Privacy policy

This is a courtesy translation. The legally binding version is the German Datenschutzerklärung. It covers the website kundrio.de and the demo at demo.kundrio.de. For the application at app.kundrio.de, the data processing agreement with each customer applies.

Information pursuant to Art. 13 and Art. 14 GDPR.

1. Controller

The controller within the meaning of the GDPR for processing in connection with this website and the demo is:

Pioneerdesk GmbH
Palmberg 29, 84539 Zangberg, Germany
Represented by the managing director Marcus Lenczyk
Email: info@kundrio.de
Phone: +49 162 375 3011

2. Data protection officer

We are not legally obliged to appoint a data protection officer; the requirements of § 38 BDSG (in particular, generally employing at least 20 people in the automated processing of personal data) are not met. For all data protection matters, you can reach us at the email address above.

3. Hosting and processors

We operate kundrio.de, the demo at demo.kundrio.de and the application at app.kundrio.de on the infrastructure of STACKIT (Schwarz Group). Processing takes place exclusively in data centres in Germany.

Processing purely in Germany/the EU, no third-country transfer. No personal data is transferred to a third country outside the EU/EEA; standard contractual clauses (SCC) under Art. 46 GDPR are therefore not required for hosting. A data processing agreement under Art. 28 GDPR is in place with the hosting provider.

4. Processing when you visit the website

When you access our website, the server automatically processes server log data that is technically required to deliver the page and to keep operations secure and stable. This includes in particular:

  • IP address
  • date and time of access
  • requested resource (URL) and HTTP status code
  • amount of data transferred
  • referrer URL as well as browser type/version and operating system (user agent)

The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure, functioning operations).

No cookies on kundrio.de. The website sets no cookies and uses no local storage. No tracking, no analytics, no audience measurement, no advertising or third-party cookies, no external fonts or CDN resources. A cookie consent banner is therefore not required under § 25 TDDDG.

5. Contact by email or phone

If you write to us or call us, we process your details (name, contact details, content of your request) to handle your request. The legal basis is Art. 6 (1) (b) GDPR where a contract or its preparation is concerned, otherwise Art. 6 (1) (f) GDPR.

6. Demo at demo.kundrio.de

The demo is a single account shared by all visitors. Please do not enter real personal data.

  • Login session: After you log in, we set the technically necessary session cookie pd_session (readable only by the server, lifetime at most 14 days). Your device is accessed only to the extent strictly necessary for the service you explicitly requested (§ 25 (2) no. 2 TDDDG). Every session ends with the nightly reset.
  • Your input: Whatever you enter in the demo is visible to other visitors and is completely deleted every night and replaced with sample data.
  • Emails: The demo does not send any emails.
  • AI features: Text you pass to AI features (e.g. drafts, summaries, knowledge search) is sent for processing to STACKIT AI Model Serving (data centres in Germany). STACKIT acts as our processor.
  • Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in demonstrating the software).

7. Two roles – please distinguish

For data protection purposes, two separate processing situations must be distinguished:

(a) Website visitors, prospects and the demo. For processing in connection with visiting the website, using the demo and any contact, Pioneerdesk GmbH itself is the controller within the meaning of Art. 4 (7) GDPR. This privacy policy applies.

(b) Customer data in app.kundrio.de. Where a business customer processes personal data in Kundrio (e.g. contacts, emails, form submissions), Pioneerdesk GmbH acts exclusively as a processor bound by the customer's instructions (Art. 28 GDPR). The customer is the controller in that case. The details are governed by the data processing agreement (DPA) together with the technical and organisational measures (TOMs).

8. Retention

Server log data is stored only as long as necessary for the purposes stated and then deleted or anonymised, usually within 7 days. Requests by email or phone are stored until your matter is settled. For data processed on behalf of customers, the deletion and return rules agreed in the DPA apply. Statutory retention obligations (e.g. §§ 147 AO, 257 HGB) remain unaffected.

9. Your rights as a data subject

Under the GDPR, you have the right to:

  • access (Art. 15 GDPR)
  • rectification (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • object to processing (Art. 21 GDPR) where it is based on Art. 6 (1) (f) GDPR

If the processing concerns data for which we act as a processor, please address your request to the responsible customer; we support them in accordance with the DPA.

10. Right to lodge a complaint

Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state of your habitual residence, place of work or place of the alleged infringement. The supervisory authority responsible for the controller is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de

11. Last updated

This privacy policy was last updated on 9 October 2026. We will update it whenever changes to the processing or the legal situation require it.