact details, CV, cover letter, references, and other documents you provide) exclusively to carry out the application process. The legal basis is § 26 BDSG in conjunction with Art. 6 (1) (b) GDPR. After completion of the process, we delete your documents no later than 6 months afterwards, unless you have consented to longer storage (e.g. for future positions) or you are hired.

28. Social Media Presences

We maintain company presences on Instagram (instagram.com/gesellschafter24) and Facebook (facebook.com/gesellschafter24) – each Meta Platforms Ireland Limited, Dublin, Ireland – as well as LinkedIn (linkedin.com/company/gesellschafter24) – LinkedIn Ireland Unlimited Company, Dublin, Ireland. When you visit these presences, the respective platform operator processes your data under its own responsibility; the privacy notices of the respective platform apply. For the data processing taking place there (in particular page statistics / “insights”), there is partial joint controllership with the respective platform operator (Art. 26 GDPR); we only receive aggregated statistics without any personal reference. The legal basis for our presences is Art. 6 (1) (f) GDPR (legitimate interest in a contemporary public presence). For the publication of Platinum listings on these channels, see section 9.

29. Changes to This Privacy Policy

We reserve the right to continually update this Privacy Policy in line with changing legal frameworks or adjustments to our services. The currently valid version is always available at www.gesellschafter24.de/datenschutz. Material changes affecting your rights are actively communicated via email or a clearly visible notice at the next login.


This Privacy Policy has been valid in this version since July 2026.

Gesellschafter24

Marktplatz für Unternehmenskauf, Unternehmensverkauf und Nachfolge.

Plattform

  • Unternehmen finden
  • Investoren finden
  • Inserat schalten
  • Marktplatz-Preise

Für Berater

  • Berater werden
  • Experten finden
  • Erfolgsgeschichten
  • Hilfe & FAQ

Unternehmen

  • Über uns
  • Magazin
  • Kontakt
  • Karriere

Rechtliches

  • Impressum
  • Datenschutz
  • AGB
  • Verträge kündigen
  • Vertrag widerrufen
  • Inhalt melden
SSL-verschlüsselt·Datenschutzfreundlich·Made in Germany

© 2026 Gesellschafter24 UG (haftungsbeschränkt). Alle Rechte vorbehalten.