Draft – This privacy policy is provisional. The final version will follow.
This is a translation. In case of discrepancies, the German version prevails.
Privacy policy
1. Controller
Elbe Systems UG (haftungsbeschränkt), Haynauer Straße 75, 12249 Berlin, Germany
Managing director: Stefan Emilov
Email: kontakt@elbe-systems.de
2. Principle
This website uses no cookies, no tracking or analytics tools, no social media plugins and no embedded third-party content (such as maps or videos). Fonts and graphics are embedded in the page; no connections to third-party servers are made. Your language setting is not stored.
3. Hosting
The website and our servers are operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, in a data centre in Nuremberg (Germany). A data processing agreement under Art. 28 GDPR is in place with Hetzner. No transfer to third countries takes place.
Delivering the page technically requires a connection to your device. We do not store IP addresses or location data in log files.
4. Request form and demo access
Data: type of request, industry, business name, first and last name, email address, phone number, tax number, address including country, selected language, your consent with time and version of the consent text.
Purpose: handling your request, setting up demo access and preparing a licence agreement. Demo access is valid for 12 hours. We use the selected country to prepare the legal settings of your till.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps at your request). Retention after your request has been handled (see retention period) is based on Art. 6(1)(f) GDPR; our legitimate interest is proving and defending legal claims and preventing abusive repeated demo requests. If a contract is concluded, Art. 6(1)(c) GDPR applies (statutory retention obligations).
Required fields: all fields are required so that we can handle your request and set up a suitable till.
Recipients: the data is processed only by us and is not passed on to third parties. Our hosting provider (section 3) processes it on our behalf.
Retention period:
- No contract: we store your details until the end of the third calendar year after your request (standard limitation period, §§ 195, 199 German Civil Code) and then delete them. Example: request in October 2026 → deletion after 31 December 2029. The demo data itself (test receipts, test settings) is deleted when the demo expires.
- Contract concluded: your details become part of the contract and customer data. Statutory retention periods under § 257 German Commercial Code and § 147 German Fiscal Code apply: business letters 6 years, accounting vouchers (e.g. invoices) 8 years, books and financial statements 10 years, each from the end of the calendar year.
Abuse prevention: to prevent automated mass requests, we limit the number of requests in a short time and use a control field that is invisible to humans. No IP addresses are stored permanently.
5. Contact by email
If you email us, we process your details to handle your enquiry (Art. 6(1)(b) GDPR for contract-related enquiries, otherwise Art. 6(1)(f) GDPR).
6. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) (Art. 21). You can withdraw consent at any time with effect for the future (Art. 7(3) GDPR). An informal email to kontakt@elbe-systems.de is sufficient.
You can also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the country where you live or work. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information. The authority for your country is listed in section 7.
7. Country-specific information
Our offer is aimed at businesses in several countries. In all cases, processing is carried out by us in Germany; the data does not leave the European Economic Area. Depending on the country, the following also applies:
Germany
Legal basis: GDPR and the Federal Data Protection Act (BDSG); for access to end devices the TDDDG – however, this website does not store or read anything on your device.
Supervisory authority: Berliner Beauftragte für Datenschutz und Informationsfreiheit – datenschutz-berlin.de
Austria
Legal basis: GDPR and the Austrian Data Protection Act (DSG).
Supervisory authority: Österreichische Datenschutzbehörde – dsb.gv.at
Switzerland
Legal basis: For persons in Switzerland, the Swiss Federal Act on Data Protection (FADP/DSG) also applies. Your details are transferred to Germany; the Swiss Federal Council has determined that Germany provides an adequate level of data protection. You can exercise your rights (incl. access under Art. 25 FADP and data portability under Art. 28 FADP) informally by email.
Supervisory authority: Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB) – edoeb.admin.ch
Netherlands
Legal basis: GDPR (AVG) and the Dutch GDPR Implementation Act (UAVG).
Supervisory authority: Autoriteit Persoonsgegevens – autoriteitpersoonsgegevens.nl
Belgium
Legal basis: GDPR and the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.
Supervisory authority: Gegevensbeschermingsautoriteit / Autorité de protection des données – dataprotectionauthority.be
Luxembourg
Legal basis: GDPR and the Luxembourg Act of 1 August 2018 on the organisation of the National Data Protection Commission.
Supervisory authority: Commission nationale pour la protection des données (CNPD) – cnpd.public.lu
Poland
Legal basis: GDPR (RODO) and the Polish Act of 10 May 2018 on the protection of personal data.
Supervisory authority: Prezes Urzędu Ochrony Danych Osobowych (UODO) – uodo.gov.pl
8. Automated decision-making
No automated decision-making, including profiling, takes place.
Last updated: October 2026 · Version DS-2026-10 (draft)