Legal
Privacy policy
Last updated: 27 July 2026
1. Controller
Zalion GmbH
Bildungscampus 11
74076 Heilbronn
Germany
Represented by the managing directors Alex Morbe and Moritz Weimer
Register court: Amtsgericht Stuttgart, HRB 799733
Email: info@zalion.ai
Phone: +49 (0) 178 5302489
2. Scope
This privacy policy applies to our website at zalion.ai.
3. Overview of processing activities
Categories of data processed
Master and contact data (e.g. name, company, position, email address, phone number)
Content data (e.g. entries in forms, contents of messages)
Usage data (e.g. pages visited, time on page, access times, referrer, campaign parameters)
Meta, communication and procedural data (e.g. IP addresses, browser and device information, cookie identifiers)
Application data (e.g. CV, references, details of your professional background)
Categories of data subjects
Visitors to our website
Prospects, customers and their contact persons
Job applicants
Purposes of processing
Provision, operation and security of our website
Handling contact requests and demo appointments
Audience measurement and optimization of our offering
Prospect management and business development
Running application processes
Compliance with legal obligations
4. Legal bases
We process personal data on the basis of:
Art. 6(1)(a) GDPR – consent
Sec. 25(1) TDDDG – consent to the storage of, or access to, information on your device
Sec. 25(2) no. 2 TDDDG – strictly necessary storage and access operations
Art. 6(1)(b) GDPR – performance of a contract and pre-contractual measures
Art. 6(1)(c) GDPR – compliance with legal obligations
Art. 6(1)(f) GDPR – protection of legitimate interests
Sec. 26(1) BDSG – processing for the purposes of the employment relationship, including the application process
5. Provision of the website
5.1 Hosting
Our website is built with Framer and delivered via Framer's infrastructure. The provider is Framer B.V., Amsterdam, Netherlands. Framer processes the data generated when the website is accessed on our behalf; a data processing agreement under Art. 28 GDPR is in place.
Framer's privacy policy: https://www.framer.com/legal/privacy-statement/
5.2 Server log files
When our website is accessed, technical access data transmitted by your browser is processed automatically:
IP address of the requesting device
Date and time of access
Name and URL of the file retrieved
Referrer URL
Browser type, browser version and operating system
This processing is technically necessary in order to deliver the website, ensure its stability and security and fend off attacks. This data is not combined with other data sources, nor analyzed for marketing purposes.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in providing our offering securely and reliably.
Retention period: Log data is stored only as long as necessary for the purposes described and is then deleted or anonymized.
5.3 Domain and DNS
Our domain is registered with IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. IONOS operates the associated name servers and answers the technical name resolution requests through which your browser reaches our website. IONOS does not host the website content; that is delivered by Framer (see 5.1).
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the availability of our website).
5.4 Content delivery network
Images, scripts and font files are delivered via Framer's content delivery servers, including framerusercontent.com. For technical reasons your IP address is transmitted to these servers so that the content can be sent to your browser. For delivery and protection against automated access, Framer uses Cloudflare, among others, as a sub-processor.
Legal basis: Art. 6(1)(f) GDPR.
5.5 Google Fonts
Our website embeds fonts from Google Fonts. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
When you open a page, your browser loads the required fonts from a Google server. Your IP address is transmitted to Google in the process, which means Google learns that our website was accessed from your IP address. Embedding the fonts does not store cookies or access information on your device.
A transfer of data to the USA cannot be ruled out. Google LLC is certified under the EU-U.S. Data Privacy Framework, for which the EU Commission has determined an adequate level of data protection.
Legal basis: Art. 6(1)(a) GDPR. The fonts are embedded on the basis of your consent, which you can withdraw at any time with effect for the future.
Further information: https://policies.google.com/privacy and https://developers.google.com/fonts/faq
6. Cookies and consent management
Cookies are small text files stored on your device. We distinguish between two categories.
Technically necessary cookies and storage operations
These are required for the website to work and for your privacy settings to be saved. The choice you make in the consent banner is stored in your browser's local storage for that purpose. In addition, the cookie __cf_bm is set with a lifetime of 30 minutes. It comes from Cloudflare, our website's content delivery provider, and serves to distinguish automated from human access and to protect our offering against abuse. These storage operations take place without consent (Sec. 25(2) no. 2 TDDDG, Art. 6(1)(f) GDPR).
Cookies requiring consent
We only use cookies for analytics and marketing purposes – in our case the cookies from HubSpot (see section 8) – if you have explicitly agreed via our consent banner (Sec. 25(1) TDDDG, Art. 6(1)(a) GDPR). Until you consent, the corresponding scripts are not loaded.
Withdrawal: You can withdraw or adjust your consent at any time with effect for the future. To do so, use the cookie icon in the footer of our website. You can also delete cookies that have been set in your browser. The lawfulness of processing carried out up to the point of withdrawal remains unaffected.
7. Audience measurement with Framer Analytics
We use the analytics function built into Framer to understand how our website is used – for example page views, country of origin, device type and referrer.
Framer Analytics is privacy-friendly: no cookies are set and no persistent identifiers are stored on your device. To determine the daily visitor count, your IP address and user agent are hashed together with a random value that changes daily and is then deleted. This makes it impossible to identify you, and no recognition beyond the day takes place.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in statistical analysis and in designing our offering to meet actual demand. As no information on your device is accessed, no consent under Sec. 25 TDDDG is required.
Provider: Framer B.V., Amsterdam, Netherlands, as processor.
8. HubSpot
We use the HubSpot platform for website analytics, for forms and for managing prospect and customer relationships.
Provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland, jointly with HubSpot, Inc., USA.
8.1 Web analytics and tracking
After you consent, the HubSpot tracking code is loaded. It records in particular:
pages visited and time on page
referrer and campaign parameters (UTM)
browser, device and operating system information
IP address, also to determine region and company domain
a pseudonymous visitor identifier
In particular, the following cookies are set:
__hstc– recognition of visitors across multiple sessions (retention: no more than 6 months)hubspotutk– visitor identifier; passed to HubSpot when a form is submitted and used for matching in the CRM (retention: no more than 6 months)__hssc– records the current session and the page views within it (retention: 30 minutes)__hssrc– detects whether the browser was restarted between two page views (retention: session)
Depending on which HubSpot features we use on a given page, further cookies may be added. You will find an up-to-date overview of the cookies in use, including their retention periods, in our cookie settings.
The visitor identifier makes it possible to trace your behavior on our website. If you fill in a form or book an appointment, your previously pseudonymous usage history is linked to your contact record in our CRM.
Legal basis: Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG. You can withdraw your consent at any time with effect for the future.
8.2 Forms and demo booking
If you use our contact form or book a demo appointment via HubSpot Meetings, we process the data you enter – such as name, business email address, company, position and your message – as well as the chosen appointment and the technical metadata of the submission. This data is stored in HubSpot and used there to handle your enquiry and to manage the business relationship.
When booking an appointment, your time zone and the available time slots are also processed in order to complete the booking.
Legal basis: Art. 6(1)(b) GDPR for initiating or performing a contract, otherwise Art. 6(1)(f) GDPR based on our legitimate interest in responding to enquiries and in efficient prospect management.
8.3 Data processing agreement and transfer to the USA
A data processing agreement under Art. 28 GDPR is in place with HubSpot. HubSpot also processes data on servers in the USA. HubSpot, Inc. is certified under the EU-U.S. Data Privacy Framework, for which the EU Commission has determined an adequate level of data protection. In addition, the EU Commission's standard contractual clauses form part of the agreement.
HubSpot's privacy policy: https://legal.hubspot.com/privacy-policy
9. Email communication and Microsoft 365
We use Microsoft 365 for our business email communication and internal collaboration. The provider for customers in the European Economic Area is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.
If you contact us by email, we process your details in order to handle your enquiry. The communication may also be documented in our CRM.
A data processing agreement under Art. 28 GDPR is in place with Microsoft. Microsoft stores and processes the data of European customers within the EU and the EFTA states as part of the so-called EU Data Boundary. Where, in strictly limited cases, a transfer to the USA does occur, Microsoft Corporation is certified under the EU-U.S. Data Privacy Framework; the EU Commission's standard contractual clauses apply in addition.
Legal basis: Art. 6(1)(b) GDPR for contract-related communication, otherwise Art. 6(1)(f) GDPR.
10. Careers and applications
On our careers page we link to an externally hosted page on Notion (provider: Notion Labs, Inc., USA) describing our open roles. When you open that linked page, Notion's privacy terms apply and your IP address is transmitted to Notion. No Notion content is embedded on our own website.
Please send applications to us by email. We process the application data you submit – such as contact details, CV, references and details of your professional background – solely in order to run the application process.
Legal basis: Sec. 26(1) BDSG in conjunction with Art. 6(1)(b) GDPR (decision on entering into an employment relationship).
Retention period: If an application is unsuccessful, we delete the application documents no later than six months after the process is concluded, unless you have explicitly consented to longer retention for future positions. If an employment relationship is established, the data may be transferred to the personnel file.
11. Recipients of the data
We disclose personal data to:
Framer B.V., Netherlands – hosting, provision of the website, audience measurement
IONOS SE, Germany – domain and DNS
Google Ireland Limited, Ireland – provision of fonts
HubSpot Ireland Limited and HubSpot, Inc. – web analytics, forms, appointment booking, CRM
Microsoft Ireland Operations Limited – email and internal collaboration
Authorities and public bodies where there is a legal obligation
Legal and tax advisors as well as auditors, to the extent necessary
All service providers that process data on our behalf are contractually bound under Art. 28 GDPR.
12. Transfers to third countries
Where we transfer data to countries outside the European Economic Area or have it processed there, we do so only under the conditions of Art. 44 et seq. GDPR. The safeguards used are an adequacy decision of the EU Commission – in particular the EU-U.S. Data Privacy Framework – or the EU Commission's standard contractual clauses, in each case supplemented by appropriate additional protective measures.
13. Retention periods
We store personal data only as long as necessary for the respective purpose or as long as statutory retention obligations apply:
Server log files: stored briefly, then deleted or anonymized
Contact and demo requests without a subsequent business relationship: deleted as soon as the matter has been conclusively dealt with and no retention obligations prevent it
Business correspondence and contract documents: six or ten years respectively under Sec. 257 HGB and Sec. 147 AO
Analytics cookies: in line with the lifetimes stated in section 8.1
Application documents: six months after the process is concluded
Records of consent: for as long as there is an interest in evidencing it
14. Necessity of providing data
Providing your data is neither legally nor contractually required. However, without the details marked as mandatory in our forms we cannot process your enquiry.
15. Your rights
Under the GDPR you have the following rights:
Access to the data processed about you (Art. 15)
Rectification of inaccurate or incomplete data (Art. 16)
Erasure of your data (Art. 17)
Restriction of processing (Art. 18)
Data portability in a structured, commonly used and machine-readable format (Art. 20)
Objection to processing (Art. 21, see below)
Withdrawal of consent given with effect for the future (Art. 7(3))
An informal message to info@zalion.ai is enough to exercise them.
Right to object under Art. 21 GDPR
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out on the basis of Art. 6(1)(f) GDPR. We will then no longer process the data concerned, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
If your data is processed for direct marketing, you have the right to object at any time and without giving reasons. Following such an objection we will no longer process your data for that purpose.
16. Right to lodge a complaint
Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Postfach 10 29 32, 70025 Stuttgart, Germany
Email: poststelle@lfdi.bwl.de
17. Security of processing
We take appropriate technical and organizational measures in line with the state of the art to ensure a level of protection appropriate to the risk. These include transport encryption (TLS/HTTPS), access and authorization concepts, logging, and regular review and adjustment of our measures.
18. No automated decision-making
This website does not carry out solely automated decision-making, including profiling within the meaning of Art. 22 GDPR, that produces legal effects concerning you or similarly significantly affects you.
19. Minors
Our offering is aimed at companies and their employees, not at persons under the age of 16. We do not knowingly collect personal data from children.
20. Changes to this privacy policy
We update this privacy policy when changes to our processing activities or to the legal situation make it necessary. The current version is always available on this page. The date given at the top is the applicable one.