Data Privacy

Privacy Policy

Privacy Policy of Tacto Technology GmbH in accordance with the GDPR. The controller responsible for data protection is Tacto Technology GmbH, Sandstraße 33, 80335 Munich, Germany. Data subjects may contact the Data Protection Officer at any time with questions regarding data protection at datenschutz@tacto.ai.

A. General Information on Data Processing

1. Controller and Data Protection Officer

The controller responsible for data protection is:

Tacto Technology GmbH
Sandstraße 33
80335 Munich, Germany
Email: datenschutz@tacto.ai

Data subjects may contact the Data Protection Officer at any time with questions regarding data protection at the above address.

2. Principles of Data Processing and Retention Period

2.1 Legal Bases for Processing Personal Data

Personal data is collected and processed in accordance with the EU General Data Protection Regulation (GDPR) and European as well as national data protection laws.

Legal bases are:

  • Art. 6(1)(a) GDPR – Consent
  • Art. 6(1)(b) GDPR – Performance of a contract
  • Art. 6(1)(c) GDPR – Legal obligation
  • Art. 6(1)(f) GDPR – Legitimate interests

2.2 Storage and Deletion of Data

Personal data is only stored for as long as the purpose of storage requires. After the purpose ceases to apply, the data is deleted or processing is restricted. European and national retention periods may require longer storage.

2.3 Recipients of Data

Personal data is only shared with service providers, business partners, and third parties in accordance with applicable data protection laws.

Web Hosting by Webflow

Our Tacto website and thus your data are hosted, among others, by Webflow Inc., 398 11th Street, San Francisco, CA 94103, USA. Webflow may only access data within the scope of our instructions (commissioned processing). Webflow is certified under the EU-U.S. Data Privacy Framework and ensures an adequate level of data protection. Further information: https://webflow.com/legal/dpa

Other categories of recipients:

  • Courts and authorities in case of legal obligations
  • Internal recipients for processing within departments
  • Cooperation partners for service provision
  • External data processors
  • Client companies for which Tacto operates
  • Auditors

3. Your Rights

As a data subject, you have the following rights:

Right of Access: You may request information about the processing of your data at any time (Art. 15 GDPR).

Right to Rectification: Inaccurate or incomplete data may be corrected (Art. 16 GDPR).

Right to Restriction of Processing: You may request restriction of processing (Art. 18 GDPR).

Right to Erasure: You may request deletion of personal data, provided the legal requirements are met (Art. 17 GDPR).

Right to Notification: In the event of rectification, erasure, or restriction of processing, recipients must be notified (Art. 19 GDPR).

Right to Data Portability: You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format (Art. 20 GDPR).

Right to Object: You may object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR).

Objection to Advertising: In the case of direct marketing, you may object at any time (Art. 21(2) GDPR).

Objections can be sent to: datenschutz@tacto.ai

Right to Withdraw Consent: Consent may be withdrawn at any time with future effect (Art. 7 GDPR). You can adjust or withdraw your cookie and tracking consents at any time via the “Cookie Settings” link in the page footer or the privacy icon at the bottom left of every page.

Right to Lodge a Complaint: You may file a complaint with a data protection supervisory authority, particularly in your Member State. The authority responsible for Tacto is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.

4. Security Standards

We have implemented appropriate physical, technical, and administrative security measures to protect personal data against loss, misuse, alteration, or destruction. Service providers are contractually obligated to maintain confidentiality. All website visits are conducted via a secure TLS connection. Data transmission is TLS-encrypted. Tacto is ISO/IEC 27001 certified.

5. Changes to this Privacy Policy

This privacy policy may be updated from time to time to reflect legal requirements or changes to our services. Last updated: August 6, 2026.

B. Data Processing on the Tacto Website

1. Log Data / Log Files

Each time the website is accessed, the following data is automatically collected:

  • IP address of the requesting device
  • Date and time of access
  • Referrer URL (originating website)
  • Browser description and version
  • Operating system and screen resolution
  • File name and URL of the requested file
  • Access provider description
  • Time spent on site
  • Amount of data transferred
  • Access status

This data is stored in log files, generally not together with other personal data.

Legal basis: Art. 6(1) sentence 1 (f) GDPR

Purpose: Website delivery, optimization, functionality, and IT system security. No analysis for marketing purposes.

Retention period: Data is only processed as long as necessary for the collection purpose. For system security reasons, data may be retained until misuse, security, or disruption incidents are resolved.

2. Cookies, Pixels, and Similar Technologies

2.1 General

Cookies are small text files stored on end devices. Tracking pixels are invisible 1x1 pixel images for tracking events. Device and browser fingerprinting attempts to identify website visitors based on specific browser settings.

Legal bases:

  • Section 25(1) TDDDG – Consent
  • Section 25(2) no. 1 TDDDG – Message transmission
  • Section 25(2) no. 2 TDDDG – Strictly necessary services
  • Art. 6 GDPR – Processing of personal data

Technically required cookies cannot be disabled without compromising functionality. We only use cookies and comparable technologies for statistics, analytics and marketing purposes with your consent.

Google Consent Mode: We use Google's Consent Mode with the default setting “denied”. Without your consent, no marketing or statistics cookies are set and no identifiers are transmitted to Google; only cookieless, aggregated signals without personal reference may be transmitted.

2.2 Consent Management Platform – Usercentrics

We use the Usercentrics Consent Management Platform to obtain, document and manage your consent to the use of cookies and comparable technologies.

Processing company: Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany

Data processing purposes: Obtaining, storing and demonstrating consent, controlling cookies and services, compliance with legal obligations.

Technology used: Cookies, Local Storage, JavaScript

Data collected: Consent ID, consent status (opt-in/opt-out per service and category), date and time of consent, banner language, device information, browser information (user agent), shortened/anonymised IP address, URL of the page visited, settings ID.

Legal basis: Section 25(2) no. 2 TDDDG, Art. 6(1)(c) GDPR (obligation to demonstrate consent under Art. 7(1) GDPR). Processing location: European Union.

Retention period: Consent data is stored for as long as required to demonstrate consent.

Privacy policy: https://usercentrics.com/privacy-policy/

2.3 Objection/Revocation

You can withdraw any consent given at any time with effect for the future and adjust your selection — via the “Cookie Settings” link in the page footer or the privacy icon at the bottom left of every page. In addition, you can delete or disable cookies at any time via your browser settings. Completely disabling cookies may cause functional restrictions.

2.4 Third-Party Services

A. Google Ads

Advertising service for placing ads in Google Search, YouTube, and other websites. Data transmission occurs regardless of whether a Google user account exists. If an account exists, data may be linked. Cross-device tracking is possible.

Processing company: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, Ireland (EEA and Switzerland) / Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (outside EEA and Switzerland)

Data processing purposes: Display of relevant advertising, analytics, prevention of click fraud, creation of statistics. Technology used: Cookies.

Data collected: Viewed and displayed ads, cookie ID, date and time of visit, device information, geographic location, IP address, search terms, Publisher Provided Identifiers (PPID), Ad ID (within mobile applications), impressions, browser information (type, language).

Legal basis: Section 25(1) TDDDG, Art. 6(1)(a) GDPR. Processing location: European Union, United States, Singapore, Taiwan, Chile.

Retention period: IP address anonymized after 9 months. Cookie and personal identifiers anonymized or deleted after 18 months.

Data recipients: Alphabet Inc., Google LLC, Google Ireland Limited. Transfer to third countries: United States, Singapore, Taiwan, Chile. Google is certified under the EU-U.S. Data Privacy Framework.

Privacy policy: https://business.safety.google/adsprocessorterms/

B. Google Ads Conversion Tracking

Conversion tracking records what happens after a click on a Google Ads advertisement when users subsequently visit our website. It measures whether users perform certain actions after clicking an ad (e.g. contact requests).

Processing company: Google Ireland Limited / Google LLC (as above)

Data processing purposes: Measurement of advertising success (conversion tracking), analysis of advertising campaigns. Technology used: Cookies, tracking pixels, tracking code (tags and code snippets).

Data collected: Browser type, clicked advertising, cookie ID, browser language, user behavior (clicks, newsletter sign-ups, other actions), date and time of visit, IP address, web request, referrer URL.

Legal basis: Section 25(1) TDDDG, Art. 6(1)(a) GDPR. Processing location: European Union, United States, Singapore, Taiwan, Chile.

Privacy policy: https://business.safety.google/adscontrollerterms/

C. Google Ads Remarketing

With remarketing, users are targeted with interest-based advertising on other websites in the Google Display Network based on their interactions.

Processing company: Google Ireland Limited / Google LLC (as above)

Data processing purposes: Display of interest-based advertising in the Google Display Network, tracking of user behavior. Technology used: Cookies.

Data collected: Duration of visit, IP address, pages visited, content of interest, website usage, referrer URL, Ad ID (for mobile apps), date and time of visit, device information, browser information (type, language).

Legal basis: Section 25(1) TDDDG, Art. 6(1)(a) GDPR. Processing location: European Union, United States, Singapore, Taiwan, Chile.

Privacy policy: https://business.safety.google/adscontrollerterms/

D. Google Analytics 4

Web analytics service for measuring advertising ROI and analysing user behavior on websites and in applications. We only load Google Analytics after consent; without consent, no analytics cookies are set and no measurement data with personal reference is transmitted (Google Consent Mode, default “denied”).

Processing company: Google Ireland Limited / Google LLC (as above)

Data processing purposes: Analytics, reach measurement, marketing. Technology used: Cookies, tags (JavaScript code snippets), pixels.

Data collected: Click path, date and time of visit, hostname, browser language settings, browser type, screen resolution, additional browser information, device used, operating system, additional device information, visitor interactions, user behavior, URL of visited website, referrer URL, pages visited, shortened IP address, approximate location information (based on the shortened IP).

Legal basis: Section 25(1) TDDDG, Art. 6(1)(a) GDPR. Processing location: European Union, United States, Singapore, Taiwan, Chile.

Retention period: Depends on the type of stored data and customer settings; we use the shortest available default setting.

Opt-out: via the cookie settings (see 2.3) or https://tools.google.com/dlpage/gaoptout

Data recipients: Alphabet Inc., Google LLC, Google Ireland Limited. Transfer to third countries: United States, Singapore, Taiwan, Chile. Google is certified under the EU-U.S. Data Privacy Framework.

Privacy policy: https://business.safety.google/adsprocessorterms/

E. Google Fonts

Collection of fonts for commercial and personal use. Fonts are embedded locally, not via the Google API. No connection to Google servers is established and no data is processed by Google.

F. Google Tag Manager

Tag management system for centrally integrating tags via a user interface. Tags are small code sections used to integrate services. Google Tag Manager itself does not set marketing cookies; the services integrated via it are only triggered after your respective consent. According to Google, GTM itself does not process personal data.

Processing company: Google Ireland Limited / Google LLC (as above)

Data processing purposes: Tag management. Technology used: Tags. Data collected: Aggregated data on tag firing.

Legal basis: Section 25(2) TDDDG, Art. 6(1)(f) GDPR. Processing location: European Union, United States, Singapore, Taiwan, Chile.

Privacy policy: https://policies.google.com/privacy

G. Hotjar

Web analytics service for analysing user behavior (e.g. heatmaps, session recordings). Hotjar is only loaded after consent. Hotjar stores information in pseudonymized user profiles; input into form fields is automatically suppressed.

Processing company: Hotjar Limited, Dragonara Business Centre, 5th Floor, Dragonara Road, Paceville St Julian's STJ 3141, Malta. Hotjar processes as a data processor; a data processing agreement pursuant to Art. 28 GDPR has been concluded.

Data processing purposes: Analytics, feedback. Technology used: Cookies, scripts.

Data collected: Device type, unique device identifiers, device screen resolution, operating system, anonymized IP address, geographic location (country only), browser type, mouse movements, mouse position on website, clicks performed, keystrokes (automatically suppressed in input fields), date and time of access, pages visited, referrer URL, domain, unique user identifier (UUID), language information, user inputs in surveys.

Legal basis: Section 25(1) TDDDG, Art. 6(1)(a) GDPR. Processing location: Worldwide.

Retention period: Visit data usually retained for 365 days, then automatically deleted. Survey and feedback data may be retained longer.

Opt-out: via the cookie settings (see 2.3) or https://www.hotjar.com/legal/policies/do-not-track/

Data recipients: Hotjar Ltd., Amazon Web Services EMEA SARL, Datadog Inc., Functional Software, Inc. Transfer to third countries: United States.

Privacy policy: https://www.hotjar.com/legal/policies/privacy/

H. HubSpot

We use HubSpot as our CRM and marketing platform, including for contact and registration forms, e-mail communication and — only with your consent — for analysing user behavior on our website (website tracking). Without consent, no HubSpot tracking cookies are set and no tracking data is transmitted; the form functionality remains unaffected (see section B.3).

Processing company: HubSpot Ireland Ltd., 1 Sir John Rogerson's Quay, Dublin 2, Ireland / HubSpot Inc., 2 Canal Park, Cambridge, MA 02141, USA

Data processing purposes: Contact and lead management (CRM), provision of forms, e-mail marketing; after consent: reach analysis and tracking of user behavior. Technology used: Cookies, pixels, JavaScript.

Data collected: When using forms, the data you enter (e.g. name, business e-mail address, company, phone number, message); after consent additionally: pages visited, date and time of visit, duration of visit, referrer URL, IP address, device and browser information, cookie ID (hubspotutk).

Legal basis: Forms and CRM: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR; website tracking: Section 25(1) TDDDG, Art. 6(1)(a) GDPR. Processing location: European Union, United States.

Data recipients: HubSpot Inc. and subsidiaries. Transfer to third countries: United States. HubSpot is certified under the EU-U.S. Data Privacy Framework; in addition, a data processing agreement pursuant to Art. 28 GDPR has been concluded.

Privacy policy: https://legal.hubspot.com/privacy-policy

I. LinkedIn Insight Tag / LinkedIn Conversion Tracking

Service for conversion tracking and retargeting. The LinkedIn Insight Tag and conversion tracking are only loaded after your consent. They track user interactions after an ad click; retargeting enables personalized advertising on LinkedIn based on the data collected.

Processing company: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland

Data processing purposes: Marketing, analysis of marketing activities, retargeting of website visitors, conversion tracking, cross-device tracking, measurement of advertising campaign success. Technology used: Cookies, JavaScript code, pixels (event-specific).

Data collected: Device type, device ID, operating system, additional device information, browser type, installed browser add-ons, additional browser information, proxy server used, IP address (truncated or hashed for cross-device tracking), website URL, referrer URL, timestamp, user behavior on website, LinkedIn profile information (profile, employer, title, industry, country, job), LinkedIn usage data.

Legal basis: Section 25(1) TDDDG, Art. 6(1)(a) GDPR. Processing location: Worldwide.

Retention period: LinkedIn member identifiers removed within 7 days. Pseudonymized data deleted after 180 days.

Data recipients: LinkedIn Ireland, LinkedIn Singapore, Microsoft companies, additional LinkedIn subsidiaries. Transfer to third countries: United States, Singapore, China.

Privacy policy: https://www.linkedin.com/legal/privacy-policy

J. Microsoft Advertising (Bing Ads / UET Tag)

Advertising service by Microsoft for placing ads in Bing Search and the Microsoft advertising network. Universal Event Tracking (UET) is only loaded after your consent and measures which actions users perform on our website after clicking a Microsoft ad (conversion tracking); it also enables remarketing.

Processing company: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland / Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA

Data processing purposes: Conversion tracking, remarketing, measurement of advertising success. Technology used: Cookies (incl. MUID), tracking pixels, JavaScript (UET tag).

Data collected: Pages visited, ads clicked, date and time of visit, IP address, device and browser information, cookie ID, referrer URL, search terms, user behavior on the website.

Legal basis: Section 25(1) TDDDG, Art. 6(1)(a) GDPR. Processing location: European Union, United States.

Data recipients: Microsoft Corporation and subsidiaries. Transfer to third countries: United States. Microsoft is certified under the EU-U.S. Data Privacy Framework.

Privacy statement: https://privacy.microsoft.com/en-us/privacystatement

K. Snitcher

Service for identifying corporate visitors (B2B visitor identification). Snitcher assigns website visits to companies based on the IP address; no profiles of individual private persons are created. Snitcher only sets recognition cookies after your consent.

Processing company: Snitcher B.V., Weesperstraat 61-105, 1018 VN Amsterdam, Netherlands

Data processing purposes: Identification of corporate visitors, B2B marketing and sales, analysis of visit behavior at company level. Technology used: Cookies (after consent), JavaScript.

Data collected: IP address, company information derived from it (company name, industry, size), pages visited, date and time of visit, duration of visit, referrer URL, device and browser information, cookie ID (after consent).

Legal basis: Section 25(1) TDDDG, Art. 6(1)(a) GDPR. Processing location: European Union.

Retention period: In accordance with Snitcher's policies; a data processing agreement pursuant to Art. 28 GDPR has been concluded.

Privacy policy: https://www.snitcher.com/privacy-policy

L. Vimeo (Video Embedding with Do-Not-Track)

We embed videos via the provider Vimeo. All embeds consistently use the activated “Do Not Track” parameter (dnt=1). This means Vimeo does not set tracking cookies, does not create session profiles and does not use playback data for advertising purposes. When a video is played, your IP address is technically transmitted to Vimeo, as the video content is delivered from Vimeo servers.

Processing company: Vimeo.com Inc., 330 West 34th Street, 5th Floor, New York, NY 10001, USA

Data processing purposes: Provision and playback of video content. Technology used: iFrame embedding (with dnt=1), JavaScript player.

Data collected: IP address, date and time of retrieval, device and browser information, video content retrieved (technical playback data without advertising profiling).

Legal basis: Section 25(2) no. 2 TDDDG, Art. 6(1)(f) GDPR (legitimate interest in the functional display of our video content, without advertising tracking). Processing location: United States. Vimeo is certified under the EU-U.S. Data Privacy Framework.

Privacy policy: https://vimeo.com/privacy

3. Contact, Demo and Event Enquiries (Forms)

You can contact us via forms on our website (e.g. contact form, demo request, webinar and event registrations, content downloads). The forms are provided via HubSpot (see B.2.4 H).

Data processed: the data you provide in the respective form, e.g. name, business e-mail address, company, position, phone number and your message.

Purposes: Processing your enquiry, organising and conducting webinars/events, sending requested content, sales contact at your request.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures at your request), otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). Where you consent to receiving further marketing communication, the legal basis is Art. 6(1)(a) GDPR; you can withdraw this consent at any time (unsubscribe link in every e-mail or via datenschutz@tacto.ai).

Storage period: We store your enquiry data for as long as necessary for processing and beyond that only within the scope of statutory retention obligations or until you object.

4. Careers Page and Applications

Our careers page displays open positions managed via our applicant tracking system Ashby. The application process itself takes place on the Ashby platform (jobs.ashbyhq.com); supplementary privacy information for applicants applies there, which we provide during the application process.

Processing company: Ashby Inc., 49 Geary Street, Suite 411, San Francisco, CA 94108, USA (as processor)

Data processed: the data you provide in your application (e.g. name, contact details, CV, references, information on your professional career).

Legal basis: Art. 6(1)(b) GDPR in conjunction with Section 26 BDSG (decision on the establishment of an employment relationship).

Storage period: Application documents are deleted after completion of the application process, at the latest six months after rejection, unless you have consented to longer storage (talent pool).

Transfer to third countries: United States of America, on the basis of the EU Standard Contractual Clauses. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Ashby.