Status: July 2026 · Version 1 · This English version is a non-binding translation. The German version is legally binding.
We, Gesellschafter24 UG (haftungsbeschränkt), hereby inform you in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR) and § 25 of the German Telecommunications-Digital-Services Privacy Act (TDDDG) about the processing of your personal data and your rights. The Privacy Policy is designed to be transparent so you can clearly identify which data we process, for what purpose, and on what legal basis.
Gesellschafter24 UG (haftungsbeschränkt)
Fuhrenkämpe 2, 49716 Meppen, Germany
Authorised managing director: Joel Maximilian Johannes Jahn
Register court: Local court (Amtsgericht) Osnabrück, HRB 223404
General: info@gesellschafter24.de
Privacy: datenschutz@gesellschafter24.de
A data protection officer is currently not required (§ 38 BDSG). For data protection enquiries, please contact the privacy address above directly.
The terms used in this Privacy Policy (in particular "personal data", "processing", "controller", "processor", "recipient", "consent", "data subject") follow the definitions in Article 4 GDPR. The full text is available in the General Data Protection Regulation of the European Union.
This Privacy Policy applies to the processing of personal data in connection with the use of the Gesellschafter24 platform accessible at www.gesellschafter24.de including all subdomains and any technical deployment domains of our hosting provider through which the platform is delivered. For external websites that we only link to, the privacy notices of the respective providers apply.
We process personal data exclusively within the legal framework. The relevant legal bases are in particular:
Necessity of provision (Art. 13 (2) (e) GDPR): There is no statutory obligation to provide us with personal data. However, where data is marked as mandatory in forms, its provision is necessary for the conclusion or performance of the respective contract or the use of the respective feature; without this information, we cannot provide the service in question (e.g. no registration without an email address, no contact request without a reply address). Optional information is identifiable as such.
Our website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Vercel operates a global edge network with a focus on European locations (in particular Frankfurt, Dublin), but content may be delivered worldwide as needed.
Upon access to our pages, technically necessary data is automatically transmitted: IP address, browser type and version, operating system, referrer URL, timestamp, paths accessed. The legal basis is Art. 6 (1) (f) GDPR; the legitimate interest lies in the technical provision, security, and optimisation of the platform.
Third-country transfer: Since Vercel Inc. is based in the USA, your data may be processed there. We have concluded a data processing agreement with Vercel under Art. 28 GDPR, which incorporates the EU Commission's Standard Contractual Clauses of 4 June 2021 (Decision (EU) 2021/914). Vercel Inc. is also certified under the EU-US Data Privacy Framework (status to be checked at dataprivacyframework.gov/list). We point out that under the US Cloud Act, US authorities may, under certain conditions, gain access to data held by US providers. Further information is available in the Vercel Privacy Policy.
For storing account and listing data, authentication, and file uploads (e.g. logos, cover images of advisor profiles) we use Supabase Inc., 970 Toa Payoh North #07-04, Singapore. Operational data processing takes place in the EU region eu-west-1 (Dublin, Ireland).
We have concluded a data processing agreement with Supabase under Art. 28 GDPR. Row-Level Security is used at database level so that each user has access exclusively to their own data and content explicitly made public.
Third-country reference: Even though data processing takes place in the EU, the parent company Supabase Inc. is headquartered outside the EU (or has US subsidiaries). We point out as a precaution that intra-corporate access from the US area cannot theoretically be excluded; contractual safeguards (Standard Contractual Clauses) are in place. Further information is available in the Supabase Privacy Policy.
When the platform is accessed, technically required access data is recorded in server logs:
The legal basis is Art. 6 (1) (f) GDPR; the legitimate interest lies in the security and functionality of the platform and in abuse prevention. Logs are stored for 7 to 30 days, after which they are anonymised or deleted.
We use cookies and comparable technologies (LocalStorage) only to the extent technically required. We do not use a comprehensive tracking infrastructure (e.g. marketing cookies, cross-site tracking).
| Name | Provider | Purpose | Type / Duration | Legal basis |
|---|---|---|---|---|
g24_consent | Gesellschafter24 | Storage of your cookie preferences | Necessary / 365 days | Art. 6 (1) (f) GDPR; § 25 (2) No. 2 TDDDG |
sb-* | Supabase | Authentication / session maintenance | Necessary / 60 min. or until logout | Art. 6 (1) (b) GDPR; § 25 (2) No. 2 TDDDG |
LocalStorage language | Gesellschafter24 | Storage of language setting (DE/EN) | Necessary / unlimited | Art. 6 (1) (f) GDPR; § 25 (2) No. 2 TDDDG |
You can adjust your cookie preferences at any time via the cookie banner, which can be reopened through the corresponding footer link. We do not currently use tracking or marketing cookies; should this change in the future, the relevant cookies will only be set after your express consent.
When creating a user account, we collect the following data:
The legal basis is Art. 6 (1) (b) GDPR (performance of a contract). Data is stored as long as your account exists. You can request account deletion at any time in your account settings.
If you log in via external identity services (e.g. Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland), data is exchanged between your browser and the respective provider for authentication. We typically receive your email address, name, and a unique provider identifier. The legal basis is Art. 6 (1) (b) GDPR: the processing is necessary for the performance of the user agreement by means of the authentication method you have chosen yourself. We recommend reviewing the privacy policy of the respective provider.
When creating a listing, we collect and publish the following data:
This data is publicly displayed on the platform; postal codes may be obscured at the lister's request ("country only", "first two digits only", or "full"). When the "anonymous listing" feature is selected, the lister's identity is not shown in the public listing display; in case of direct response traffic following a contact request, however, the lister's email address may become known to the requester.
The legal basis is Art. 6 (1) (b) GDPR. The retention period depends on the chosen runtime; after expiry, listings are deactivated. Upon request we delete the listing completely; in backup systems, residual data remains for a maximum of 90 days.
Publication of Platinum listings on social media channels: If you book a Platinum listing, we additionally publish your listing on our social media channels (Instagram and Facebook – each Meta Platforms Ireland Limited, Dublin, Ireland – and LinkedIn – LinkedIn Ireland Unlimited Company, Dublin, Ireland). The data transmitted is the listing content that is public anyway (title, description, key figures, images; for non-anonymous listings, possibly your name or company name). The legal basis is Art. 6 (1) (b) GDPR (performance of the Platinum service booked by you). Posts are labelled as a user listing; the privacy notices of the respective platform operator additionally apply to processing on that platform. Upon your request, we delete the respective post.
Advisors create a publicly visible profile. We process:
The legal basis is Art. 6 (1) (b) GDPR. Advisors act in the exercise of their professional activity; publication in the directory serves business initiation. After termination of the subscription, we deactivate the profile; personal profile data is deleted within a 90-day grace period unless statutory retention duties prevail.
Verification process: Before an advisor profile is publicly displayed, we manually review the information provided during onboarding for plausibility; for this purpose, we compare it with publicly available sources (e.g. commercial register, company website, professional directories). We process additional evidence only if we request it from you in individual cases; such documents are stored only until the review is completed and to document the verification decision. The legal bases are Art. 6 (1) (b) GDPR (performance of the subscription contract) and Art. 6 (1) (f) GDPR (legitimate interest in protecting platform users from inaccurate advisor information).
If you submit a request to a lister via the platform's contact form, we process:
We forward your request via email to the lister, setting your email address as the reply address ("Reply-To"), so that the lister can reply directly to you. As soon as the lister responds, further communication takes place directly between you and the lister outside the platform – we have no influence on this. For the further processing of your contact data, the lister is responsible as a separate data controller within the meaning of the GDPR.
The legal bases are Art. 6 (1) (b) GDPR (initiation of a contract between lister and searcher) and Art. 6 (1) (f) GDPR (legitimate interest in abuse prevention). Request data is stored for 12 months and then anonymised.
You can send us general enquiries via our contact form. We collect name, email address, subject, and message. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in processing enquiries) or Art. 6 (1) (b) GDPR (in case of pre-contractual enquiries). Data is retained for up to 12 months and then deleted unless further correspondence ensues.
For processing paid services (listing packages, advisor subscriptions) we use Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland ("Stripe"). Stripe processes your payment data on its own responsibility in accordance with PCI-DSS standards.
From Stripe we receive:
We do not receive or store card or account data. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract).
Third-country reference: Stripe Inc. (USA) is the parent of Stripe Payments Europe Ltd.; intra-corporate access from the USA cannot be excluded. Contractual safeguards (Standard Contractual Clauses, Data Privacy Framework) are in place.
Tax-relevant data (in particular invoices) is retained in line with statutory retention periods (currently eight years, § 147 AO, § 14b UStG); the legal basis for this is Art. 6 (1) (c) GDPR. Further information is available in the Stripe Privacy Policy.
For sending transactional emails (e.g. confirmations, contact requests, cancellation confirmations, reminders) we use Resend Inc., 2261 Market Street #4493, San Francisco, CA 94114, USA. To deliver messages, Resend processes your email address, name, and the respective message content.
The legal basis is Art. 6 (1) (b) GDPR or Art. 6 (1) (f) GDPR. We have concluded a data processing agreement with Resend.
Third-country reference: Since Resend is based in the USA, a transfer to a third country occurs. Resend Inc. is certified under the EU-US Data Privacy Framework; in addition, the Standard Contractual Clauses of the EU Commission apply (certification status can be checked at dataprivacyframework.gov/list). Logs at Resend are typically stored for 30 days and then deleted.
Our own dispatch log: In addition, we log every automated email dispatch on our own systems. We store the recipient address, the subject, the time and the dispatch status (delivered or failed, including the reason) — but not the content of the message. The purpose is to prove that a message was sent (for example confirmations we are legally required to provide) and to detect and resolve delivery problems. The legal basis is Art. 6 (1) (b) GDPR and Art. 6 (1) (f) GDPR; our legitimate interest lies in the verifiability and reliability of our email dispatch. The log is deleted automatically after 12 months.
As soon as we offer a newsletter, the double opt-in procedure applies: you enter your email address and receive a confirmation email with an activation link. Only after clicking this link is your email address added to the distribution list. Date, time, and IP address of registration are stored as evidence of consent. The legal basis is Art. 6 (1) (a) GDPR; you can revoke consent at any time via the unsubscribe link in any newsletter. We maintain a suppression list to prevent re-contacting recipients who have revoked consent (Art. 6 (1) (f) GDPR).
If you save a listing as a favourite, we process the listing IDs in connection with your account. The legal basis is Art. 6 (1) (b) GDPR. You can remove favourites yourself at any time.
We use the "Inter" font via the next/font module, which integrates fonts locally into our website at build time. There is no live connection to third-party servers (e.g. Google Fonts CDN) on page load; no IP transmission to Google occurs.
All images displayed on the platform – including the industry sample images we provide for listings – are delivered via our own domain or the image optimisation service of our hosting provider (section 5.1). Your browser does not establish a direct connection to servers of external image providers when viewing listings. Tracking scripts, analytics tools, or third-party plugins (e.g. Google Analytics, Meta Pixel, Hotjar, Sentry, Intercom) are not used.
We use carefully selected processors with whom we have concluded data processing agreements pursuant to Art. 28 GDPR:
| Processor | Location / data location | Function | Third-country reference |
|---|---|---|---|
| Supabase Inc. | Singapore (HQ); data in Dublin, Ireland | Database, authentication, file storage | indirect (US parent) |
| Vercel Inc. | USA | Hosting, CDN | USA – SCCs, EU-US DPF |
| Stripe Payments Europe Ltd. | Dublin, Ireland | Payment processing | indirect (US parent) |
| Resend Inc. | USA | Sending transactional emails | USA – SCCs, EU-US DPF |
| Google Ireland Ltd. (with OAuth login) | Dublin, Ireland | Authentication ("Login with Google") | EU |
To the extent personal data is transferred to countries outside the European Union (so-called third countries), we comply with Art. 44 et seq. GDPR. We take appropriate safeguards for the protection of the data, in particular through:
For transfers to the USA, we point out as a precaution that under the US Cloud Act, US authorities may, under certain conditions, gain access to data held by US providers. Upon request, we provide copies of the agreed Standard Contractual Clauses.
We store personal data only for as long as necessary for the respective purpose or as required by statutory retention duties. The following retention periods apply:
| Data category | Retention period |
|---|---|
| Account master data | Until account deletion by the user |
| Listings | Until expiry or deletion request |
| Advisor profiles | Until account deletion; 90-day grace period after cancellation |
| Contact requests | 12 months, then anonymisation |
| General contact form | Up to 12 months |
| Reports via the DSA report form | 12 months after completion of the review |
| Job applications | 6 months after completion of the process (longer only with consent) |
| Invoices, accounting records, Stripe transaction data | 8 years (§ 147 AO, § 14b UStG); commercial books and annual financial statements: 10 years |
| Server logs | 7 to 30 days |
| Backups | Rolling 30 to 90 days |
| Newsletter (planned) | Until unsubscription; suppression list 3 years |
| Dispatch log for automated emails (recipient address, subject, dispatch status) | 12 months |
| Cookie consent record | 365 days |
We take technical and organisational measures pursuant to Art. 32 GDPR to protect your personal data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorised access by third parties. These include in particular:
Our security measures are regularly reviewed and adapted to the state of the art.
Regarding the personal data we process about you, you have the following rights:
To exercise your rights, the following channels are open:
We respond to your request without undue delay, in any case within one month of receipt of the request (Art. 12 (3) GDPR).
Where processing is based on your consent (Art. 6 (1) (a) GDPR), you can withdraw this consent at any time with future effect. The lawfulness of processing carried out until withdrawal remains unaffected. You can declare the withdrawal informally by email to datenschutz@gesellschafter24.de.
You have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your data infringes the GDPR. In particular, the supervisory authority of your habitual residence or the authority at the registered office of our company is competent.
The supervisory authority responsible for us is:
Der Landesbeauftragte für den Datenschutz Niedersachsen (State Commissioner for Data Protection of Lower Saxony)
Prinzenstraße 5, 30159 Hannover, Germany
lfd.niedersachsen.de
A list of all German supervisory authorities is available at bfdi.bund.de.
Automated decision-making within the meaning of Art. 22 GDPR or profiling does not currently take place. In particular, advisor verification and listing moderation are performed manually by our staff. Should we introduce automated decisions in the future, we will inform you in advance separately.
Via our report form at www.gesellschafter24.de/inhalt-melden you can report allegedly illegal content to us (Art. 16 of Regulation (EU) 2022/2065 – DSA). In doing so, we process: the URL of the reported content, the selected report category, your description, your name and email address, and your declaration that the report is submitted in good faith.
We use this data to review the report, to confirm receipt, and to communicate our reasoned decision (Art. 16, 17 DSA), as well as, where applicable, to inform the content creator about the complaint. We do not disclose your identity to the content creator unless legally required. The legal bases are Art. 6 (1) (c) GDPR (compliance with our DSA obligations) and Art. 6 (1) (f) GDPR (abuse prevention). The data is deleted or anonymised 12 months after completion of the review, unless longer retention is required for legal defence.
We accept applications by email to karriere@gesellschafter24.de. We process the applicant data you submit (contact details, CV, cover letter, references, and other documents you provide) exclusively to carry out the application process. The legal basis is § 26 BDSG in conjunction with Art. 6 (1) (b) GDPR. After completion of the process, we delete your documents no later than 6 months afterwards, unless you have consented to longer storage (e.g. for future positions) or you are hired.
We maintain company presences on Instagram (instagram.com/gesellschafter24) and Facebook (facebook.com/gesellschafter24) – each Meta Platforms Ireland Limited, Dublin, Ireland – as well as LinkedIn (linkedin.com/company/gesellschafter24) – LinkedIn Ireland Unlimited Company, Dublin, Ireland. When you visit these presences, the respective platform operator processes your data under its own responsibility; the privacy notices of the respective platform apply. For the data processing taking place there (in particular page statistics / “insights”), there is partial joint controllership with the respective platform operator (Art. 26 GDPR); we only receive aggregated statistics without any personal reference. The legal basis for our presences is Art. 6 (1) (f) GDPR (legitimate interest in a contemporary public presence). For the publication of Platinum listings on these channels, see section 9.
We reserve the right to continually update this Privacy Policy in line with changing legal frameworks or adjustments to our services. The currently valid version is always available at www.gesellschafter24.de/datenschutz. Material changes affecting your rights are actively communicated via email or a clearly visible notice at the next login.
This Privacy Policy has been valid in this version since July 2026.