Privacy Policy according to Art. 13 GDPR

Name and Address of the Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection regulations is:

Bridge ITS GmbH
Käthe-Kollwitz-Ufer 76
01309 Dresden
Germany

Contact
info@bridge-systems.com

Name and Address of the Data Protection Officer

The Data Protection Officer of the controller is:

3 P Datenschutz GmbH
Stefan Leißl
Sanderstraße 47
86161 Augsburg
Telefon: 0821 6508 8582
E-Mail: leissl@3-p-datenschutz.de

General Information on Data Processing

Legal Basis for Processing Personal Data

In accordance with Art. 13 GDPR, we inform you about the legal bases of our data processing. Unless the legal basis is specifically mentioned in the privacy policy, the following applies:
The legal basis for obtaining consent is Art. 6(1)(a) in conjunction with Art. 7 GDPR. The legal basis for processing to fulfill our services and implement contractual measures as well as to respond to inquiries is Art. 6(1)(b) GDPR. The legal basis for processing to fulfill our legal obligations is Art. 6(1)(c) GDPR. If the processing of your data is necessary to protect a legitimate interest of our company or a third party and if the interests, fundamental rights and freedoms of the data subject do not override the first-mentioned interest, Art. 6(1)(f) GDPR serves as the legal basis for processing. In cases where vital interests of the data subject or another natural person make the processing of personal data necessary, Art. 6(1)(d) GDPR serves as the legal basis.

Data Deletion and Storage Duration

We adhere to the principles of data minimization according to Art. 5(1)(c) GDPR and storage limitation according to Art. 5(1)(e) GDPR. We store your personal data only for as long as necessary to achieve the purposes mentioned here or as required by statutory retention periods. After the respective purpose ceases to exist or after these retention periods expire, the corresponding data will be deleted promptly.

Note on Data Transfer to Third Countries

Our website also includes tools from companies based in third countries (notably the USA). If these tools are active, your personal data may be transferred to the servers of the respective companies. The data protection level in third countries generally does not correspond to EU data protection law. Therefore, there is a risk that your data may be disclosed to authorities in these countries. We have no influence on these processing activities.

Use of AI-supported conversation transcription and automated summarization

The bridge platform offers the possibility to create a transcription and automated summary of the conversation using Artificial Intelligence (AI) during consultation sessions. The aim is to improve the quality of consultation and enable more precise documentation of conversation content.

The activation of this function occurs exclusively situatively and by the respective consultant. Before any recording, the customer is transparently informed that an AI-supported processing of their statements will take place. The function is activated only after explicit, voluntary consent. During transcription, the customer can see that this function is activated and has the option to deactivate it at any time.

By consenting, the customer confirms that they have been informed about the purpose, scope and technical functionality and have read and understood the privacy notice regarding the processing.

The legal basis for data processing is Art. 6(1)(a) GDPR (consent). The consent can be revoked at any time with effect for the future. The revocation has no disadvantages for further consultation.

There is no automated decision making based on the captured data. The stored transcripts and summaries are used exclusively for internal consultation purposes. They are deleted once the purpose ceases to exist or at the request of the data subject, provided there are no legal retention obligations. The customer can request their own transcript and its deletion at any time.

The usage is in accordance with the transparency requirements of the EU AI Act (Art. 52). An interaction with Artificial Intelligence exists and is marked accordingly.

Processing of Personal Data for Appointments

The bridge platform enables end users to independently book consultation appointments with their personal advisor. As part of this process, we collect and process various personal data to ensure smooth and efficient communication and appointment handling.

Specifically, we process first name and last name, email address, optionally a phone number, contents of the free text field such as concerns or appointment type as well as the calendar entry with associated metadata like timestamp and status.

Note: Please do not provide any sensitive information according to Art. 9 GDPR in the free text field, such as health data or information about religious beliefs.

Purpose of Processing

The data collected during appointment booking is used exclusively to efficiently organize the consultation process. This includes sending you appointment confirmations and reminders, contacting you for questions or changes, maintaining calendar functionality and avoiding double bookings. Additionally, this information allows us to optimally manage advisor availability.

An appointment can be scheduled maximum 120 days in advance. The data collected during the appointment booking process is stored in accordance with legal requirements and then deleted.

Legal Bases under GDPR

The legal basis for data processing is Art. 6(1)(b) GDPR, as the processing is necessary for the implementation of pre-contractual measures as well as for the fulfillment of a contract. Additionally, Bridge ITS GmbH has a legitimate interest in the technically stable and user-friendly execution of the appointment process and in quality assurance. This interest is also legally secured according to Art. 6(1)(f) GDPR.

Data may remain stored even after the actual appointment if this serves quality assurance or internal documentation purposes. This also occurs within the scope of our legitimate interest.

Integration into Customer Profile

The information collected during appointment scheduling – i.e. name, email address and if applicable phone number – is automatically transferred to the central Customer Relationship Management system of the bridge platform. This system serves the structured management of all customer interactions and enables us to analyze, improve and efficiently control usage processes.

Bridge ITS GmbH is responsible for this data processing. It occurs on the same legal bases as the appointment booking itself. If there is a technical interface to a CRM system of the consulting partner, the data can additionally be transferred there once an appointment is accepted.

Sign-in and Calendar Synchronization via Google and Microsoft

The bridge platform offers the option to link your user account with a Google or Microsoft account. The link can be used for registration and sign-in (single sign-on) and – independently of that – for the synchronization of appointments with the calendar of the respective provider.

Both functions are voluntary, optional additional features and not a mandatory part of using the platform. bridge can be used entirely with your own email address and your own password and without any calendar link. If you choose not to create a link, there is no limitation other than the calendar synchronization itself.

The legal basis for the link and the associated processing is your consent pursuant to Art. 6 para. 1 lit. a GDPR, which you give by actively creating the link and confirming the permission dialog at the respective provider. The link is established using the standard OAuth 2.0 / OpenID Connect procedure; bridge never receives your password for the respective provider, only time-limited access tokens.

Since the processing technically takes place at Google LLC or Microsoft Corporation, both based in the USA, data is transferred to a third country in the process. Both providers are certified under the EU-US Data Privacy Framework, for which the European Commission has issued an adequacy decision. Please also note our section "Note on Data Transfer to Third Countries".

Google

Which data is accessed: For registration and sign-in, bridge requests only the permissions (scopes) openid, email and profile. This provides us with a pseudonymous account identifier, your email address and basic profile data such as your name and, where applicable, profile picture and language setting.

For calendar synchronization, the permissions https://www.googleapis.com/auth/calendar.readonly (reading your calendar list and your appointments) and https://www.googleapis.com/auth/calendar.events.owned (creating, modifying and deleting only those appointments that you created yourself or for which you are the organizer) are added. This involves reading the calendar name and identifier as well as, for each appointment, the title, start and end, description, location, availability status (free/busy) and the markers for all-day and cancelled appointments. So that synchronization can also run without an open session, a refresh token is additionally issued and stored.

There is no access to your phone number, your postal address, your contacts, your email mailbox, your files or any other content of your Google account.

Please note: Calendar synchronization with Google is currently not yet available, as the verification procedure with Google has not been completed. The permissions described above are disclosed here in advance and apply from the moment this function is enabled.

What the data is used for: Account identifier, email address and name are used exclusively for authentication, i.e. signing in securely without a separate bridge password, and for creating and matching your bridge user account. The calendar data is used exclusively to display and reconcile your appointments in bridge, to avoid double bookings, to correctly represent your availability and to write bridge appointments back to your calendar.

Sharing, transfer and disclosure: Data received from Google APIs is not shared with or sold to third parties, is not used for advertising or profiling and is not used to train generalized AI or machine learning models. It is processed exclusively by Bridge ITS GmbH and by the processors and hosting providers named in this privacy policy. Humans do not read this data – except with your explicit consent, for security and abuse purposes, to comply with applicable law, or in aggregated and anonymized form.

bridge's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Storage duration and withdrawal: We store access and refresh tokens as well as the assignment of the linked calendar for as long as the link exists; they are deleted once the link is removed. Imported calendar data is stored only for as long as it is required for synchronization. You can remove the link at any time in bridge in your profile or calendar settings and additionally withdraw your consent directly at Google at myaccount.google.com/permissions. After withdrawal, bridge no longer accesses your Google account. Please note the scope of the withdrawal: appointments already written to your Google calendar remain there and may have to be deleted there; the lawfulness of the processing carried out up to the withdrawal remains unaffected; removing a link used for sign-in does not delete your bridge user account – in that case you subsequently sign in with your email address and password.

Microsoft

Which data is accessed: For registration and sign-in, bridge requests only the permissions (scopes) openid, email and profile. This provides us with a pseudonymous account identifier, your email address and basic profile data such as your name.

For calendar synchronization, bridge requests the permissions openid, offline_access, Calendars.Read and Calendars.ReadWrite. This access deliberately takes place without profile and email permission, so only the account identifier and the calendar data are processed. We read your calendar list as well as, for each appointment, the identifier, title, start and end, description, location, availability status (free/tentative/busy) and the markers for all-day and cancelled appointments. For ongoing synchronization, bridge registers a subscription for change notifications for the linked calendar with Microsoft so that changes can be applied promptly. The permission offline_access enables synchronization even without an open session.

There is no access to your phone number, your postal address, your contacts, your email mailbox, your files or any other content of your Microsoft account.

What the data is used for: Account identifier, email address and name are used exclusively for authentication and for creating and matching your bridge user account. The calendar data is used exclusively to display and reconcile your appointments in bridge, to avoid double bookings and to correctly represent your availability.

Write access: bridge writes appointments exclusively to those calendars that you explicitly marked as target calendars when creating the link. Only the title, start and end, availability status, description and location of the appointment are transferred, plus two technical markers by which bridge recognizes its own entries. Email addresses and names of other participants are not transferred to Microsoft; no meeting invitations are sent via this interface either.

Sharing, transfer and disclosure: Data received from the Microsoft interfaces is not shared with or sold to third parties, is not used for advertising or profiling and is not used to train generalized AI or machine learning models. It is processed exclusively by Bridge ITS GmbH and by the processors and hosting providers named in this privacy policy.

Storage duration and withdrawal: We store access and refresh tokens as well as the assignment of the linked calendar for as long as the link exists; they are deleted once the link is removed, and the subscription for change notifications is terminated. Imported calendar data is stored only for as long as it is required for synchronization. You can remove the link at any time in bridge in your profile or calendar settings and additionally withdraw the granted permission directly in the permission settings of your Microsoft account. After withdrawal, bridge no longer accesses your Microsoft account. Please note the scope of the withdrawal: appointments already written to your Microsoft calendar remain there and may have to be deleted there; the lawfulness of the processing carried out up to the withdrawal remains unaffected; removing a link used for sign-in does not delete your bridge user account.

External Links

This website may contain links to third-party websites or to other websites under our responsibility. If you follow a link to any websites outside our responsibility, please note that these websites have their own privacy policies. We do not accept any responsibility or liability for these external websites and their privacy notices. Therefore, please check before using these websites whether you agree with their privacy policies.

You can recognize external links either by being slightly offset in color from the rest of the text or by being underlined. Your cursor will indicate external links when you hover over such a link. Only when you click on an external link will your personal data be transmitted to the link destination. The operator of the other website receives in particular your IP address, the time at which you clicked the link, the page on which you clicked the link, as well as other information that you can find in the privacy policy of the respective provider.

Please also note that individual links may lead to data transmission outside the European Economic Area. This could allow foreign authorities to access your data. You may not have any legal remedies against such data access. If you do not want your personal data to be transferred to the link destination or even unintentionally exposed to access by foreign authorities, please do not click on any links.

Rights of the Data Subject

As a data subject within the meaning of the GDPR, you have various rights that you can exercise. The data subject rights under the GDPR include the right of access (Art. 15), the right to rectification (Art. 16), the right to erasure (Art. 17), the right to restriction of processing (Art. 18), the right to object (Art. 21), the right to lodge a complaint with a supervisory authority, and the right to data portability (Art. 20).

Right of Withdrawal:

Some data processing operations can only be carried out with your express consent. You have the right to withdraw your consent at any time. The lawfulness of data processing, up until the withdrawal, remains unaffected.

Right to Object:

If processing is based on Art. 6(1)(e) or (f) GDPR, you as a data subject have the right to object at any time to the processing of personal data concerning you on grounds relating to your particular situation. This right also applies to profiling based on these provisions within the meaning of Art. 4(4) GDPR. If we cannot demonstrate compelling legitimate grounds for processing which override your interests, rights and freedoms, or processing serves the establishment, exercise or defense of legal claims, we will cease processing your data after your objection.

If personal data is processed for direct marketing purposes, you also have the right to object at any time. The same applies to profiling related to direct marketing. Here too, we will no longer process personal data once you raise an objection.

Right to Lodge a Complaint with a Supervisory Authority:

If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your residence, place of work or place of the alleged violation, without prejudice to any other administrative or judicial remedy.

Right to Data Portability:

If your data is processed based on consent or contract performance in an automated manner, you have the right to receive this data in a structured, commonly used and machine-readable format. Furthermore, you have the right to request the transfer and provision of the data to another controller, insofar as this is technically feasible.

Right of Access, Rectification and Erasure:

You have the right to obtain information about your processed personal data regarding the purpose of data processing, the categories, recipients and duration of storage. For questions on this topic or other topics regarding personal data, you can of course contact us via the contact details provided in the imprint.

Right to Restriction of Processing:

You can request restriction of the processing of your personal data at any time. To do so, you must meet one of the following requirements:
  • You contest the accuracy of the personal data. For the duration of verifying the accuracy, you have the right to request restriction of processing.
  • If processing is unlawful, you can request restriction of data use instead of erasure.
  • If we no longer need your personal data for processing purposes but you need the data for the establishment, exercise or defense of legal claims, you can request restriction of processing instead of erasure.
  • If you object to processing pursuant to Art. 21(1) GDPR, a balancing of interests between your and our interests will be carried out. Until this balancing is completed, you have the right to request restriction of processing.

A restriction of processing means that personal data may only be stored and not processed in any other way, except with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.
Website Hosting (Web Hosting Provider)
Our website is hosted by:

IONOS SE Elgendorfer Straße 57, 56410 Montabaur
Germany

When you visit our website, we automatically collect and store information in server log files. This information is automatically transmitted by your browser to our server or to the server of our hosting company.

This includes:
  • IP address of the website visitor's device
  • Device used
  • Hostname of the accessing computer
  • Visitor's operating system
  • Browser type and version
  • Name of the retrieved file
  • Time of server request
  • Amount of data
  • Information whether the data retrieval was successful

This data is not combined with other data sources.

The legal basis for processing this data is Art. 6(1)(f) GDPR. Our legitimate interest is the technically error-free presentation and optimization of this website.

Instead of operating this website on our own server, we can also have it operated on the server of an external service provider (hosting company). In this case, the personal data collected on this website is stored on the servers of the hosting company. In addition to the above-mentioned data, this may include contact requests, contact details, names, website access data, meta and communication data, contract data and other data generated through a website.
As an additional legal basis, the purpose of pre-contractual or contractual performance with respect to the data subject is cited. (Art. 6(1)(b) GDPR). In the event that we have commissioned a hosting company, there is a data processing agreement with this service provider.
Use of Local Storage Items, Session Storage Items and Cookies
Our website uses local storage items, session storage items and/or cookies. Local storage is a mechanism that enables the storage of data within the browser on your device. This data usually includes user preferences, such as "day mode" or "night mode" of a website, and remains stored until you manually delete the data. Session storage is very similar to local storage, whereas the storage duration only lasts during the current session, i.e. until the current tab is closed. After that, the session storage items are deleted from your device. Cookies are information that a web server (server providing web content) stores on your device to identify this device. They are either stored temporarily for the duration of a session (session cookies) and deleted after your visit to a website or permanently (permanent cookies) on your device until you delete them yourself or automatic deletion occurs through your web browser.

These objects can also be stored on your device by third-party companies when you enter our site (third-party requests). This enables us as operators and you as visitors of this website to use certain services from third parties that are installed on this website. Examples include the processing of payment services or the display of videos.

These mechanisms have various applications. They can improve the functionality of a website, control shopping cart functions, increase the security and convenience of website usage, and conduct analyses regarding visitor flows and behavior. Depending on the individual functions, these are to be classified under data protection law. If they are necessary for the operation of the website and intended to provide certain functions (shopping cart function) or serve to optimize the website (e.g. cookies to measure visitor behavior), then their use is based on Art. 6(1)(f). As website operators, we have a legitimate interest in storing local storage items, session storage items and cookies for the technically error-free and optimized provision of our services. In all other cases, the storage of local storage items, session storage items and cookies only occurs with your express consent (Art. 6(1)(a) GDPR).

If local storage items, session storage or cookies are used by third-party companies or for analysis purposes, we will inform you separately about this within this privacy notice. Your consent will be requested and can be revoked at any time.

Use of External Services

Our website uses external services. External services are third-party services that are used on our website. This can be for various reasons, for example for embedding videos or for website security. When using these services, personal data is also transferred to the respective providers of these external services. If we do not have a legitimate interest in using these services, we obtain your revocable consent as a visitor to our website before using them (Art. 6(1)(a) GDPR).
Web Security
On our website, we use tools that protect against unauthorized access, spam or other attacks. This increases the security of our website.

We base this processing on a legitimate interest (Art. 6(1)(f) GDPR).

Our legitimate interest is to ensure the security of our website and protect ourselves against unauthorized access, spam and other attacks.
Use of AltCha to prevent abuse and spam
We use the AltCha service to protect our website and online services from automated attacks, bots and spam.

AltCha is a so-called Captcha service that ensures that the interactions carried out on our website are with human users. Unlike other providers, AltCha is not based on the analysis of personal data or the creation of user profiles. Instead, AltCha uses a process called proof-of-work, in which the end device used solves small computing tasks in the background to rule out automated bots. No personal data is collected, processed or stored in the process.

In particular, there is no tracking, no transfer of data to third parties and no evaluation of user behavior. No cookies are set, no IP addresses are stored and no data is transmitted to AltCha servers, as the captcha service is hosted entirely by bridge.

The legal basis for the processing is our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR to ensure the security of our website and the trouble-free operation of our online services and to protect us against misuse and attacks.

You can find more information about AltCha at: https://altcha.org


Last updated: 31 July 2026