Privacy Policy
As of: April 5, 2026
Applicable to: zemid.de and tca.zemid.de (TransformCheck)
1. Controller
The controller responsible for data processing on this website and the TransformCheck application within the meaning of the GDPR is:
ZEMID – Zentrum für Mittelstand und Digitalisierung GmbHRalf Schmidt
Neue Mainzer Str. 84
60311 Frankfurt am Main
Phone: +49 69 300 38 658
Email: hallo@zemid.de
Privacy: datenschutz@zemid.de
2. General Information
The protection of your personal data is important to us. This privacy policy informs you transparently about which personal data we collect, for what purposes we process it, and what rights you have.
This privacy policy applies both to our corporate website zemid.de and to the TransformCheck application at tca.zemid.de.
3. Hosting and Technical Provision
3.1 Hosting Provider
This website and the TransformCheck application are technically provided by Lovable Technology AB, Gothenburg, Sweden. Lovable acts as a data processor within the meaning of Art. 28 GDPR.
The database infrastructure is operated by Supabase (Supabase Inc., Singapore), which uses the AWS infrastructure in the eu-central-1 region (Frankfurt am Main, Germany).
Overview of hosting providers:
| Provider | Function | Location / Infrastructure | Privacy Document |
|---|---|---|---|
| Lovable Technology AB | Hosting, Backend, Edge Functions, Auth | Gothenburg, Sweden (EU) / AWS eu-central-1 Frankfurt | lovable.dev/data-processing-agreement |
| Supabase Inc. | Database infrastructure (sub-processor) | AWS eu-central-1 Frankfurt | supabase.com/privacy |
| IONOS SE | Domain registrar zemid.de | Montabaur, Germany | ionos.de/terms-gtc/terms-privacy/ |
3.2 Server Log Files
Each time our website is accessed, the web server automatically records information in server log files. This data is automatically deleted after a maximum of 8 weeks.
The following data is collected:
- IP address of the accessing device (shortened/anonymized)
- Date and time of the request
- Name and URL of the requested file
- Website from which the access was made (referrer URL)
- Browser and operating system used
- Host name of the accessing computer
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technical provision, stability, and security).
4. IONOS WebAnalytics
We use IONOS WebAnalytics for statistical analysis of website usage. This tool operates cookie-free and exclusively server-side. Only anonymized data is collected.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in website optimization).
5. Google Analytics 4
This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Consent Requirement
Google Analytics is only activated after your explicit consent via a cookie banner. You can revoke your consent at any time via the cookie settings.
Data Transfer to the USA
Google partially processes data on servers in the USA. The data transfer is based on the EU-U.S. Data Privacy Framework (DPF) and Standard Contractual Clauses pursuant to Art. 46 GDPR. User data is stored for a maximum of 14 months.
Legal basis: Art. 6(1)(a) GDPR (consent).
6. Cookies and Similar Technologies
Our website uses cookies and similar technologies (e.g., Local Storage). On your first visit, a cookie banner is displayed.
6.1 Technically Necessary Cookies
These cookies are essential for the basic functions of the website (login status, security features).
Legal basis: Art. 6(1)(f) GDPR.
6.2 Cloudflare Cookie (__cf_bm)
Our website is delivered via Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). Cloudflare sets the __cf_bm cookie (max. 30 minutes, no personal data) to protect against bot traffic. Cloudflare is certified under the EU-U.S. Data Privacy Framework.
Legal basis: Art. 6(1)(f) GDPR.
6.3 Analytics and Marketing Cookies
These cookies (e.g., Google Analytics) are only set after your explicit consent.
Legal basis: Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG.
7. Newsletter
7.1 Newsletter Delivery and Registration Form
On our website, you can subscribe to our newsletter. The registration form and newsletter delivery are technically provided by Rapidmail.
- Provider: rapidmail GmbH, Wentzingerstraße 21, 79106 Freiburg im Breisgau, Germany
- Function: Registration form, subscriber management, newsletter delivery
- Server location: Germany
- Privacy: rapidmail.de/datenschutz
Rapidmail acts as a data processor pursuant to Art. 28 GDPR. A data processing agreement (DPA) has been concluded. No third-country transfer occurs.
Data collected during newsletter registration:
At least your email address and – if provided – your name are collected. Registration follows a double opt-in procedure.
Revocation: You can revoke your consent at any time by using the unsubscribe link or by contacting datenschutz@zemid.de.
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with § 7(2) No. 3 UWG.
8. Contact Form and Email Communication
If you contact us via the contact form or by email, the following data is processed: name, email address, phone number (if provided), content of your message, and time of contact. This data is used exclusively to process your inquiry.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in processing contact inquiries).
9. TransformCheck – AI-powered Diagnostic Tool
9.1 Description and Purpose
TransformCheck is a web-based diagnostic application by ZEMID, accessible at tca.zemid.de. It enables mid-sized companies to conduct a structured self-assessment of their transformation readiness before an IT investment decision.
9.2 Data Collected and Processing Purposes
The following personal data is collected for using TransformCheck:
| Data Category | Fields | Required | Purpose |
|---|---|---|---|
| Contact data | First name, last name, email address | Yes | Personalization of risk report, contact option |
| Company data | Company name | Yes | Identification in report |
| Project context | Project type (ERP, CRM, AI Pilot, Other) | Yes | Risk weighting control |
| Assessment data | 5 × 8 Likert responses (scale 1–5) | Yes | Basis for transformation maturity analysis |
| Free-text comments | Up to 5 × max. 2,000 characters | No | In-depth AI analysis |
All processing steps are carried out exclusively on the basis of your explicit consent, given before the assessment via a checkbox.
Legal basis: Art. 6(1)(a) GDPR (consent).
9.3 Technical Processing and Storage
Your entries are stored in a PostgreSQL database (operated by Lovable Technology AB / Supabase on AWS eu-central-1, Frankfurt am Main). Your data is assigned via a randomly generated session token (UUID v4). No user account is created.
Additionally, the following data is temporarily stored in your browser's local storage:
- Session token (UUID v4)
- Context data (company name, name, email, project type)
- Responses and comments from all five assessment dimensions
- The complete AI-generated risk analysis
This local data does not leave your device and is removed when the assessment is restarted or through manual deletion in your browser settings.
9.4 Processing by Anthropic API – AI Analysis (Third-Country Transfer USA)
Note: This processing involves a transfer of personal data to the USA. It is carried out exclusively on the basis of your explicit consent.
To generate the individual risk report, the following data is transmitted to and processed by the Anthropic API:
| Transmitted Data | Content |
|---|---|
| Company name | Free text |
| Contact person | First and last name |
| Project type | e.g., "ERP Migration" |
| Assessment data | 5 × 8 numerical values (Likert scale 1–5) |
| Free-text comments | Up to 5 × max. 2,000 characters (if entered) |
| Aspect | Detail |
|---|---|
| Provider | Anthropic, Inc. |
| Location | 548 Market St PMB 90375, San Francisco, CA 94104, USA |
| Processing purpose | AI-powered evaluation and creation of the individual risk report |
| Transfer mechanism | SCCs (Modules 2 and 3) pursuant to Art. 46(2)(c) GDPR, incorporated in Anthropic’s DPA; Irish law as contractual basis |
| Data use by Anthropic | Data submitted via the API is not used for training AI models |
| Data processing | The DPA is automatically part of Anthropic’s Commercial Terms of Service. Available at: privacy.claude.com |
9.5 Retention and Deletion
Your data is automatically deleted 4 weeks after completing the assessment via an automated daily cron job at 3:00 AM.
You can request early deletion at any time by emailing datenschutz@zemid.de.
Legal basis: Art. 6(1)(a) GDPR (consent); deletion upon request pursuant to Art. 17 GDPR.
10. Blog Comments
If you leave a comment on our blog, we store the comment text, chosen name, email address (not publicly visible), IP address (anonymized after 7 days), and date and time. Comments remain publicly visible until deletion upon request.
Legal basis: Art. 6(1)(a) GDPR (consent) and Art. 6(1)(f) GDPR (legitimate interest in spam prevention).
11. Overview of Data Processors
For the provision of our services, we engage the following data processors pursuant to Art. 28 GDPR:
| Provider | Function | Location | Transfer Mechanism |
|---|---|---|---|
| Lovable Technology AB | Hosting, Backend, Database, Edge Functions, Auth (zemid.de and tca.zemid.de) | Gothenburg, Sweden (EU/EEA) | Within EU/EEA – no third-country transfer |
| Supabase Inc. | Database infrastructure (sub-processor of Lovable) on AWS eu-central-1 | Singapore / AWS Frankfurt | Data storage in EU (Frankfurt) |
| rapidmail GmbH | Newsletter registration form and newsletter delivery | Freiburg im Breisgau, Germany | Within Germany – no third-country transfer; DPA concluded |
| Anthropic, Inc. | AI analysis via API (TransformCheck only) | San Francisco, USA | SCCs (Modules 2 and 3) pursuant to Art. 46 GDPR |
| Google Ireland Limited | Google Analytics 4 (consent only) | Dublin, Ireland / USA | DPF + SCCs |
| Cloudflare, Inc. | CDN, DDoS protection | San Francisco, USA | DPF + SCCs |
12. Your Rights as a Data Subject
You have the following rights under Art. 15 ff. GDPR:
- Right of access (Art. 15 GDPR): You can obtain information about the personal data we process.
- Right to rectification (Art. 16 GDPR): You can request the correction of inaccurate or the completion of incomplete data.
- Right to erasure (Art. 17 GDPR): You can request the deletion of your personal data.
- Right to restriction (Art. 18 GDPR): You can request the restriction of processing of your data.
- Right to data portability (Art. 20 GDPR): You have the right to receive your data in a machine-readable format.
- Right to object (Art. 21 GDPR): You can object to the processing of your data.
- Right of withdrawal (Art. 7(3) GDPR): You can withdraw your consent at any time with effect for the future.
To exercise your rights, please contact: datenschutz@zemid.de
13. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority.
The supervisory authority responsible for us is:
The Hessian Commissioner for Data Protection and Freedom of InformationPostfach 3163
65021 Wiesbaden
Phone: +49 611 1408-0
Email: poststelle@datenschutz.hessen.de
Website: datenschutz.hessen.de
14. Currency and Changes to This Privacy Policy
This privacy policy is dated April 5, 2026, and reflects the current legal situation.
We reserve the right to adapt this privacy policy. The current version can always be found on this page.
In the event of significant changes affecting your rights, we will inform you separately.
We recommend reviewing this privacy policy regularly.
