ZEMID – Zentrum für Mittelstand und Digitalisierung

    Privacy Policy

    As of: April 5, 2026

    Applicable to: zemid.de and tca.zemid.de (TransformCheck)

    1. Controller

    The controller responsible for data processing on this website and the TransformCheck application within the meaning of the GDPR is:

    ZEMID – Zentrum für Mittelstand und Digitalisierung GmbH
    Ralf Schmidt
    Neue Mainzer Str. 84
    60311 Frankfurt am Main
    Phone: +49 69 300 38 658
    Email: hallo@zemid.de
    Privacy: datenschutz@zemid.de

    2. General Information

    The protection of your personal data is important to us. This privacy policy informs you transparently about which personal data we collect, for what purposes we process it, and what rights you have.

    This privacy policy applies both to our corporate website zemid.de and to the TransformCheck application at tca.zemid.de.

    3. Hosting and Technical Provision

    3.1 Hosting Provider

    This website and the TransformCheck application are technically provided by Lovable Technology AB, Gothenburg, Sweden. Lovable acts as a data processor within the meaning of Art. 28 GDPR.

    The database infrastructure is operated by Supabase (Supabase Inc., Singapore), which uses the AWS infrastructure in the eu-central-1 region (Frankfurt am Main, Germany).

    Overview of hosting providers:

    ProviderFunctionLocation / InfrastructurePrivacy Document
    Lovable Technology ABHosting, Backend, Edge Functions, AuthGothenburg, Sweden (EU) / AWS eu-central-1 Frankfurtlovable.dev/data-processing-agreement
    Supabase Inc.Database infrastructure (sub-processor)AWS eu-central-1 Frankfurtsupabase.com/privacy
    IONOS SEDomain registrar zemid.deMontabaur, Germanyionos.de/terms-gtc/terms-privacy/

    3.2 Server Log Files

    Each time our website is accessed, the web server automatically records information in server log files. This data is automatically deleted after a maximum of 8 weeks.

    The following data is collected:

    • IP address of the accessing device (shortened/anonymized)
    • Date and time of the request
    • Name and URL of the requested file
    • Website from which the access was made (referrer URL)
    • Browser and operating system used
    • Host name of the accessing computer

    Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technical provision, stability, and security).

    4. IONOS WebAnalytics

    We use IONOS WebAnalytics for statistical analysis of website usage. This tool operates cookie-free and exclusively server-side. Only anonymized data is collected.

    Legal basis: Art. 6(1)(f) GDPR (legitimate interest in website optimization).

    5. Google Analytics 4

    This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

    Consent Requirement

    Google Analytics is only activated after your explicit consent via a cookie banner. You can revoke your consent at any time via the cookie settings.

    Data Transfer to the USA

    Google partially processes data on servers in the USA. The data transfer is based on the EU-U.S. Data Privacy Framework (DPF) and Standard Contractual Clauses pursuant to Art. 46 GDPR. User data is stored for a maximum of 14 months.

    Legal basis: Art. 6(1)(a) GDPR (consent).

    6. Cookies and Similar Technologies

    Our website uses cookies and similar technologies (e.g., Local Storage). On your first visit, a cookie banner is displayed.

    6.1 Technically Necessary Cookies

    These cookies are essential for the basic functions of the website (login status, security features).

    Legal basis: Art. 6(1)(f) GDPR.

    6.2 Cloudflare Cookie (__cf_bm)

    Our website is delivered via Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). Cloudflare sets the __cf_bm cookie (max. 30 minutes, no personal data) to protect against bot traffic. Cloudflare is certified under the EU-U.S. Data Privacy Framework.

    Legal basis: Art. 6(1)(f) GDPR.

    6.3 Analytics and Marketing Cookies

    These cookies (e.g., Google Analytics) are only set after your explicit consent.

    Legal basis: Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG.

    7. Newsletter

    7.1 Newsletter Delivery and Registration Form

    On our website, you can subscribe to our newsletter. The registration form and newsletter delivery are technically provided by Rapidmail.

    • Provider: rapidmail GmbH, Wentzingerstraße 21, 79106 Freiburg im Breisgau, Germany
    • Function: Registration form, subscriber management, newsletter delivery
    • Server location: Germany
    • Privacy: rapidmail.de/datenschutz

    Rapidmail acts as a data processor pursuant to Art. 28 GDPR. A data processing agreement (DPA) has been concluded. No third-country transfer occurs.

    Data collected during newsletter registration:

    At least your email address and – if provided – your name are collected. Registration follows a double opt-in procedure.

    Revocation: You can revoke your consent at any time by using the unsubscribe link or by contacting datenschutz@zemid.de.

    Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with § 7(2) No. 3 UWG.

    8. Contact Form and Email Communication

    If you contact us via the contact form or by email, the following data is processed: name, email address, phone number (if provided), content of your message, and time of contact. This data is used exclusively to process your inquiry.

    Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in processing contact inquiries).

    9. TransformCheck – AI-powered Diagnostic Tool

    9.1 Description and Purpose

    TransformCheck is a web-based diagnostic application by ZEMID, accessible at tca.zemid.de. It enables mid-sized companies to conduct a structured self-assessment of their transformation readiness before an IT investment decision.

    9.2 Data Collected and Processing Purposes

    The following personal data is collected for using TransformCheck:

    Data CategoryFieldsRequiredPurpose
    Contact dataFirst name, last name, email addressYesPersonalization of risk report, contact option
    Company dataCompany nameYesIdentification in report
    Project contextProject type (ERP, CRM, AI Pilot, Other)YesRisk weighting control
    Assessment data5 × 8 Likert responses (scale 1–5)YesBasis for transformation maturity analysis
    Free-text commentsUp to 5 × max. 2,000 charactersNoIn-depth AI analysis

    All processing steps are carried out exclusively on the basis of your explicit consent, given before the assessment via a checkbox.

    Legal basis: Art. 6(1)(a) GDPR (consent).

    9.3 Technical Processing and Storage

    Your entries are stored in a PostgreSQL database (operated by Lovable Technology AB / Supabase on AWS eu-central-1, Frankfurt am Main). Your data is assigned via a randomly generated session token (UUID v4). No user account is created.

    Additionally, the following data is temporarily stored in your browser's local storage:

    • Session token (UUID v4)
    • Context data (company name, name, email, project type)
    • Responses and comments from all five assessment dimensions
    • The complete AI-generated risk analysis

    This local data does not leave your device and is removed when the assessment is restarted or through manual deletion in your browser settings.

    9.4 Processing by Anthropic API – AI Analysis (Third-Country Transfer USA)

    Note: This processing involves a transfer of personal data to the USA. It is carried out exclusively on the basis of your explicit consent.

    To generate the individual risk report, the following data is transmitted to and processed by the Anthropic API:

    Transmitted DataContent
    Company nameFree text
    Contact personFirst and last name
    Project typee.g., "ERP Migration"
    Assessment data5 × 8 numerical values (Likert scale 1–5)
    Free-text commentsUp to 5 × max. 2,000 characters (if entered)
    AspectDetail
    ProviderAnthropic, Inc.
    Location548 Market St PMB 90375, San Francisco, CA 94104, USA
    Processing purposeAI-powered evaluation and creation of the individual risk report
    Transfer mechanismSCCs (Modules 2 and 3) pursuant to Art. 46(2)(c) GDPR, incorporated in Anthropic’s DPA; Irish law as contractual basis
    Data use by AnthropicData submitted via the API is not used for training AI models
    Data processingThe DPA is automatically part of Anthropic’s Commercial Terms of Service. Available at: privacy.claude.com

    9.5 Retention and Deletion

    Your data is automatically deleted 4 weeks after completing the assessment via an automated daily cron job at 3:00 AM.

    You can request early deletion at any time by emailing datenschutz@zemid.de.

    Legal basis: Art. 6(1)(a) GDPR (consent); deletion upon request pursuant to Art. 17 GDPR.

    10. Blog Comments

    If you leave a comment on our blog, we store the comment text, chosen name, email address (not publicly visible), IP address (anonymized after 7 days), and date and time. Comments remain publicly visible until deletion upon request.

    Legal basis: Art. 6(1)(a) GDPR (consent) and Art. 6(1)(f) GDPR (legitimate interest in spam prevention).

    11. Overview of Data Processors

    For the provision of our services, we engage the following data processors pursuant to Art. 28 GDPR:

    ProviderFunctionLocationTransfer Mechanism
    Lovable Technology ABHosting, Backend, Database, Edge Functions, Auth (zemid.de and tca.zemid.de)Gothenburg, Sweden (EU/EEA)Within EU/EEA – no third-country transfer
    Supabase Inc.Database infrastructure (sub-processor of Lovable) on AWS eu-central-1Singapore / AWS FrankfurtData storage in EU (Frankfurt)
    rapidmail GmbHNewsletter registration form and newsletter deliveryFreiburg im Breisgau, GermanyWithin Germany – no third-country transfer; DPA concluded
    Anthropic, Inc.AI analysis via API (TransformCheck only)San Francisco, USASCCs (Modules 2 and 3) pursuant to Art. 46 GDPR
    Google Ireland LimitedGoogle Analytics 4 (consent only)Dublin, Ireland / USADPF + SCCs
    Cloudflare, Inc.CDN, DDoS protectionSan Francisco, USADPF + SCCs

    12. Your Rights as a Data Subject

    You have the following rights under Art. 15 ff. GDPR:

    • Right of access (Art. 15 GDPR): You can obtain information about the personal data we process.
    • Right to rectification (Art. 16 GDPR): You can request the correction of inaccurate or the completion of incomplete data.
    • Right to erasure (Art. 17 GDPR): You can request the deletion of your personal data.
    • Right to restriction (Art. 18 GDPR): You can request the restriction of processing of your data.
    • Right to data portability (Art. 20 GDPR): You have the right to receive your data in a machine-readable format.
    • Right to object (Art. 21 GDPR): You can object to the processing of your data.
    • Right of withdrawal (Art. 7(3) GDPR): You can withdraw your consent at any time with effect for the future.

    To exercise your rights, please contact: datenschutz@zemid.de

    13. Right to Lodge a Complaint

    You have the right to lodge a complaint with a data protection supervisory authority.

    The supervisory authority responsible for us is:

    The Hessian Commissioner for Data Protection and Freedom of Information
    Postfach 3163
    65021 Wiesbaden
    Phone: +49 611 1408-0
    Email: poststelle@datenschutz.hessen.de
    Website: datenschutz.hessen.de

    14. Currency and Changes to This Privacy Policy

    This privacy policy is dated April 5, 2026, and reflects the current legal situation.

    We reserve the right to adapt this privacy policy. The current version can always be found on this page.

    In the event of significant changes affecting your rights, we will inform you separately.

    We recommend reviewing this privacy policy regularly.