assistora
HomeSmartCheckSmartCalcSmartMatchContact
DEENFRIT
Login Login

Privacy Policy

1. Introduction

This website is operated by: emvau GmbH - assistora.

It is very important to us to handle our website visitors' data confidentially and to protect it in the best possible way. For this reason, we make every effort to comply with the requirements of the GDPR.

Below we explain how we process your data on our website. We use language that is as clear and transparent as possible so that you really understand what happens to your data.

2. General information

2.1 Processing of personal data and other terms

Data protection applies to the processing of personal data. Personal data means all data with which you can be personally identified. This is, for example, the IP address of the device (PC, laptop, smartphone, etc.) you are currently using. Such data is processed when 'something happens to it'. Here, for example, the IP is transmitted from the browser to our provider and automatically stored there. This is then a processing (according to Art. 4 No. 2 GDPR) of personal data (according to Art. 4 No. 1 GDPR).

These and other legal definitions can be found in Art. 4 GDPR.

2.2 Applicable regulations/laws - GDPR, BDSG and TDDDG

The scope of data protection is regulated by law. In this case, these are the GDPR (General Data Protection Regulation) as a European regulation and the BDSG (Federal Data Protection Act) as a national law.

In addition, the TDDDG supplements the provisions of the GDPR as far as the use of cookies is concerned.

2.3 The person responsible

The controller within the meaning of the GDPR is responsible for data processing on this website. This is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

You can reach the person responsible at:

emvau GmbH - assistora

Blücherstrasse 32 75177 Pforzheim

datenschutz@emvau-agentur.de

2.4 Data Protection Officer

We have appointed a data protection officer for our company. You can reach him under:

simply Legal GmbH

Sebastian Schenk

Burkarderstr. 36, 97082 Würzburg

dpo@dieter-datenschutz.de

2.5 How data is generally processed on this website

As we have already established, there is data (e.g. IP address) that is collected automatically. This data is mainly required for the technical provision of the website. If we also use personal data or collect other data, we will inform you of this or ask for your consent.

You consciously provide us with other personal data.

You will find detailed information on this below.

2.6 Your rights

The GDPR provides you with comprehensive rights. These include, for example, free information about the origin, recipient and purpose of your stored personal data. You can also request the rectification, blocking or erasure of this data or lodge a complaint with the competent data protection supervisory authority. You can revoke your consent at any time.

You can find out what these rights look like in detail and how to exercise them in the last section of this Privacy Policy.

2.7 Data protection - Our view

Data protection is more than just a chore for us! Personal data has great value and careful handling of this data should be a matter of course in our digitalized world. As a website visitor, you should also be able to decide for yourself what "happens" to your data, when and by whom. That is why we are committed to complying with all legal regulations, only collect the data we need and, of course, treat it confidentially.

2.8 Forwarding and deletion

The transfer and deletion of data are also important and sensitive issues. We would therefore like to briefly inform you in advance about our general approach to this.

Data will only be passed on on the basis of a legal basis and only if this is unavoidable. This may be the case in particular if it is a so-called Data Processor and a Data Processing Agreement has been concluded in accordance with Art. 28 GDPR.

We delete your data when the purpose and legal basis for processing no longer apply and the deletion does not conflict with any other legal obligations. Art. 17 GDPR also provides a 'good' overview of this.

For further information, please refer to this Privacy Policy and contact the controller if you have any specific questions.

2.9 Hosting

Hetzner

We use the services of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, to host our website. Hetzner provides the technical infrastructure for the storage, delivery and management of all content provided on the website, including hosting of websites, domains, databases, backups and e-mail functionalities. When using Hetzner, in particular customer master data, all website data stored on the servers, usage and access logs (e.g. IP addresses and access data) and backup data are processed. The data processing serves to provide a functional, secure and efficient website infrastructure and to fulfill legal storage and verification obligations. The legal basis is Art. 6 para. 1 lit. f GDPR due to the legitimate interest in a secure and efficient provision of the online offer, as well as Art. 6 para. 1 lit. b GDPR, insofar as the processing is necessary for the fulfillment of a contract or pre-contractual measures. Hetzner does not set its own cookies as part of the hosting service. There is no transfer of personal data to third countries, as the data is processed exclusively in data centers within the EU and is not transferred to third countries. The stored data is deleted as soon as it is no longer required to achieve the purpose for which it was collected; this applies in particular in the event of termination of the hosting contract, revocation or expiry of statutory retention periods. Further information can be found at: https://www.hetzner.com/legal/privacy-policy/

2.10 Legal basis

The processing of personal data always requires a legal basis. The GDPR provides the following possibilities in Art. 6 para. 1 sentence 1:

a) The data subject has given their consent to the processing of their personal data for one or more specific purposes;

b) Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

c) The processing is necessary for compliance with a legal obligation to which the controller is subject;

d) Processing is necessary in order to protect the vital interests of the data subject or of another natural person;

e) The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

f) Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

In the following sections, we will provide you with the specific legal basis for the respective processing.

3. What happens on our website

When you visit our website, we process your personal data.

We use SSL or TLS encryption to provide the best possible protection against unauthorized access by third parties. You can recognize this encrypted connection by the https:// or lock symbol in the address bar of your browser.

Below you can find out what data is collected when you visit our website, for what purpose this is done and on what legal basis.

3.1 Data collection when accessing the website

When you visit the website, information is automatically stored in so-called server log files. This is the following information:

• Browser type and browser version

• Operating system used

• Referrer URL

• Host name of the accessing computer

• Time of the server request

• IP address

This data is required temporarily in order to be able to display our website to you permanently and without any problems. In particular, this data is used for the following purposes:

• System security of the website

• System stability of the website

• Troubleshooting on the website

• Establishing a connection to the website

• Presentation of the website

Data processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR and is based on our legitimate interest in the processing of this data, in particular our interest in the functionality of the website and its security.

Where possible, this data is stored in pseudonymized form and deleted once the respective purpose has been achieved.

If the server log files make it possible to identify the data subject, the data is stored for a maximum period of 14 days. An exception is made if a security-relevant event occurs. In this case, the server log files are stored until the security-relevant event has been resolved and finally clarified.

Otherwise, no merging with other data takes place.

3.2 Data processing through user input

3.2.1 Use of AI

Personal data of visitors to this website may be processed using artificial intelligence (e.g. for the automatic evaluation of contact forms, by means of an AI chatbot or to optimize internal processes).

In particular, contact data and form or chat content may be recorded and analyzed by AI models. The legal basis for this is Art. 6 para. 1 lit. a GDPR (if consent has been given) or Art. 6 para. 1 lit. f GDPR (legitimate interest in increasing efficiency). Data is only transferred to third parties (e.g. CRM providers or external AI service providers) if this is necessary to achieve the stated purposes. The tools used are listed in this Privacy Policy in the context of their functionality and details are provided.

3.2.2 Own data collection

We offer the following (service) on our website: assistora is an automation platform that relieves workshops of administrative and business management processes. The solution is based on a well-founded and continuously growing database of industry-specific knowledge, court rulings and documentation, which structures (and intelligently automates) processes and uses artificial intelligence (AI) to make optimization potential visible. .

We collect the following data for this purpose:

• Name

• E-mail address

• Address

• Phone number

• License plate number, VIN (vehicle identification number)

The legal basis for this data processing is Art. 6 para. 1 lit. b GDPR.

The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.

3.2.3 Comment function

The website visitor has the opportunity to write a comment on our website.

For security reasons, we collect the IP address in order to prevent misuse and to be able to take criminal action if necessary, as well as the content of the comment and the (user) name provided for publication on our website.

We also process your e-mail address to ensure that you are a genuine user and not an automated program (spam). The e-mail address can also be used to contact you in the event of queries or responses to your comment.

The data is processed with consent in accordance with Art. 6 para. 1 lit. a GDPR. Consent can be revoked at any time.

The data collected will be stored as long as the comment is publicly accessible on the website or as long as this is required for legal reasons. The data will then be deleted, unless statutory retention periods prevent this.

3.2.4 Contact us

a) e-mail

When you contact us by email, we process your email address and any other data contained in the email. This data is stored on the mail server and in some cases on the respective end devices. Depending on the request, the legal basis for this is regularly Art. 6 para. 1 lit. f GDPR or Art. 6 para. 1 lit. b GDPR. The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.

b) Telephone

If you contact us by telephone, the call data may be stored in pseudonymized form on the respective end device and with the telecommunications provider used. Personal data collected during the telephone call will only be processed in order to process your request. Depending on the request, the legal basis for this is regularly Art. 6 para. 1 lit. f GDPR or Art. 6 para. 1 lit. b GDPR. The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.

c) Contact form

Contact form (own development)

A self-developed contact form is provided on our website to enable direct contact. The form is used to enter and transmit personal inquiries and we, the website operator, are solely responsible for its technical content. The contact form is generally used to process the communication content entered (such as name, email address and message text), technical metadata (e.g. IP address, time of transmission, browser used) and any other information provided by users. This data is processed for the purpose of processing and responding to inquiries and initiating or processing contractual relationships. The legal basis for the processing is Art. 6 para. 1 lit. b GDPR for the implementation of (pre-)contractual measures or Art. 6 para. 1 lit. f GDPR on the basis of the legitimate interest in efficient and user-friendly communication. No cookies are set as part of the contact form. Personal data is not transferred to third countries. The data is deleted as soon as it is no longer required to fulfill the purpose, consent is revoked or statutory retention obligations have expired. Further information can be found in this Privacy Policy.

3.2.5 Questionnaires/Forms

In-house development

We integrate self-developed forms on our website. The data entered is stored on our servers. The legal basis for the processing is Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. Consent can be revoked at any time. The legality of the processing that has already taken place remains unaffected by any revocation. The stored data can be made available at any time by e-mail or a request for deletion of the data can be made.

3.3 AI services

Microsoft Azure OpenAI Service

Our website uses the Microsoft Azure OpenAI Service, an AI-supported API service for the provision of functions for chatbots, natural language processing and generative content, offered by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA. The service enables the use of modern AI models, in particular for the implementation of interactive chat and support functions, automated content generation, retrieval-augmented generation (RAG) as well as data queries and personalization on the website. During integration, the content of API requests and responses (e.g. entered texts and AI output), metadata such as response headers (e.g. apim-request-id, content-type, cache-control, date), technical log data and, in the case of RAG functions, references to relevant document content are typically processed. The data is processed for the purpose of providing and improving the AI-based functions, for error diagnosis, security and for customizing the content provided. The legal basis for the processing of personal data is Art. 6 para. 1 lit. a GDPR in the case of consent, Art. 6 para. 1 lit. b GDPR in the case of (pre-)contractual inquiries and Art. 6 para. 1 lit. f GDPR in the case of our legitimate interest in a secure and functional website; in the case of access to terminal device information by the service, the legal basis is also based on Section 25 para. 1 or 2 TDDDG, if technically necessary or only with consent. According to the current status, no cookies are set by the service through the integration of the Microsoft Azure OpenAI Service. Personal data may be transferred to third countries outside the EU/EEA, in particular to the Microsoft Corporation in the USA; for European users, Microsoft ensures data processing within the framework of the EU Data Boundary. If data is transferred to third countries, this is done on the basis of the EU standard contractual clauses pursuant to Art. 46 para. 2 lit. c GDPR. Data is generally deleted as soon as it is no longer required to achieve the purpose or consent has been revoked, provided there are no legal obligations to retain it. Further information can be found at: https://learn.microsoft.com/en-us/azure/foundry/responsible-ai/openai/data-privacy

3.4 Newsletter

Brevo

Our website uses functions from Brevo (formerly Sendinblue), a newsletter management and marketing automation service from Sendinblue SAS, 7 Rue de Madrid, 75008 Paris, France. Brevo enables the sending of newsletters, the management of contact and registration data, the tracking of user interactions (e.g. openings and clicks within emails) as well as the automation of email campaigns and the synchronization of CRM data. Personal data is processed, in particular email addresses, contact characteristics entered by the user via forms (such as name or interests) and interaction data (e.g. email open and click rates). Data processing is used to send and analyze newsletters, to manage and segment contacts and to optimize marketing measures. The legal basis is regularly Art. 6 para. 1 lit. a GDPR i.V.m. § Section 25 para. 1 TDDDG with prior consent; in the case of existing business relationships, Art. 6 para. 1 lit. b GDPR may also apply. Insofar as cookies or comparable technologies (such as tracking pixels) are used in connection with the use of Brevo, this is done exclusively on the basis of consent; the type, purpose and storage duration of the cookies are specifically described in the consent banner in each case. Personal data is not transferred to third countries, as the data is processed on servers within the European Union. Data is deleted as soon as the purpose of processing no longer applies, consent is withdrawn or statutory retention obligations expire. Further information on data processing by Brevo and on data protection rights can be found at: https://www.brevo.com/legal/privacypolicy/

3.5 Analysis and tracking tools

3.6 Social media profiles

In addition to our website, our company is also present on social networks. Here we want to present our company and create the opportunity to get in touch with us.

We also use the opportunity to place advertisements and job advertisements on social media.

In the following, we provide information about which data we and the respective social network process when you visit and interaction with our profile.

LinkedIn

We operate a LinkedIn profile on https://www.linkedin.com/. This social network is operated by LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA.

Interaction with our company profile

When you visit our LinkedIn profile and interact with us, we process personal data. On the one hand, the data made publicly available on the profile. On the other hand, we also process the personal data contained in posts, comments or direct messages to us. Through interactions such as liking or sharing, we can see the user profile with the public information. The legal basis for this processing is Art. 6 para. 1 lit. f GDPR. It is in our legitimate interest to provide relevant and interesting content and to enable the use and functionality of our LinkedIn profile. Insofar as a request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures, our processing is based on Art. 6 para. 1 lit. b GDPR.

Page Insights

LinkedIn provides us with aggregated statistics and insights (called Page Insights) that tell us how people interact with our Company Page. Among other things, we receive information about the number of profiles that view, comment on or otherwise interact with our posts, as well as aggregated demographic and other information that helps us learn about the interaction with our page or LinkedIn profile. Page Insights provided to us by LinkedIn consist of aggregated data, and LinkedIn does not provide us with any personally identifiable information about members in relation to Page Insights. We also have no way of linking Page Insights to individual members. When placing ads, LinkedIn provides us with information about the types of people who see our ads and the success of our ads. Personal data is only passed on to us if this person has consented to such processing. We also receive information from LinkedIn that allows us to understand which of our ads led to a purchase being made or an action being taken. This data is processed for the purpose of analyzing our reach and adapting our content and ads to user interests. By evaluating this data, we can recognize how our content, our profile and our advertising are consumed. This enables us to create target-group-specific content and place advertisements in order to better market our company and our services. The processing is based on our legitimate interest in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR. When processing personal data in the course of the so-called Page Insights, the processing is carried out in joint responsibility with LinkedIn in accordance with Art. 26 para. 1 GDPR. We have concluded a corresponding agreement with LinkedIn for this purpose, which can be viewed [here](https://legal.linkedin.com/pages-joint-controller-addendum). LinkedIn's contact details are as follows: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. For LinkedIn, you can contact the data protection officer at the following link: https://www.linkedin.com/help/linkedin/ask/TSO-DPO.

Processing by LinkedIn

By visiting our company profile, LinkedIn may also process additional personal data. In this case, the processing is carried out under the sole responsibility of LinkedIn and without our knowledge. More information from LinkedIn on this: https://de.linkedin.com/legal/privacy-policy.

3.7 Third-party content

3.8 Cloud backups

Hetzner S3 Object StorageHetzner S3 Object StorageHetzner S3 Object Storage

https://www.hetzner.com/de/storage/object-storage/

This service will be added shortly.

4. What else is important

Finally, we would like to inform you in detail about your rights and how you will be informed about changes to data protection requirements.

4.1 Your rights in detail

4.1.1 Right to information in accordance with Art. 15 GDPR

You can request information about whether your personal data is being processed. If this is the case, you can request further information on the type and manner of processing. A detailed list can be found in Art. 15 para. 1 lit. a to h GDPR.

4.1.2 Right to rectification in accordance with Art. 16 GDPR

This right includes the correction of incorrect data and the completion of incomplete personal data.

4.1.3 Right to erasure in accordance with Art. 17 GDPR

This so-called 'right to be forgotten' gives you the right, under certain conditions, to request the deletion of your personal data by the controller. This is generally the case if the purpose of the data processing no longer applies, if consent has been withdrawn or the initial processing took place without a legal basis. A detailed list of reasons can be found in Art. 17 para. 1 lit. a to f GDPR. This "right to be forgotten" also corresponds to the controller's obligation under Art. 17 para. 2 GDPR to take reasonable steps to ensure that the data is generally erased.

4.1.4 Right to restriction of processing in accordance with Art. 18 GDPR

This right is subject to the conditions set out in Art. 18 para. 1 lit. a to d.

4.1.5 Right to data portability in accordance with Art. 20 GDPR

This regulates the basic right to receive your own data in a commonly used form and to transfer it to another controller. However, this only applies to data processed on the basis of consent or a contract in accordance with Art. 20 (1) (a) and (b) and insofar as this is technically feasible.

4.1.6 Right to object pursuant to Art. 21 GDPR

In principle, you can object to the processing of your personal data. This applies in particular if your interest in objecting outweighs the legitimate interest of the controller in the processing and if the processing relates to direct marketing and/or profiling.

4.1.7 Right to "individual decision-making" pursuant to Art. 22 GDPR

In principle, you have the right not to be subject to a decision based solely on automated processing (including profiling) which produces legal effects concerning you or similarly significantly affects you. However, this right is also restricted and supplemented by Art. 22 (2) and (4) GDPR.

4.1.8 Further rights

The GDPR contains comprehensive rights to inform third parties about whether or how you have asserted rights under Art. 16, 17, 18 GDPR. However, this only applies insofar as this is possible or feasible with reasonable effort.

We would like to take this opportunity to draw your attention once again to your right to withdraw your consent in accordance with Art. 7 (3) GDPR. However, this does not affect the lawfulness of the processing carried out up to that point.

We would also like to draw your attention to your rights under §§ 32 ff. BDSG, which, however, are largely congruent with the rights just described.

4.1.9 Right to lodge a complaint pursuant to Art. 77 GDPR

You also have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of personal data relating to you infringes this Regulation.

5. What if the GDPR is abolished tomorrow or other changes take place?

The current status of this Privacy Policy is 28.05.2026. From time to time it is necessary to adapt the content of the Privacy Policy in order to react to actual and legal changes. We therefore reserve the right to amend this Privacy Policy at any time. We will publish the amended version in the same place and recommend that you read the Privacy Policy regularly.

Created with the kind support of Dieter macht den Datenschutz

assistora

More time for your workshop.

Navigation

  • Home
  • SmartCheck
  • SmartCalc
  • SmartMatch

Company

  • Contact
  • Legal notice
  • Privacy policy

© 2026 assistora · Designed & Developed by emvau GmbH