Gemploy
PricingAbout
HR toolsFree HR calculators & tools
DERequest a demo
PricingAboutHR toolsDE

Privacy Policy

Gemploy GmbH, as of 1 September 2026

This is a non-binding reading aid. The German version of this privacy policy is the only binding one. In case of any discrepancy, the German text prevails.

Are you an employee of a company that uses Gemploy?

Then your employer is the controller of your personnel data, not Gemploy. We process that data solely on their behalf and on their instructions.

Please address requests for access, rectification, erasure or restriction to your employer. We are not permitted to answer such requests ourselves; we forward them to your employer without undue delay.

What we additionally process within the application under our own responsibility is described in the Privacy Notice for the Application, which you will find in Gemploy after signing in.

This policy covers our website and our business contacts.

1 Controller

Gemploy GmbH
Borselstraße 3
22765 Hamburg, Germany

Commercial register: Amtsgericht Hamburg, HRB 194703
Managing directors: Frank Heindörfer, Philip Chinery

Email: [email protected]

No data protection officer has been appointed. For data protection enquiries, please use the address above.

2 Visiting our website

When you access gemploy.com, we process the connection data technically required to deliver the page: IP address, date and time of access, the page requested, the volume of data transferred, and information about your browser and operating system. The site cannot be delivered without this processing.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is providing and securing our website.

Retention: 30 days

We use no cookies, no analytics and no reach-measurement tools on this website. Fonts and other assets are served from our own servers. There is exactly one piece of third-party content: the spam protection on the contact form, which loads only once you select one of its fields (see section 3).

Hosting and delivery

Our website is delivered via Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare processes the connection data described above on our behalf and also operates the DNS resolution for our domains. This may involve a transfer to the United States.

Basis for the transfer: the European Commission’s Standard Contractual Clauses under Art. 46(2)(c) GDPR, agreed in the Cloudflare Data Processing Addendum. To the extent that Cloudflare, Inc. is certified under the EU-US Data Privacy Framework, the transfer is additionally based on the European Commission’s adequacy decision under Art. 45 GDPR.

Traffic of our application is not routed through Cloudflare.

3 Contact form and enquiries

If you contact us via the contact form or by email, we process the data you provide in order to handle your enquiry.

Legal basis: Art. 6(1)(b) GDPR where your enquiry concerns the conclusion or performance of a contract, otherwise Art. 6(1)(f) GDPR with our legitimate interest in responding to enquiries.

Retention: We delete the data once your enquiry has been dealt with conclusively, unless statutory retention obligations apply.

Spam protection on the contact form

The contact form is protected by Cloudflare Turnstile, a service of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. It distinguishes human input from automated input and so prevents the form being abused for bulk enquiries.

The code required for this is loaded from Cloudflare, and only at the moment you select one of the form’s fields. If you do not use the form, no connection to Cloudflare is made. Merely opening the page does not trigger it.

In doing so, Cloudflare processes your IP address, information about your browser and device, and your interaction with the form, in order to assess whether the request comes from a human. Turnstile may store and read information on your device for this purpose. That information serves abuse detection only, not advertising and not the analysis of your behaviour across websites.

When you submit the form, we transmit the verification token issued by Turnstile together with your IP address to Cloudflare to have it checked. We store neither the token nor your IP address; they are not part of the record created from your enquiry.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is preventing automated and abusive enquiries. For storing and reading information on your device we rely on § 25(2) no. 2 TDDDG: the spam protection is necessary for us to provide the form you deliberately opened.

Basis for the transfer: the same as described for Cloudflare in section 2.

Retention: No record is created on our side. How long Cloudflare retains the verification data is governed by Cloudflare’s own information.

4 Newsletter

To send our newsletter we process your email address and any further data you provide.

Subscription uses the double opt-in procedure: after you subscribe, we send you an email with a confirmation link. Only after you confirm do we add you to the distribution list. We log the subscription and the confirmation, including timestamps, in order to be able to demonstrate your consent.

Legal basis: Art. 6(1)(a) GDPR (consent). You may withdraw your consent at any time with effect for the future, for example via the unsubscribe link in every newsletter. The lawfulness of processing carried out before withdrawal remains unaffected.

Retention: Until withdrawal. Proof of consent is retained beyond that for as long as it is required to defend against claims.

Delivery uses a newsletter system we operate ourselves; for technical delivery we use the email service provider named in section 7.

5 Application sign-in page

When you open the sign-in page of our application, we process the same technically required connection data described in section 2, in order to deliver the page and to detect and prevent attacks against the sign-in.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the security of the sign-in process.

What happens after sign-in is described in the Privacy Notice for the Application.

6 Business contacts, customers and prospects

To initiate and perform contracts, we process the data of our customers’ and prospects’ contact persons, in particular name, role, business contact details, correspondence and billing data. For payment processing we use a payment service provider; the payment data involved is described in section 7.

Legal basis: Art. 6(1)(b) GDPR; for contact persons of a company, Art. 6(1)(f) GDPR with our legitimate interest in performing the business relationship; for retaining accounting records, Art. 6(1)(c) GDPR.

Retention: For the duration of the business relationship, thereafter in line with statutory retention periods of up to 8 years.

7 Recipients

We disclose personal data only where necessary. Recipients are:

Recipient Purpose Location
Cloudflare, Inc., USA Website delivery, DNS resolution, spam protection on the contact form USA (see section 2)
Hetzner Online GmbH, Germany Operation of our servers Germany; server configuration backups in Finland
IONOS Cloud GmbH, Germany Object storage Germany (Frankfurt am Main)
Lettermint B.V., Netherlands Email delivery Netherlands, France, Germany
JetBrains s.r.o., Czech Republic Ticketing system for fault reports European Union
Microsoft Deutschland GmbH, Germany Email, file storage and identity management Germany, with narrowly limited exceptions (see below)
Tax advisor Bookkeeping and accounting Germany
Stripe Payments Europe, Limited, Ireland Payment processing European Union, with transfers to the USA (see below)

These recipients act as our processors and are bound by our instructions. Beyond that, we disclose data to public authorities where we are legally obliged to do so.

Microsoft: enquiries, correspondence and job applications reach us by email and are handled there. The mailbox service region is Germany. For the narrowly limited cases in which Microsoft processes data outside the European Economic Area, the Standard Contractual Clauses in the Microsoft data protection addendum apply under Art. 46(2)(c) GDPR, supplemented by the EU-US Data Privacy Framework adequacy decision under Art. 45 GDPR.

Stripe: For payment processing we use Stripe Payments Europe, Limited, Ireland. Stripe processes payment and invoicing data partly on our behalf and partly as an independent controller, in particular for fraud prevention and to meet its own regulatory obligations. For transfers to its US parent company, the Standard Contractual Clauses under Art. 46(2)(c) GDPR apply, supplemented by the EU-US Data Privacy Framework adequacy decision under Art. 45 GDPR. The Stripe data protection addendum applies in its version of 18 November 2025.

8 Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR).

Right to object: You have the right to object at any time, on grounds relating to your particular situation, to processing of your data based on Art. 6(1)(f) GDPR (Art. 21 GDPR).

You may withdraw any consent you have given at any time with effect for the future.

You have the right to lodge a complaint with a supervisory authority. The authority competent for us is the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany.

9 No automated decision-making

No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.

10 Changes to this policy

We update this policy when the processing described here or the legal situation changes. The version published on this page applies; its date is stated above.

Gemploy

Next-generation people management

All systems operational
Product
  • Pricing
Resources
  • HR tools
Company
  • About
  • Contact
Legal
  • Imprint
  • Privacy
© 2026 Gemploy · Hamburg-Ottensen
Made with care in Hamburg