Legal
Privacy Policy
Table of contents
- 1. Subject matter and scope
- 2. Controller
- 3. Visiting our website & hosting
- 4. Contacting us and contact form
- 5. Customer and prospect management (CRM)
- 6. Cookies
- 7. Microsoft 365
- 8. Social media
- 9. Job applications
- 10. Video conferences
- 11. Recipients of data
- 12. Your rights
- 13. Mandatory information and profiling
- 14. Storage and deletion
- 15. Information security
- 16. License plate recognition on our parking areas
- 17. Changes to this privacy policy
As of: September 2026
1. Subject matter and scope
We take the protection of your personal data very seriously. This privacy policy informs you about which personal data we collect, how we process it and for what purposes. It applies to all websites and digital services of Hello:Parker GmbH, in particular to www.helloparker.com as well as the web-based software and the Hello:Parker Help Center.
We process personal data exclusively in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and other applicable data protection regulations.
2. Controller
The controller within the meaning of the GDPR is:
Hello:Parker GmbH
Henkestr. 8
91054 Erlangen
Deutschland
Email: info@helloparker.com
We have voluntarily appointed a data protection officer (contact details in the imprint). If you have any questions regarding data protection, you can also contact us directly at the email address given above.
3. Visiting our website & hosting
3.1 Log files
Each time our website is accessed, the system automatically records the following data in server log files:
- IP address of the accessing device
- Browser type and browser version
- Operating system used
- Name and URL of the retrieved file
- Date and time of access
- Volume of data transferred
- Referring URL (referrer)
This data is technically necessary to display the website and to ensure its security and stability (e.g. to detect and ward off attacks). It is not combined with other data sources. The log files are deleted after no more than 7 days.
Legal basis: Art. 6 (1) lit. f) GDPR (legitimate interest in the secure and stable operation of our website).
3.2 Hosting with Hetzner
Our website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hetzner acts as a processor on our behalf on the basis of a data processing agreement pursuant to Art. 28 GDPR. Data processing takes place exclusively in data centers within the European Union.
Legal basis: Art. 6 (1) lit. f) GDPR.
4. Contacting us and contact form
If you contact us via our contact form or by email, the information you provide (e.g. name, email address, telephone number, message) is stored and processed in order to handle your request. This data is not passed on to third parties unless this is necessary for the performance of a contract.
To handle your enquiry, requests submitted through the contact form are transferred automatically to our CRM system (see section 5). Alongside the details you provide, technical information about the origin of your visit is stored where available – such as the page you visited beforehand, the page from which you submitted the form, and identifiers from advertisements through which you reached us. Pipedrive acts as a processor on our behalf and is not considered a third party under data protection law. Enquiries from parkers about a specific parking event are not transferred to the CRM.
Legal basis: Art. 6 (1) lit. f) GDPR (legitimate interest in communicating with prospective customers) or Art. 6 (1) lit. b) GDPR, where contact takes place within the scope of an existing or intended contractual relationship.
The data collected in the course of contacting us is deleted as soon as the request has been conclusively processed and no statutory retention obligations preclude this.
5. Customer and prospect management (CRM)
To manage our customer, prospect and partner relationships, we use Pipedrive, a CRM system provided by Pipedrive OÜ, Mustamäe tee 3a, 10615 Tallinn, Estonia. Pipedrive acts as a processor on our behalf on the basis of a data processing agreement pursuant to Art. 28 GDPR.
Within the scope of the CRM use, personal data such as name, contact details, communication history and contract-related information is processed. Pipedrive may process data on servers within and outside the EU. For transfers to third countries without an adequate level of data protection, we ensure that appropriate safeguards pursuant to Art. 46 GDPR (standard contractual clauses) are in place.
Legal basis: Art. 6 (1) lit. b) GDPR (performance of a contract and pre-contractual measures) as well as Art. 6 (1) lit. f) GDPR (legitimate interest in the efficient maintenance of customer relationships).
6. Cookies
Our website uses cookies and similar technologies. We use technically necessary cookies without your consent; we only use optional cookies for statistics and marketing after you have explicitly agreed to them in the cookie banner.
6.1 Technically necessary cookies
These cookies are required for the proper operation of the website, for example to save your cookie settings or to deliver the website securely. They do not store any personal data that would allow conclusions to be drawn about you and are automatically deleted at the end of your browser session or after a set period, depending on their purpose.
Legal basis: Art. 6 (1) lit. f) GDPR (legitimate interest in a functional and secure operation of our website).
6.2 Cookie consent
On your first visit to our website, we ask you via a cookie banner whether you consent to the use of optional cookies for statistics ("Analytics") and company recognition ("Marketing"). You can change or withdraw your choice at any time via the "Cookie settings" link in the footer of our website.
Legal basis: Art. 6 (1) lit. a) GDPR (consent). You can withdraw your consent at any time with effect for the future.
6.3 Google Tag Manager
To manage the analytics and marketing services described below, we use Google Tag Manager provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The Tag Manager itself does not set any cookies of its own and does not collect personal data; it merely loads the services described below in line with your cookie settings.
Legal basis: Art. 6 (1) lit. a) GDPR (consent), insofar as consent-requiring services are loaded via the Tag Manager.
6.4 Google Analytics 4
Once you have given consent to the "Analytics" category, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics creates pseudonymous usage profiles and evaluates, for example, page views, time spent, device used and approximate geographic origin (based on IP address). Your IP address is shortened by Google and not merged with other Google data.
Google also processes data in the USA. Google is certified under the EU-U.S. Data Privacy Framework, which is intended to ensure an adequate level of data protection for transfers to the USA.
Legal basis: Art. 6 (1) lit. a) GDPR (consent).
6.5 Microsoft Clarity
Once you have given consent to the "Analytics" category, we also use Microsoft Clarity, a service provided by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA. Clarity creates anonymised heatmaps and session recordings to understand how visitors use our website (e.g. clicks, mouse movements, scrolling behaviour). Input fields and other potentially sensitive content are automatically masked.
Microsoft is certified under the EU-U.S. Data Privacy Framework.
Legal basis: Art. 6 (1) lit. a) GDPR (consent).
6.6 Leadfeeder (Dealfront)
Once you have given consent to the "Marketing" category, we use Leadfeeder, a product of Dealfront Group Oy, Helsinki, Finland, to identify companies visiting our website. Your IP address is matched against a database of known company IP ranges in order to draw conclusions about the company likely visiting; this service is not intended to identify individual persons. In addition, pages visited, time spent and the referring URL are recorded.
As Dealfront/Leadfeeder is based in Finland and therefore within the European Union, no transfer of personal data to a third country takes place in this respect.
Legal basis: Art. 6 (1) lit. a) GDPR (consent).
6.7 Calendly (appointment booking)
On our page "/termin" we embed a scheduling calendar provided by Calendly, LLC, 271 17th Street NW, Suite 1000, Atlanta, GA 30363, USA, which allows you to book a conversation with us directly online. When you visit this page, your IP address and technical data about your device are transmitted to Calendly; when booking an appointment, the details you provide (e.g. name, email address) are transmitted as well.
As this embed only operates on the page you specifically visit in order to book an appointment, we do not require separate consent via the cookie banner for it. Legal basis: Art. 6 (1) lit. b) GDPR (pre-contractual measure at your request) or Art. 6 (1) lit. f) GDPR (legitimate interest in a straightforward way to schedule appointments).
Calendly also processes data in the USA. Calendly is certified under the EU-U.S. Data Privacy Framework, which is intended to ensure an adequate level of data protection for transfers to the USA.
6.8 Google Ads
Subject to consent for the "Marketing" category, we may in future also use Google Ads of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to measure the effectiveness of our online advertisements (conversion tracking) and to show tailored ads on other websites to users who have already visited our website (remarketing). This uses cookies that make it possible to link a visit to our website with later actions (e.g. clicking on an ad).
Google also processes data in the USA. Google is certified under the EU-U.S. Data Privacy Framework, which is intended to ensure an adequate level of data protection for transfers to the USA.
Legal basis: Art. 6(1)(a) GDPR (consent).
6.9 LinkedIn Ads (Insight Tag)
Subject to consent for the "Marketing" category, we may in future also use the LinkedIn Insight Tag of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, to measure the effectiveness of our LinkedIn ads (conversion tracking) and to show targeted advertising on LinkedIn to visitors of our website (retargeting). This sets a cookie; certain browser and device information may be transmitted to LinkedIn in hashed form.
LinkedIn may also process data outside the European Union, including in the USA. LinkedIn is certified under the EU-U.S. Data Privacy Framework.
Legal basis: Art. 6(1)(a) GDPR (consent).
7. Microsoft 365
For email communication, scheduling, internal collaboration and video conferences we use Microsoft 365, provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.
The following services may be used within the scope of Microsoft 365:
- Exchange Online / Outlook – email communication
- Microsoft Teams – video conferences, chats and online meetings
- SharePoint / OneDrive – document storage and collaboration
Microsoft acts as a processor on the basis of a data processing agreement pursuant to Art. 28 GDPR. Microsoft may transfer data to third countries (in particular the USA). Standard contractual clauses pursuant to Art. 46 GDPR have been agreed for this purpose. Further information can be found in the Microsoft privacy statement.
When participating in video meetings with us, the following data is processed, among others: name (or pseudonym), IP address, device information, audio and video data (if you activate microphone/camera). Recordings of meetings are only made with the explicit consent of all participants.
Where Microsoft transfers data to the USA, we additionally rely on the European Commission's adequacy decision regarding the EU-US Data Privacy Framework. Microsoft is certified under the Data Privacy Framework.
Legal basis: Art. 6 (1) lit. b) GDPR (performance of a contract) and Art. 6 (1) lit. f) GDPR (legitimate interest in efficient internal and external communication).
8. Social media
8.1 Links to our profiles
Our website contains links to our profiles on LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland) and Instagram (Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland). When you click on a link, you leave our website. From that point on, the privacy policy of the respective network applies.
The mere embedding of links does not transfer any data to the networks.
8.2 Our company profiles
We operate our own company pages on LinkedIn and Instagram. When you visit these pages, the respective platform operator processes data about your visit (possibly also if you are not logged in). We are jointly responsible for this processing together with the platform operator (Art. 26 GDPR). For questions regarding data processing by the platforms, we refer you to the privacy notices of LinkedIn and Instagram/Meta.
Currently, on our website we use no social media pixels or tracking tags of the platforms; for our planned use of LinkedIn Ads, see Section 6.9.
Legal basis for our use of the company profiles: Art. 6 (1) lit. f) GDPR (legitimate interest in our external presentation and customer communication).
9. Job applications
If you apply to us, we process your application documents (name, contact details, CV, references, etc.) exclusively for the purpose of carrying out the application procedure. The data is not passed on to unauthorized third parties.
If no employment relationship is established, we delete your application documents after completion of the procedure, at the latest after 6 months – unless you have consented to longer storage in our talent pool.
Legal basis: § 26 BDSG in conjunction with Art. 6 (1) lit. b) GDPR.
10. Video conferences
For online meetings and video conferences we use Microsoft Teams (see Section 7). When participating, name, IP address, device data as well as audio and video content are processed. We recommend using a pseudonym if necessary. Recordings are only made with explicit consent.
Legal basis: Art. 6 (1) lit. b) GDPR or Art. 6 (1) lit. f) GDPR.
11. Recipients of data
Within our company, only those employees who need it to perform their tasks are granted access to your data (need-to-know principle).
We use the following processors with whom data processing agreements pursuant to Art. 28 GDPR are in place:
- Hetzner Online GmbH – web hosting (Germany)
- Microsoft Ireland Operations Limited – M365 (email, Teams, SharePoint)
- Pipedrive OÜ – CRM system (Estonia / EU)
Any further disclosure to third parties only takes place if this is required by law, you have consented or it is necessary for the performance of a contract.
In the event of violations of the terms of use of our parking areas, we also transfer license plate data to our partner, acceto GmbH, which acts independently in this regard. For more information, see Section 16 "License plate recognition on our parking areas".
12. Your rights
As a data subject, you have the following rights:
- Access (Art. 15 GDPR) – you may request information about the data we process.
- Rectification (Art. 16 GDPR) – you may request the correction of inaccurate data.
- Erasure (Art. 17 GDPR) – under certain conditions you may request the erasure of your data.
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR) – you may object at any time to processing based on legitimate interests.
- Withdrawal of consent (Art. 7 (3) GDPR) – consent granted may be withdrawn at any time with effect for the future.
To exercise your rights, please contact: info@helloparker.com
You also have the right to lodge a complaint with the competent data protection supervisory authority:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
www.lda.bayern.de
13. Mandatory information and profiling
The provision of personal data is generally voluntary. However, certain information is required for the conclusion of a contract or the processing of a request – we point this out in each case.
Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place at our company.
14. Storage and deletion
We store personal data only for as long as is necessary for the respective processing purpose or as required by statutory retention obligations (e.g. tax-law periods of up to 10 years). Thereafter, the data is routinely deleted or anonymized.
15. Information security
We take technical and organizational measures (TOMs) in line with the current state of the art to protect your data against unauthorized access, loss or misuse. Our website uses an encrypted connection (TLS/SSL). Internal access to personal data is restricted to authorized employees.
16. License plate recognition on our parking areas
On parking areas that we operate on behalf of the respective property owner, we use a license-plate-based control and management system. Cameras at the entrances and exits automatically capture the license plate and the time of entry and exit as vehicles pass through. Only the license plate and the timestamp are captured – no faces, no vehicle occupants and no other personal data.
The parking duration is calculated based on the recorded entry and exit times, and it is checked whether a valid parking authorization exists or whether the applicable parking fee has been paid in time. Payment of parking fees and legitimation for authorized parking are possible for up to 48 hours after the parking event has ended.
If no payment or legitimation is made within this period, the parking event is automatically classified by the system as a violation of the parking area's terms of use and is transferred to our partner, acceto GmbH, for further processing. Acceto GmbH determines, in its own name, the registered keeper of the vehicle by means of a keeper inquiry with the competent authority and takes over the further sanctioning of the parking violation – without involving an external debt collection company.
The recorded license plates are processed exclusively in Germany and are stored and deleted in accordance with the statutory requirements of the GDPR as soon as they are no longer required for the purposes stated above.
Legal basis: Art. 6(1)(b) GDPR (performance of the contractual or pre-contractual obligations associated with the use of the parking area) and Art. 6(1)(f) GDPR (legitimate interest in enforcing the applicable terms of use and in protecting the parking area from unauthorized use).
17. Changes to this privacy policy
We update this privacy policy in the event of legal changes or adjustments to our services. The current version can always be found on this page. The date of the last update is indicated at the end.
As of: September 2026