Privacy Policy
Effective Date: September 2025
Company: Beyond Corporate GmbH
Address: Ahornweg 9, 22395 Hamburg, Germany
Email: office@thinkbeyondcorporate.com
Website: https://www.thinkbeyondcorporate.com/
1. Introduction
Beyond Corporate GmbH (“Beyond Corporate”, “we”, “our”, “us”) respects your privacy and values the trust you place in us.
This Privacy Policy explains how we collect, process, store, and protect your personal data when you visit our website, use our services, or communicate with us in any way.
We are committed to protecting your personal information in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and all applicable data protection laws in Germany and the European Union.
Our mission as a company is to provide world-class software and app development services, and we take privacy as seriously as we take performance, security, and design in our products.
2. Data Controller
The data controller responsible for processing your personal data is:
Beyond Corporate GmbH
Ahornweg 9, 22395 Hamburg, Germany
Email: office@thinkbeyondcorporate.com
As the controller, we determine the purposes and means of processing personal data.
If you have any questions about how we process your information or wish to exercise your rights, you can reach out to us via the email above.
3. What Data We Collect
We collect personal data only when necessary for legitimate business purposes. Depending on your interaction with us (visitor, client, supplier, or applicant), we may collect the following categories of data:
a) Contact Data
- Full name
- Company name
- Job title or role
- Email address
b) Communication Data
- Information you send to us via email or contact forms (including project inquiries, support requests, or other correspondence)
- Any attachments or documents you choose to share
c) Technical and Usage Data
- IP address, browser type, and operating system
- Date and time of access
- Pages visited, time spent on pages, and referring URLs
- Device information (e.g., desktop, tablet)
- Cookie identifiers or other tracking information
d) Client and Project Data
For our software and app development clients, we may process limited personal data as part of providing our services — for example, user data, test accounts, or datasets provided by clients.
We handle such data strictly under the client’s instructions and ensure confidentiality through contractual agreements.
e) Billing and Transaction Data
- Business address and billing details
- Bank or payment reference numbers (when applicable for invoicing)
- Records of payments and accounting documentation
4. How We Use Your Data
We process personal data solely for defined purposes and only when a lawful basis applies under Article 6 of the GDPR.
We may use your data for the following:
a) Service Delivery and Contract Fulfillment
To provide and manage our software and app development services, including:
- Preparing offers, project proposals, and contracts
- Setting up project communication channels
- Delivering and maintaining digital solutions
- Managing client relationships and support
b) Communication and Correspondence
To respond to emails and inquiries, schedule meetings, or send project updates and administrative notifications.
c) Website Operation and Improvement
To operate, secure, and optimize our website, including performance monitoring, analytics, and troubleshooting issues.
d) Legal and Compliance Obligations
To comply with applicable German and EU legal obligations such as tax regulations, record retention laws, and data protection audits.
e) Business Interests and Development
To evaluate and improve our products and services, analyze usage data, and ensure that our website and digital tools meet user needs.
5. Legal Bases for Processing
Under Article 6 of the GDPR, we process your personal data based on one or more of the following legal grounds:
- Art. 6(1)(a) Consent: When you explicitly consent (e.g., submitting a contact form).
- Art. 6(1)(b) Contract: When processing is necessary for the performance or preparation of a contract.
- Art. 6(1)(c) Legal Obligation: When we are required by law to process your data.
- Art. 6(1)(f) Legitimate Interest: When processing is necessary for our legitimate business interests, such as improving services, website maintenance, or ensuring network security.
We always balance our legitimate interests with your fundamental rights and freedoms before relying on this basis.
6. Cookies and Analytics
Our website uses cookies and similar tracking technologies to ensure smooth functionality and enhance user experience.
Cookies are small text files placed on your device that help us analyze how users interact with our site and remember your preferences.
a) Types of Cookies We Use
- Essential Cookies: Required for website operation (e.g., session cookies).
- Performance Cookies: Measure traffic and usage patterns (e.g., Google Analytics).
- Preference Cookies: Store your preferences (e.g., language selection).
b) Managing Cookies
You can manage cookie preferences in your browser settings. You may refuse or delete cookies, though doing so may affect the site’s functionality.
Before setting non-essential cookies, we seek your consent via a cookie banner in compliance with GDPR Article 7.
c) Analytics
We may use Google Analytics or similar tools to gather anonymized data about user behavior, enabling us to improve website content and performance.
Analytics data is anonymized wherever possible, and no personally identifiable data is used without consent.
7. Data Sharing and Transfers
We treat your personal information as confidential and share it only when necessary.
We may disclose your information to:
- Service Providers: such as hosting providers, email systems, and analytics services, under strict data processing agreements (Art. 28 GDPR).
- Professional Advisors: including auditors, accountants, and lawyers, under confidentiality obligations.
- Legal Authorities: when required to comply with legal obligations or court orders.
- Clients or Partners: where necessary for project delivery and contractual collaboration.
If we transfer data outside the European Economic Area (EEA), we ensure compliance using EU Standard Contractual Clauses (SCCs) or other GDPR-approved mechanisms.
We do not sell, rent, or trade personal information for marketing or any other commercial purposes.
8. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal requirements.
Typical retention periods:
- General contact and communication data: up to 2 years after last correspondence.
- Client project data: retained for up to 5 years following project completion, unless longer retention is legally required or contractually agreed.
- Billing, financial, and tax data: retained for 10 years as per German tax law (§147 AO).
Once data is no longer required, it is securely deleted, anonymized, or archived according to best practices.
9. Your Rights Under GDPR
As a data subject, you have the following rights under the GDPR:
- Right of Access (Art. 15): Request a copy of your personal data we hold.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete information.
- Right to Erasure (Art. 17): Request deletion of your data (“right to be forgotten”).
- Right to Restrict Processing (Art. 18): Temporarily stop processing your data.
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests.
- Right to Withdraw Consent (Art. 7(3)): Withdraw your consent at any time.
To exercise your rights, email us at office@thinkbeyondcorporate.com.
We will respond promptly, usually within 30 days, unless a longer period is justified due to complexity.
If you believe your data has been handled unlawfully, you have the right to lodge a complaint with the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI).
10. Data Security
We implement appropriate technical and organizational measures (TOMs) to ensure the protection of personal data against unauthorized access, loss, or misuse.
Our security framework includes:
- Secure data hosting in GDPR-compliant servers
- Encrypted communications (HTTPS/SSL)
- Regular access control reviews
- Employee confidentiality agreements
- Routine backups and system monitoring
Despite our best efforts, no system can be guaranteed completely secure; however, we continuously review and improve our safeguards.
11. Third-Party Links and Integrations
Our website may contain links to third-party websites, tools, or plugins (such as GitHub, LinkedIn, or analytics dashboards).
These third-party sites operate independently and have their own privacy policies.
We encourage users to review those policies, as we do not control their content or data practices.
12. Changes to This Privacy Policy
We reserve the right to amend this Privacy Policy at any time to reflect new legal requirements, technological developments, or changes in our business operations.
Whenever changes are made:
- The effective date at the top will be updated.
- The latest version will be published on our website.
- Significant updates may be communicated via email or website notices.
Your continued use of our website or services after such updates constitutes your acceptance of the revised policy.
13. Contact Information
For all data protection inquiries, including requests related to your rights or questions about this Privacy Policy, please contact:
Beyond Corporate GmbH
Ahornweg 9, 22395 Hamburg, Germany
Email: office@thinkbeyondcorporate.com
