Compliance with data protection law is not only a legal obligation for us but also an important factor of trust. With the following privacy policy, we would therefore like to inform you transparently about the nature, scope and purpose of the personal data collected and processed on this website, and about your rights.
I-FS Berlin GmbH, Janusz-Korczak-Str. 35, 12627 Berlin, Germany, phone +49 30 3377 1235 (hereinafter: “we”), as operator of the website www.i-fs.de, is the controller within the meaning of Art. 4 No. 7 of the EU General Data Protection Regulation (GDPR). If you have any questions, please contact info@i-fs.de.
Pursuant to Art. 37 GDPR in conjunction with Section 38 BDSG (German Federal Data Protection Act), we are not required to appoint a data protection officer. You can, of course, contact us at any time using the contact details above with questions about data protection and to exercise the rights described below.
As a data subject, you have the following rights with regard to your personal data. You have:
If you exercise your rights under the GDPR and the BDSG towards us, we will process the data you send us in order to fulfil your request. We then store the data you sent us and the data we sent you in return for documentation purposes until the limitation period for administrative offences has expired (3 years). The legal basis for storing this data is Art. 6 (1) sentence 1 lit. f GDPR (legitimate interest). Our legitimate interest results from our obligation to comply with your request and from the need to be able to exonerate ourselves in possible fine proceedings by proving that we have properly complied with your request.
You may object at any time to the processing of your data based on our legitimate interest under the conditions of Art. 21 GDPR. Please use the contact details given in the legal notice (Impressum). However, we point out that processing your data to prove compliance with data subject rights is compelling within the meaning of Art. 21 (1) GDPR, as no other means of proof exist or are equally suitable.
We protect our website and other systems – and thus your data – against loss, destruction, access, modification or dissemination by unauthorised persons through technical and organisational measures. In particular, your personal data is transmitted over the internet in encrypted form using TLS (Transport Layer Security). However, the transmission of information over the internet is never completely secure, which is why we cannot guarantee 100% security of data transmitted from our website.
We process your personal data insofar as it is required to establish, define the content of or amend a contractual relationship between you and us (master data). Master data may include, in particular: name, title, contact details (postal address, telephone, e-mail address), date of birth, etc.
We also process your usage data. Usage data is data generated by your behaviour when using our website and services, in particular your IP address, the start and end of your visit to our website and information about which content you accessed on our website.
We collect this data either directly from you (e.g. when you visit the website) or, where permitted by data protection law, from third parties or from publicly accessible sources (e.g. commercial and association registers, press, media, internet).
All information we receive from you or about you is generally processed on servers within the European Union. Without your express consent, your data will only be transferred to or processed in third countries if this is provided for or permitted by law, if an adequate level of data protection is ensured in the third country, or if contractual obligations exist in the form of EU standard contractual clauses.
With regard to data transfers to the USA, the European Commission has adopted an adequacy decision called the EU-U.S. Data Privacy Framework, which ensures an adequate level of protection for transfers of personal data by companies participating in the framework. Where we use services that transfer personal data to the USA, the respective service description states whether the company is certified under the EU-U.S. Data Privacy Framework.
We never disclose your personal data to third parties without authorisation. We may, however, disclose your data to third parties in particular if you have consented to the disclosure, if the disclosure is necessary to fulfil our legal obligations, or if we are entitled or obliged to disclose data on the basis of statutory provisions or official or court orders. This may in particular include providing information for the purposes of criminal prosecution, averting danger or enforcing intellectual property rights.
We may disclose the personal data collected from you to third parties in particular in the context of performing a contract, for example to the transport company commissioned with delivery or to the payment service used, insofar as this is necessary to perform the contract. You will find the individual service providers and further information below in the section “Third-party services”.
We may also transfer your data to external service providers who process data on our behalf and according to our instructions (processors) in order to simplify or relieve our own data processing. Each processor is bound by a contract in accordance with Art. 28 GDPR. This means in particular that the processor must provide sufficient guarantees that appropriate technical and organisational measures are implemented in such a way that the processing meets the requirements of the GDPR and the protection of your rights as a data subject is ensured. Despite the use of processors, we remain the controller for the processing of your personal data within the meaning of data protection law.
We generally only use the data for the purpose for which it was collected from you. We may further process the data for another purpose if that other purpose is not incompatible with the original purpose (Art. 5 (1) lit. b GDPR).
Unless stated otherwise in detail, we only store data collected from you for as long as necessary for the respective purpose, unless statutory retention obligations, e.g. under commercial or tax law, prevent erasure.
Below we would like to explain as transparently as possible which data we process, on which occasion, on which legal basis and for which purpose.
Each time a website is accessed and data is retrieved from a server, general information is automatically transmitted to the providing server. This transmission happens automatically and is a fundamental part of communication between devices on the internet. The data transmitted by default includes, among other things: your IP address, product and version information about the browser and operating system used (user agent), the website from which you accessed our site (referrer), and the date and time of the request (timestamp). In addition, the HTTP status and the amount of data transferred in the request are recorded. This information is logged by the server, stored in a table and kept there for a short time (server log files). By analysing these log files, we can identify and fix errors on the website, determine the load on the website at certain times and make adjustments or improvements on that basis, and ensure the security of the server by tracing the IP addresses from which attacks were carried out. Your IP address is only stored for the duration of your use of the website and is then deleted immediately or partially anonymised by truncation. The remaining data is stored for a limited period (usually 7 days). The legal basis for the use of server log files is Art. 6 (1) sentence 1 lit. f GDPR (legitimate interest). Our legitimate interest results from the necessity for operating and maintaining our website, as explained above. You may object at any time to the processing of your data based on our legitimate interest under the conditions of Art. 21 GDPR. Please use the contact details given in the legal notice. However, we point out in advance that processing your data in server log files is compelling within the meaning of Art. 21 (1) GDPR, as the website could not be operated at all otherwise.
Our website www.i-fs.de does not set cookies and does not use your browser’s web storage (e.g. local storage). We do not use any analytics, tracking or advertising services on this website. A consent request (cookie banner) is therefore not required.
In our client portal (kundenportal.i-fs.de) we only use technically necessary storage technologies: after you log in, a session cookie is set which is deleted when you close your browser. If you select “Stay logged in” when logging in, an additional cookie is stored that recognises you for 14 days; it contains your customer ID and a random login key, and only an encrypted check value (hash) of this key is stored on our server. This cookie is deleted when you log out. If you choose a background for a video recording, your choice is stored in your browser’s web storage (local storage) so that it is preselected next time; this information does not leave your device.
The legal basis is Section 25 (2) No. 2 TDDDG (strictly necessary to provide the service you expressly requested) as well as Art. 6 (1) sentence 1 lit. b GDPR (pre-contractual measures or performance of a contract) and lit. f GDPR (legitimate interest in the secure and user-friendly operation of the client portal). You can delete cookies and web storage at any time in your browser settings.
Our website offers ways to contact us directly. We process the data you send us only until the purpose of your enquiry has been achieved, unless statutory retention periods apply. If the purpose of your enquiry is to exercise data subject rights, the section “Your rights as a data subject” applies. We process all data you provide when contacting us, e.g. your name and e-mail address. The legal basis for using the data you send us in the context of contractual or pre-contractual relationships or for answering (pre-)contractual enquiries is Art. 6 (1) sentence 1 lit. b GDPR (performance of a contract). The legal basis for processing the data you send us in other cases is Art. 6 (1) sentence 1 lit. f GDPR (legitimate interest). Our legitimate interest results from our interest in answering enquiries and maintaining user relationships. You may object at any time to the processing of your data based on our legitimate interest under the conditions of Art. 21 GDPR. Please use the contact details given in the legal notice.
We offer to keep you up to date with our newsletter and inform you about special offers. To subscribe, you can enter your e-mail address in our mailing list. You must then confirm your subscription again (double opt-in). We use the data you send us only for sending the newsletter and do not pass it on to third parties for other purposes. Our newsletter uses so-called web beacons or tracking pixels to analyse your reading behaviour. Tracking pixels are extremely small image files embedded in the newsletter e-mail which allow log file recording and analysis. When you open the newsletter e-mail, the tracking pixel is loaded from the newsletter service’s server and certain information about you is transmitted, e.g. whether the e-mail was opened, the time of access and the associated IP address. In addition, links in the e-mail can show which products are of greater interest, i.e. were clicked more often than others. Both the web beacon/tracking pixel and the links in the e-mail can be clearly assigned to the e-mail address used for sending and thus allow conclusions to be drawn about the respective newsletter recipient. The legal basis for using your e-mail address is Art. 6 (1) sentence 1 lit. a GDPR (consent of the data subject). You can withdraw your consent at any time with effect for the future. Please use the link in every newsletter e-mail or contact us using the details in the legal notice.
Further information on data disclosure can be found below in the section “Third-party services – newsletter service”.
To simplify our data processing and extend the functionality of our website, we use services/resources of third parties, such as plugins, external content, software or other external service providers (services). Personal data may also be transmitted to the service provider. To protect your data, we have, where necessary, contractually obliged the service providers pursuant to Art. 28 GDPR to process your data only according to our instructions. We expressly point out that we are generally only responsible within the meaning of the GDPR for the collection and transmission of data by the service, but not for any subsequent processing by the respective service provider. In detail, we use the following services:
Our website is hosted by Alfahosting GmbH, Edmund-von-Lippmann-Straße 13-15, 06112 Halle (Saale), Germany. The servers are located in Germany. When you access our website, the host processes the data mentioned in the section “Server log files”. The transmission is encrypted (SSL/TLS). We have concluded a data processing agreement with Alfahosting GmbH pursuant to Art. 28 GDPR to ensure that it processes your data only according to our instructions. The legal basis is Art. 6 (1) sentence 1 lit. f GDPR (legitimate interest). Our legitimate interest results from our need for a secure, fast and technically flawless provision of our website. You may object at any time to the processing of your data based on our legitimate interest under the conditions of Art. 21 GDPR. Please use the contact details given in the legal notice.
On our website we use the fonts “IBM Plex Sans” and “IBM Plex Serif”. These fonts are hosted locally on our own server. Therefore, no connection to third-party servers (e.g. Google Fonts) is established when you access our website, and no data is transmitted to third parties.
Our website uses the newsletter service of digidor GmbH, Teltower Damm 19, 14169 Berlin, Germany, to provide you with a newsletter containing current information and offers. We have concluded a data processing agreement with the provider to ensure that it processes your data only according to our instructions. For more information on how user data is handled, please see the privacy policy of digidor GmbH: https://www.digidor.de/datenschutz.html. This is a cloud-based service that allows newsletters to be created, sent and managed. The software is provided over the internet, so we use the service via a web interface on a server of digidor GmbH. For this, it is necessary to transmit the data you provided when subscribing to the newsletter to the provider. As we ask for your consent before sending our newsletter, the legal basis for processing data to send the newsletter is Art. 6 (1) sentence 1 lit. a GDPR (consent of the data subject). You can withdraw this consent at any time with effect for the future. Please use the unsubscribe link in the newsletter or contact us. The legal basis for disclosing data when using cloud newsletter software is Art. 6 (1) sentence 1 lit. f GDPR (legitimate interest). Our legitimate interest results from our need to simplify and relieve our data processing. You may object at any time to the processing of your data based on our legitimate interest under the conditions of Art. 21 GDPR. Please use the contact details given in the legal notice.
In addition to our website, we maintain online presences on social platforms in order to communicate with customers, prospects and users active there and to inform them about our services.
When you visit our presence on a social platform, your data is usually processed by the respective platform provider for our market research and advertising purposes. The provider may also process the data for its own purposes. Usage profiles may be created from your usage behaviour and the resulting interests. These usage profiles may in turn be used, for example, to display advertisements inside and outside the platforms that presumably correspond to your interests. For these purposes, cookies are usually stored on your device in which your usage behaviour and interests are stored. In particular, if you are a member of the respective platform and logged in, additional data may be stored in the usage profiles independently. For a detailed description of the respective processing and the options to object, we refer to the information provided by the providers linked below, as only they know the exact details of their data processing.
We point out that your data may also be processed outside the European Union. This may result in risks, for example because the enforcement of your rights could be made more difficult.
The legal basis for using the online presences and the associated data processing is generally Art. 6 (1) sentence 1 lit. f GDPR (legitimate interest). Our legitimate interest results from our need to present ourselves to visitors and users of social networks and to contribute statements of all kinds to the media and opinion market. You may object at any time to the processing of your data based on our legitimate interest under the conditions of Art. 21 GDPR. Please use the contact details given in the legal notice. The use of statistical data on all visitors to our social media presences, which is collected, prepared and made available to us by the respective page operators, is based on Art. 6 (1) sentence 1 lit. f GDPR (legitimate interest). Our legitimate interest results from our need for an anonymous evaluation of visitor and usage behaviour on our web presences in order to improve the design of our online offering and optimise our communication with prospects. You may object at any time under the conditions of Art. 21 GDPR. If the respective providers ask you for consent to data processing, the legal basis is Art. 6 (1) sentence 1 lit. a GDPR (consent of the data subject). You can withdraw this consent at any time with effect for the future. Please contact the provider who asked you for consent.
If you wish to exercise your rights mentioned above, we point out that, despite any joint controllership, they can be exercised most effectively with the providers. As a rule, only the providers have direct access to your data and can take appropriate measures and provide information directly. Should you nevertheless need help, you can contact us and we will support you as far as we can.
We are represented on:
Facebook is a social network of Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, the European subsidiary of Meta Platforms Inc., 1601 Willow Road, Menlo Park, California 94025, USA. Further information on data protection at Facebook: https://www.facebook.com/about/privacy/. We inform you about our own data processing in this policy. As part of our user agreement, we have concluded an addendum with Facebook that regulates responsibility for data processing with regard to the Page Insights function pursuant to Art. 26 GDPR. The details can be found here: https://www.facebook.com/legal/terms/page_controller_addendum. Among other things, Facebook has undertaken to inform you about the data processing in the context of the Page Insights function. This information can be found here: https://www.facebook.com/legal/terms/information_about_page_insights_data.
Google Business Profile is a service of Google Ireland Ltd. (“Google EU”), Gordon House, Barrow Street, Dublin 4, Ireland, which represents Google LLC (“Google US”), 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, in the EU. Further information on data protection at Google: https://policies.google.com/privacy. You can change your Google ad settings here: https://adssettings.google.de/.
Instagram is a social network of Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, the European subsidiary of Meta Platforms Inc., 1601 Willow Road, Menlo Park, California 94025, USA. Further information on data protection at Instagram: https://instagram.com/about/legal/privacy/. Further information on data protection at Facebook: https://www.facebook.com/about/privacy/.
LinkedIn is a professional network of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, which represents LinkedIn Corporation, 1000 W. Maude Ave., Sunnyvale, California 94085, USA, in the EU. Further information on data protection at LinkedIn: https://www.linkedin.com/legal/privacy-policy. You can configure LinkedIn’s data collection here: https://www.linkedin.com/psettings/guest-controls/.
Twitter / X is a social network of Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland, the European subsidiary of Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. Further information on data protection at Twitter: https://twitter.com/privacy. You can configure Twitter’s data collection here: https://twitter.com/personalization.
XING is a professional network of New Work SE, Am Strandkai 1, 20457 Hamburg, Germany. Further information on data protection at XING: https://privacy.xing.com/en/privacy-policy.
YouTube is a social video platform of YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA, represented by Google Ireland Ltd. (“Google EU”), Gordon House, Barrow Street, Dublin 4, Ireland, which represents Google LLC (“Google US”), 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, in the EU. Further information on data protection at YouTube: https://policies.google.com/privacy.
To send WhatsApp messages we use the service “seven.io” of seven communications GmbH & Co. KG, Willestr. 4-6, 24103 Kiel, Germany. Your telephone number and the content of the messages sent are transmitted to seven.io so that this service can deliver the messages for us. We have concluded a data processing agreement with the provider to ensure that it processes your data only according to our instructions and in compliance with the GDPR. The legal basis for using seven.io is Art. 6 (1) lit. f GDPR (legitimate interest in efficient communication with you) or Art. 6 (1) lit. b GDPR if the message serves to initiate or perform a contract.
To send SMS messages we use the service “smsflatrate” of Kloppe Media GmbH, Ansbacher Str. 85, 91541 Rothenburg ob der Tauber, Germany. Your telephone number and the content of the SMS sent are transmitted to Kloppe Media GmbH so that this service can deliver the messages for us. We have concluded a data processing agreement with the provider to ensure that it processes your data only according to our instructions and in compliance with the GDPR. The legal basis for using smsflatrate is Art. 6 (1) lit. f GDPR (legitimate interest in efficient communication with you) or Art. 6 (1) lit. b GDPR if the message serves to initiate or perform a contract.
For contacting you by telephone, we use an AI-based voice assistant from Retell AI, Inc., 540 Price Ave, Redwood City, CA 94063, USA. During the call, personal data (including name, telephone number and a transcript of the conversation) is processed in order to conduct the call and evaluate its result. As Retell AI, Inc. is based in the USA, data is transferred there on the basis of appropriate safeguards pursuant to Art. 46 GDPR (EU standard contractual clauses). The legal basis for using Retell AI is Art. 6 (1) lit. f GDPR (legitimate interest in contacting you in the context of your ongoing enquiry) or Art. 6 (1) lit. b GDPR.
To manage contact and prospect data, we use the CRM system of Zoho Corporation GmbH, II. Hagen 7, 45127 Essen, Germany. The personal data collected in the context of your enquiry (including name, contact details, content of the enquiry and call notes) is stored and processed in this system. We have concluded a data processing agreement with the provider to ensure that it processes your data only according to our instructions and in compliance with the GDPR. The legal basis for using Zoho is Art. 6 (1) lit. b or lit. f GDPR. In addition, we use Zoho CRM to store and process the documents you send us via our client portal or upload page (kundenportal.i-fs.de) (e.g. identity documents, proof of income, property documents). This processing is carried out for pre-contractual measures or the performance of a contract (Art. 6 (1) lit. b GDPR). The data is stored in Zoho’s EU data centre. A data processing agreement pursuant to Art. 28 GDPR is in place with Zoho.
We use the service Make (make.com) to automate internal processes, for example passing data between our CRM system, calendar and phone assistant, and sending e-mails, WhatsApp messages and text messages. The provider is Celonis Inc. (USA), a subsidiary of Celonis SE, Theresienstraße 6, 80333 Munich, Germany. Make processes personal data such as your name, contact details, appointment data and the content of messages, but only as far as each process requires. The data is processed only to run these processes. The provider does not use it for its own purposes. We have a data processing agreement with the provider (Art. 28 GDPR). Data may be transferred to the USA. This is based on the EU-U.S. Data Privacy Framework, under which Celonis Inc. is certified, and on the EU Standard Contractual Clauses (Art. 46 GDPR). The legal basis is Art. 6 (1) lit. b GDPR (pre-contractual measures and performance of a contract) and Art. 6 (1) lit. f GDPR (legitimate interest in efficient, automated processes). More information: https://www.make.com/en/privacy-notice
Our upload page kundenportal.i-fs.de is operated by Alfahosting GmbH, Edmund-von-Lippmann-Straße 13-15, 06112 Halle (Saale), Germany. Your files are transmitted in encrypted form (SSL/TLS). The files are not stored there permanently but forwarded immediately to our CRM system (Zoho). When the page is accessed, the host processes technically necessary data (e.g. IP address, time of access) on the basis of our legitimate interest in secure operation (Art. 6 (1) lit. f GDPR). A data processing agreement pursuant to Art. 28 GDPR is in place with Alfahosting.
In the client portal you can send us – and we can send you – voice and video messages. The microphone or camera is only accessed when you start the recording yourself and grant permission in your browser. The recordings (max. 5 minutes of audio or 2 minutes of video) are transmitted in encrypted form (SSL/TLS) and stored on our web space at Alfahosting GmbH in Germany in a protected area that is not publicly accessible. Only a reference to the recording is stored in our CRM system (Zoho). Only you and we can access the recordings.
For video messages you can optionally blur or replace your background. The person detection required for this takes place exclusively locally in your browser; no image or video data is transmitted to third parties for this purpose.
The legal basis is Art. 6 (1) sentence 1 lit. b GDPR (pre-contractual measures or performance of a contract). The recordings are deleted as soon as they are no longer required for processing your request, unless statutory retention obligations apply.
Our partner on-geo GmbH, Parsevalstraße 2, 99092 Erfurt, Germany, provides the necessary documents such as land register extracts, cadastral maps, energy certificates, living area calculations, etc. on request. The owner’s consent is always required for this. A data processing agreement pursuant to Art. 28 GDPR is in place with on-geo.
To prepare our consultation minutes, we use the AI service Claude of Anthropic, PBC, San Francisco, USA. After a consultation, the automatically generated meeting notes are transmitted to Claude, which summarises them into minutes and translates them into English if required. Personal data may be processed in this context, in particular name, information on your personal and financial situation and on your financing project. Every set of minutes is checked by our advisors before it is made available to you in the client portal.
A data processing agreement is in place with Anthropic. Anthropic does not use the transmitted data to train its AI models. Data is transferred to the USA on the basis of the EU standard contractual clauses (Art. 46 GDPR). The legal basis is Art. 6 (1) lit. b GDPR (conducting the consultation) and Art. 6 (1) lit. f GDPR (legitimate interest in efficient and traceable documentation).
For online consultations we use Google Meet. For e-mail and appointment management we use Gmail and Google Calendar; the provider is Google Ireland Limited, Dublin, Ireland. During an online consultation, the “Notes by Gemini” function may be used to create an automatic summary of the conversation, which serves as the basis for your consultation minutes. A data processing agreement is in place with Google. A transfer to the USA is possible and is based on the EU-U.S. Data Privacy Framework or the EU standard contractual clauses (Art. 46 GDPR). The legal basis is Art. 6 (1) lit. b and f GDPR.