Last updated: 12 September 2026
Privacy Policy under the GDPR
In this privacy policy we inform you about the nature, scope and purposes of the collection and use of personal data by DataLion GmbH, Türkenstraße 93, 80799 Munich, Germany, for this website and for the web-based analysis software DataLion (app.datalion.net) (hereinafter together "the webpage"). Our respective roles are explained below. Personal data means all data that can be related to you personally, e.g. name, address, e-mail address or usage behaviour.
We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy. The webpage can generally be visited without registration. When you register to use the web-based analysis software DataLion, or use our forms, certain personal data are collected (e.g. name and e-mail address). Data are only passed on to third parties within the scope of the data processing described below or with your consent.
Controller
The controller within the meaning of Art. 4(7) GDPR is:
DataLion GmbH
Managing Director: Dr. Benedikt Köhler
Türkenstraße 93
80799 Munich
Germany
Phone: +49 89 92334283
E-mail: info@datalion.com
Privacy contact: datenschutz@datalion.com
Your rights
With regard to the personal data concerning you, you have the following rights:
Right of access (Art. 15 GDPR),
Right to rectification (Art. 16 GDPR),
Right to erasure (Art. 17 GDPR),
Right to restriction of processing (Art. 18 GDPR),
Right to data portability (Art. 20 GDPR),
Right to object to processing (Art. 21 GDPR),
Right to withdraw a consent you have given, with effect for the future (Art. 7(3) GDPR).
You can address questions about these rights and about data protection at DataLion GmbH in general to the address stated above at any time. You also have the right to lodge a complaint with the competent supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany.
Legal bases for processing
Where we obtain your consent for processing operations, Art. 6(1)(a) GDPR is the legal basis. Where processing is necessary for the performance of a contract or to take pre-contractual steps, Art. 6(1)(b) GDPR is the legal basis. Where processing is necessary to comply with a legal obligation, Art. 6(1)(c) GDPR applies. Where processing is necessary for the purposes of a legitimate interest pursued by us or a third party and your interests do not override it, Art. 6(1)(f) GDPR is the legal basis.
Hosting and server log files
In order to provide this webpage, we use hosting services (servers, computing and storage capacity, security services and technical maintenance) of an external provider. For this we use Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The data are processed on servers in Germany. We have concluded a data processing agreement (Art. 28 GDPR) with the provider. You can view Hetzner's privacy policy at this link.
When this website is accessed, the server automatically collects information in so-called server log files that your browser transmits (in particular IP address, date and time of access, the file requested, volume of data transferred, referrer URL and information about your browser and operating system). These data are used for the technical delivery, stability and security of the webpage. The legal basis is Art. 6(1)(f) GDPR.
Cookies and consent management
This webpage uses cookies and comparable technologies (e.g. your browser's local storage). Cookies are small text files stored on your device. Technically necessary cookies that are required to operate the website are used on the basis of Section 25(2) TDDDG and Art. 6(1)(f) GDPR.
All non-essential cookies and services – in particular for analytics and marketing – are only set or loaded after you have given your consent via our cookie banner (Section 25(1) TDDDG, Art. 6(1)(a) GDPR). On the marketing website, the banner lets you choose between the categories "Necessary", "Analytics" and "Marketing". Your choice is stored in your browser; you can withdraw or adjust your consent at any time with effect for the future via the cookie settings. To control the Google services listed below on a consent basis, we use Google Consent Mode v2.
Google Tag Manager
To manage the tags used on this website, we use Google Tag Manager provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager itself does not collect personal data; it is a technical management solution used to trigger other services. Tags that process personal data (e.g. Google Analytics, Google Ads) are only triggered after your consent.
Google Analytics
After your consent, we use Google Analytics (GA4), a web analytics service provided by Google Ireland Limited. Google Analytics uses cookies that enable an analysis of your use of the website. GA4 generally collects IP addresses only in truncated form and does not store them. The information collected is used on our behalf to evaluate your use of the website and to compile reports on website activity. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can withdraw your consent at any time with effect for the future via the cookie settings.
A transfer of data to Google LLC in the USA cannot be ruled out. Google LLC is certified under the EU-US Data Privacy Framework; in addition, the European Commission's Standard Contractual Clauses are in place as appropriate safeguards. For more information, see Google's privacy policy.
Privacy in the DataLion application
DataLion is responsible for account administration and its own separately agreed customer-assistance or analytics purposes. We process content in customer instances as a processor on the customer's instructions. For that content, the customer is your controller and privacy contact; we assist them with your rights requests. The following telemetry purposes have separate controls. Technical activation replaces neither the required legal basis nor the customer agreement. Where a customer contract excludes our own analytics purposes, the corresponding processing remains disabled.
Operational diagnostics
To detect and resolve service failures, we process technical error data such as time, affected application area, error class and shortened, filtered error messages. Diagnostics is enabled by default and controlled independently of optional product analytics. We use an internal problem register and self-hosted Sentry. Request and user context, breadcrumbs and content variables are removed from Sentry events; performance tracing is disabled. Filtering reduces personal content but cannot guarantee that arbitrary error messages are anonymous. Survey responses and other customer content must not be included in error messages.
The legal basis for our own necessary and proportionate service-security processing is Art. 6(1)(f) GDPR. Our legitimate interest is a secure and reliable service. Diagnostics on customer instructions follows the data processing agreement and the customer's legal basis. Recipients are authorised operators and our hosting providers; these diagnostics are not sent to PostHog. The internal problem register is pruned after 90 days by default. Other diagnostic events are retained only as long as needed to investigate, resolve and verify a failure; security evidence follows the separate log-retention periods.
Optional activity analysis for customer assistance
Under a separate agreement, we may record daily activity and setup milestones for each customer instance to help with onboarding and use. This processing is disabled by default. Users and customer contacts are linked only in our internal customer-management system; PostHog is not needed for this purpose. Missing collection is not treated as inactivity. Our staff, test accounts and support sessions are excluded; this processing is not intended to evaluate individual employee performance.
The legal basis is Art. 6(1)(f) GDPR where customer assistance is necessary and supported by a documented balancing of interests. Purpose, responsibility, transparency and the right to object must be established before activation. You can object to this processing at datenschutz@datalion.com. Marketing communications require their own applicable permission. Daily activity is deleted after 90 days by default; this does not shorten separate, purpose-specific periods for existing customer files and CRM history. Access is limited to authorised customer-assistance personnel.
Optional product analytics with PostHog
We use PostHog, Inc. to assess feature use and investigate suspected interaction problems in order to improve DataLion. Product analytics is disabled by default. It requires separate permission for the instance and your consent. The legal basis is Art. 6(1)(a) GDPR and, where information is stored on or read from your device, Section 25(1) TDDDG. Refusal or withdrawal does not affect access to core features.
After consent, we collect defined usage events such as feature use, export events and the visibility of and clicks on selected controls. Repeated clicks or clicks without an observed response can indicate usability problems; they are not reliable proof of an error. Events also include time, a coarse application area and role. DataLion sends the events to PostHog using pseudonymous identifiers that differ between instances. These identifiers remain personal data; the analysis is not anonymous. Names, e-mail addresses, raw user/workspace/project identifiers, full URLs, form content, survey responses and other customer content are not sent to PostHog. Person profiles, cross-instance identity merging, automatic capture of arbitrary page content and session recordings are disabled.
Optional collection covers central registration and provisioning of new instances, the customer admin backend and the authenticated frontend, each after consent. Login and password pages, project registration, guest/shared views, survey runners and internal server administration load no product-analytics collector. Consent during registration does not automatically apply to a new customer instance or a subsequently signed-in account. Demo offerings have no blanket exemption from these consent rules.
We use PostHog's EU Cloud. An EU storage location does not rule out support or other access from third countries. Required transfer safeguards, including EU Standard Contractual Clauses, must be established contractually and reviewed before use. Information and a copy of the applicable safeguards are available at datenschutz@datalion.com. See also PostHog's privacy policy and our data processing agreement and provider register.
Product-analytics events have a planned maximum retention of 90 days; analytics is only activated once this period has been configured with the provider. Withdrawal stops further collection and transmission, including events not yet sent. Previously stored data remains subject to the retention period and your statutory erasure rights; withdrawal alone does not mean that all earlier data is immediately deleted.
Consent and withdrawal in the application
You can change your choice at any time in the cookie settings of the relevant instance. Your choice and a random receipt identifier are stored in your browser for at most 180 days. Consent is requested again after at most 180 days and after relevant changes. To evidence your choice, we store time, choice, affected services, scope, version, receipt identifier and a pseudonymous association; an internal user identifier may be included for signed-in users. IP addresses and browser fingerprints are not part of this evidence. This internal documentation is separate from product analytics.
We process necessary consent evidence to meet the accountability obligation in Art. 7(1), together with Art. 6(1)(c) GDPR. It is retained only as long as needed to evidence consent and address applicable legal claims, then deleted. Consent validity is distinct from evidence retention. Access is restricted to authorised privacy and operations personnel.
Website analytics and security logs
The Google services on the marketing website described above have their own consent settings. Where Google Analytics is enabled for central new-instance registration, it is also loaded only after your consent there; it is not part of the customer-activity analysis or diagnostics described above. Product-analytics consent does not replace marketing consent.
Necessary security and access logs protect the service and evidence security-relevant actions. In the DataLion application, default periods are seven days for the general application log, 90 days for admin, support and security logs, and 400 days for access logs and the signed security audit trail. These periods are separate from optional product analytics. Contractually different deployments and purpose-specific evidence are documented separately.
Google Ads and conversion tracking
If you consent to marketing cookies, we use services from Google (Google Ireland Limited) to measure the success of our online advertising (conversion tracking) and, where applicable, for remarketing. This evaluates whether users carry out certain actions on our website after clicking one of our ads. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). Here too, data may be transferred to Google LLC in the USA (EU-US Data Privacy Framework or Standard Contractual Clauses).
Contact and forms
If you contact us via a form on this website, by e-mail or by phone, we process the data you provide (e.g. name, e-mail address, company, phone number and your message) in order to handle your enquiry. The forms are processed via an endpoint we operate ourselves on our servers in the EU, where the submissions are stored. The legal basis is Art. 6(1)(b) GDPR (contract or pre-contractual steps) or Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). The data are deleted as soon as they are no longer required to achieve the purpose and no statutory retention obligations prevent this.
To send the related notifications and confirmation e-mails and to manage prospect and newsletter contacts, we use the Brevo service (see the "Newsletter and e-mail delivery via Brevo" section).
Newsletter and e-mail delivery via Brevo
With our newsletter we inform registered users and subscribers about innovations in the software as well as new offers from DataLion. We use the double opt-in procedure for sign-up: after you sign up, you receive an e-mail in which you confirm your registration. The legal basis is your consent (Art. 6(1)(a) GDPR). You can unsubscribe from the newsletter at any time, e.g. via the unsubscribe link in every newsletter e-mail. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
To send our newsletters and transactional e-mails and to manage contacts, we use the Brevo service (Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany; parent company Brevo SA, France). The data are processed on servers within the European Union. We have concluded a data processing agreement (Art. 28 GDPR) with Brevo. You can view Brevo's privacy policy at this link.
Support and helpdesk (Atlassian Jira)
For the efficient handling of customer enquiries and support, we use Atlassian Jira Service Management. In doing so we process personal data such as contact information and enquiry details in order to provide you with the support you need. These data are hosted and processed in the EU and used exclusively to handle your enquiries. The legal basis is Art. 6(1)(b) or (f) GDPR. A data processing agreement (Art. 28 GDPR) is in place with the provider. For users who do not agree to the data processing in the external system, we offer contact options by e-mail, phone or post.
Payment processing (Stripe)
To process paid subscriptions and payments in connection with the DataLion application, we use the payment service provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland). When you purchase a paid offering, the data required to process the payment (e.g. name, e-mail address, billing address and payment and transaction data) are transmitted to and processed by Stripe. Your full payment details (e.g. credit card numbers) are collected directly by Stripe; we ourselves do not gain access to them. The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in secure and efficient payment processing). A transfer to Stripe, Inc. in the USA cannot be ruled out; the European Commission's Standard Contractual Clauses are in place as appropriate safeguards. For more information, see Stripe's privacy policy.
Spam protection for website forms and new registrations (Cloudflare Turnstile)
We use Cloudflare Turnstile, a service provided by Cloudflare, Inc., to protect the contact and download forms on this marketing website and central self-service registration of new DataLion instances against bots. Turnstile is not embedded in the login, admin backend, customer frontend or survey runner of existing customer instances. Locally served application libraries do not use the Cloudflare CDN. Turnstile remains a separate external service. Based on technical characteristics (e.g. IP address, browser information and interaction behaviour), Turnstile assesses whether an input is made by a human or automatically. The legal basis is our legitimate interest in the security of our services and the prevention of misuse (Art. 6(1)(f) GDPR). A transfer to Cloudflare, Inc. servers in the USA cannot be ruled out; the European Commission's Standard Contractual Clauses are in place as appropriate safeguards. For more information, see Cloudflare's privacy policy.
AI chat assistant (HybridAI)
On this website we offer an AI-based chat assistant provided by HybridAI (hybridai.one) that lets you ask questions about DataLion. The chat is only loaded after you have interacted with our cookie banner. When you use the chat, the messages you enter and technical connection data (e.g. IP address) are transmitted to and processed by a large language model (LLM) in order to answer your enquiry. Processing takes place on servers within the European Union. Please do not enter any special categories of personal data in the chat. The legal basis is our legitimate interest in efficient user communication (Art. 6(1)(f) GDPR) or your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG).
SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that the browser's address bar shows "https://".