Translation notice
This is an English translation for convenience. The German version is the legally binding one; in case of any discrepancy, the German text applies.
No cookies, no analytics, nothing from third parties on this website. What happens with a purchase and the licence server is below.
This is an English translation for convenience. The German version is the legally binding one; in case of any discrepancy, the German text applies.
General notice: The following notice gives a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can personally identify you. For detailed information, see the privacy policy listed under this text.
Who is responsible for collecting data on this website? Data processing on this website is carried out by the website operator. Their contact details can be found in the “Notice regarding the responsible party” section of this privacy policy.
How do we collect your data? Your data is collected in part because you provide it to us. This may be data you enter in a contact form or provide when purchasing. Other data is collected automatically by our IT systems when you visit the website — mainly technical data (e.g. browser, operating system or time of the page visit). This data is collected automatically as soon as you enter this website.
What do we use your data for? Some of the data is collected to ensure the website is provided without errors. We do not analyse your usage behaviour. Where contracts are concluded or initiated via the website, the transmitted data is also processed for contract offers, orders or other requests.
What rights do you have regarding your data? You always have the right to request, free of charge, information about the origin, recipients and purpose of your stored personal data. You also have the right to request that this data be corrected or deleted. If you have given consent to data processing, you can withdraw that consent at any time for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data. Furthermore, you have a right to lodge a complaint with the competent supervisory authority. Feel free to contact us at any time regarding this or any other questions about data protection.
We host this website’s content with the following provider: All-Inkl. The provider is ALL-INKL.COM - Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany (“All-Inkl”). Details can be found in All-Inkl’s privacy policy: all-inkl.com/datenschutzinformationen.
For the hosting of the website, All-Inkl’s data-processing terms under Art. 28 GDPR apply, which form part of the web-hosting contract under which the website is operated.
The purchase page and the licence server (shop.coworkboard.de) as well as our email mailboxes are also hosted at All-Inkl; emails to and from us are delivered via All-Inkl’s servers.
We use All-Inkl on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in the most reliable possible presentation of our website.
Data protection: The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data-protection regulations and this privacy policy. When you use this website, various pieces of personal data are collected. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens. We point out that data transmission over the internet (e.g. by email) can have security gaps. Complete protection of data against access by third parties is not possible.
Notice regarding the responsible party: The party responsible for data processing on this website is: Mike Hillebrand Media, owner Mike Hillebrand, Karl-Liebknecht-Str. 39, 09111 Chemnitz, Germany, phone +49 176 32334839, email info@coworkboard.de. The responsible party is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data (such as names, email addresses, etc.).
Storage duration: Unless a more specific storage duration is stated in this privacy policy, your personal data remains with us until the purpose for the data processing no longer applies. If you assert a legitimate request for deletion or withdraw consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, deletion takes place once those reasons no longer apply.
Legal bases for the processing: Where you have given consent to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, if special categories of data under Art. 9(1) GDPR are processed. In the case of an express consent to the transfer of personal data to third countries, processing also takes place on the basis of Art. 49(1)(a) GDPR. Where you have consented to the storage of cookies or access to information on your device (e.g. via device fingerprinting), processing additionally takes place on the basis of § 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act). Consent can be withdrawn at any time. Where your data is required for the performance of a contract or for pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. We also process your data where this is necessary to fulfil a legal obligation, on the basis of Art. 6(1)(c) GDPR. Processing may also take place on the basis of our legitimate interest under Art. 6(1)(f) GDPR. Information on the legal basis applicable in each individual case is provided in the following paragraphs of this privacy policy.
Recipients of personal data: In the course of our business activities, we work with various external parties. This sometimes requires transferring personal data to those external parties. We only pass on personal data to external parties where this is required for the performance of a contract, where we are legally obliged to do so (e.g. passing data to tax authorities), where we have a legitimate interest under Art. 6(1)(f) GDPR in the disclosure, or where another legal basis permits the disclosure. When using processors, we only pass on our customers’ personal data on the basis of a valid data-processing agreement. In the case of joint processing, a joint-controller agreement is concluded.
Withdrawing your consent to data processing: Many data-processing operations are only possible with your express consent. You can withdraw consent already given at any time. The lawfulness of the data processing carried out until the withdrawal remains unaffected by the withdrawal.
Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR): WHERE DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME, FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA, UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ASSERTION, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION UNDER ART. 21(1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT-MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH MARKETING PURPOSES; THIS ALSO APPLIES TO PROFILING TO THE EXTENT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION UNDER ART. 21(2) GDPR).
Right to lodge a complaint with the competent supervisory authority: In the event of breaches of the GDPR, data subjects have a right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, place of work or place of the alleged breach. The right to lodge a complaint exists regardless of any other administrative or judicial remedy.
Right to data portability: You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done to the extent technically feasible.
Access, correction and deletion: Within the scope of applicable statutory provisions, you have the right at any time to free information about your stored personal data, its origin and recipients, and the purpose of the data processing, and, where applicable, a right to correction or deletion of this data. Feel free to contact us at any time regarding this or any other questions about personal data.
Right to restriction of processing: You have the right to request the restriction of the processing of your personal data. You may contact us at any time to do so. The right to restriction of processing exists in the following cases:
If you have restricted the processing of your personal data, this data may — apart from being stored — only be processed with your consent, or for the assertion, exercise or defence of legal claims, or to protect the rights of another natural or legal person, or for reasons of important public interest of the European Union or a member state.
SSL/TLS encryption: For security reasons and to protect the transmission of confidential content, such as orders or enquiries you send to us as the site operator, this site uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that the browser’s address bar changes from “http://” to “https://” and by the lock icon in your browser’s address bar. When SSL/TLS encryption is active, data you transmit to us cannot be read by third parties.
No cookies, no analytics, no third-party content: coworkboard.de sets no cookies, stores nothing in your browser and does not analyse your behaviour. Fonts, images, videos and scripts sit on our own server; visiting the site does not establish connections to other providers. That’s also why there’s no cookie banner.
Server log files: The site’s provider automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are: browser type and version, operating system used, referrer URL, hostname of the accessing computer, time of the server request, and IP address. This data is not merged with data from other sources. This data is collected on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of their website — for this, the server log files must be collected.
Contact form: If you send us enquiries via the contact form, your details from the enquiry form, including the contact details you provide there, are stored with us for the purpose of processing the enquiry and in case of follow-up questions. We do not pass on this data without your consent. The enquiry is not stored in a database but sent as an email to info@coworkboard.de; you receive a confirmation of receipt at the address you provided. To protect against spam, the server counts requests per connection. For this it only stores a non-reversible checksum (HMAC) of your IP address and deletes it after at most 24 hours.
This data is processed on the basis of Art. 6(1)(b) GDPR, where your enquiry relates to the performance of a contract or is necessary for carrying out pre-contractual measures. In all other cases, processing is based on your consent (Art. 6(1)(a) GDPR), which you give in the form, or on our legitimate interest in effectively handling enquiries addressed to us (Art. 6(1)(f) GDPR); consent can be withdrawn at any time. Data you enter in the contact form remains with us until you ask us to delete it, withdraw your consent to storage, or the purpose for storing the data no longer applies (e.g. after your enquiry has been fully processed). Mandatory statutory provisions — in particular retention periods — remain unaffected.
Enquiry by email or phone: If you contact us by email or phone, your enquiry, including all resulting personal data (name, enquiry), is stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent. This data is processed on the basis of Art. 6(1)(b) GDPR, where your enquiry relates to the performance of a contract or is necessary for carrying out pre-contractual measures. In all other cases, processing is based on our legitimate interest in effectively handling enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), where this was requested; consent can be withdrawn at any time. Data you send us via contact enquiries remains with us until you ask us to delete it, withdraw your consent to storage, or the purpose for storing the data no longer applies (e.g. after your request has been fully processed). Mandatory statutory provisions — in particular statutory retention periods — remain unaffected.
Customer and contract data: If you buy a licence, additional seats or an update package, we process the data required for the contract, delivery and invoicing: name, company and VAT ID if applicable, email address, billing address, package purchased, amount, timestamp, your acceptance of the terms and of the early start of performance, and the identifiers of the Stripe payment transaction. From this we generate your licence key and send it by email together with the contract confirmation. The legal basis is Art. 6(1)(b) GDPR (contract) and, for retention, Art. 6(1)(c) GDPR. We store licence data for as long as the licence can be used (for updates, seats and support); we keep invoicing and bookkeeping records for the statutory periods under German commercial and tax law (§ 257 HGB, § 147 AO; eight or ten years depending on the document).
Purchase page: The purchase confirmation before payment runs on shop.coworkboard.de. There, the server sets a technically necessary session cookie that protects forms against misuse (HTTPS only, not readable by scripts). It contains no information about you personally and is not used to recognise you beyond the visit. The legal basis is § 25(2) No. 2 TDDDG and Art. 6(1)(f) GDPR.
Payment processing via Stripe: We process payment through Stripe. The provider for customers in the EU is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (“Stripe”). By clicking “Continue to payment” you are redirected to a Stripe payment page. There, Stripe collects your payment data (e.g. card number), name, email address, billing address and technical data about your device (including IP address) in order to carry out the payment, prevent fraud and fulfil its own statutory obligations as a payment service provider; Stripe sets its own cookies on its page for this. We do not receive full card details. Stripe also issues the invoice on our behalf. Depending on the device, you can choose card, Link (Stripe’s fast-checkout service), Apple Pay, Google Pay and PayPal.
Stripe may transfer data to Stripe, Inc. in the USA. This transfer relies on Stripe’s certification under the EU-US Data Privacy Framework (DPF) and on the European Commission’s standard contractual clauses. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). Stripe itself is responsible for fraud prevention and its own statutory obligations. Details: stripe.com/privacy.
PayPal: If you choose PayPal on Stripe’s payment page, you are redirected to PayPal. The provider is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. PayPal receives the data needed for the payment (including amount, name, email address) and processes it under its own responsibility. The legal basis is Art. 6(1)(b) GDPR. Details: PayPal privacy policy.
Referral programme: Every purchased license has a referral link. If you buy through such a link (recognisable by ?ref= in the address), the code is passed on to the purchase page only through links, without cookies; we store with the purchase which license made the referral. The referring person does not learn who bought; 14 days after the purchase, unless refunded, they are credited one year of updates and receive a short email about it. The legal basis is Art. 6(1)(b) GDPR (running the referral programme as part of the contract) or (f) (legitimate interest in settling the reward).
Refunds: In the event of a withdrawal or a refund, Stripe notifies us of it; we note it against the purchase and suspend the licence, or deduct refunded additional seats.
This section concerns customers who run CoWorkboard on their own server, and the people who have an account there.
Download: You download the software using your licence key via shop.coworkboard.de. This produces the server log files described above; in addition, we check the licence key.
Licence check and updates: Each installation asks the licence server once a day for updates. The licence key, the installation’s domain and the installed version are transmitted; we store the time of the last check for this. The purpose is to verify the licence, bind it to a domain, and deliver updates and security updates. The legal basis is Art. 6(1)(b) GDPR.
Guests with their own seat: So that a person who already has a paid seat in another CoWorkboard licence can be invited without using up another seat, the installation reports checksums (SHA-256 hashes) of the email addresses of its occupied seats during the daily check. Plain-text addresses are not transmitted. If someone in another installation invites an address, that installation only queries the checksum and receives only “has a seat” or “has no seat” in response. The stored checksums of a licence are fully replaced on every report; anyone whose account is deleted drops out within a day at the latest. Queries are limited per licence to prevent trying out addresses.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest, and that of our customers, is that already-paid seats don’t have to be paid for twice. Installation operators can switch off the reporting at any time with the setting SEAT_SHARING=0; the stored checksums are then deleted on the next check. Operators of each installation are themselves responsible for their users’ accounts and inform their users about this.
Trial version: If you request the free 7-day trial at shop.coworkboard.de/testen.php, we store your email address, the generated trial key and the time of the request, and email you the trial key and download link. The 7 days start with the first license check of your installation; the license check described above applies. To prevent mass requests we count requests per IP address and day, storing only a shortened checksum of the IP address, which is deleted after one day. There is one trial per email address. The legal basis is Art. 6(1)(b) GDPR (steps prior to entering into a contract) and, for abuse prevention, Art. 6(1)(f) GDPR. If you don’t buy, we delete the trial data no later than 12 months after it ends. After the trial ends, your installation shows a discount offer for 24 hours; the link to it contains your trial key so the shop can check the offer.
Emails about new versions: Only if you tick the optional box when requesting the trial and click the confirmation link in the email (double opt-in) do we send you a short email with the changes for each new version. For this we store your email address, the consent status and a random key for the links. The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time via the unsubscribe link in each of these emails or informally by emailing us; after that you won’t receive such emails any more.
Live demo: At demo.coworkboard.de you can try CoWorkboard without signing up. We don’t ask for any personal data there. The demo sets a technically necessary session cookie (lifetime up to 30 days) that keeps you signed in to the shared demo account during your visit, and stores display settings in your browser’s local storage. Whatever you enter in the demo, such as cards or comments, is visible to all other visitors and is completely deleted within an hour at the latest. Please don’t enter any personal data there. The legal basis is Art. 6(1)(f) GDPR, and for the cookie Section 25(2) No. 2 TDDDG.
As of: 29 Sep 2026. Basis for sections 01 to 04: eRecht24.