Data Privacy

The protection of your personal data is a top priority for us. Our Data Protection Terms (Website) informs you about the type, extent and purpose of the collection, processing and use of your personal data on our website. You can also review or download our Terms and Conditions of (Commissioned) Data Processing, our IT Security Guideline and our List of Subcontractual Processors.

Notice to our customers

From May 25, 2018, the EU-wide General Data Protection Regulation (GDPR) becomes binding.

If through using our services (hosting, software as a service, consulting, maintenance and support) you, as our customer within the scope of the GDPR, transmit personal data to LucaNet or make such data accessible to LucaNet, it is required by law that processing by LucaNet occurs solely on the basis of a contract or other legal instrument.

Unless we have already reached a written agreement with you with regard to data processing, or you have reached another agreement with us, our privacy conditions (for commissioned data processing) supplementary to existing contracts between yourself and LucaNet for the use of our services come into effect from May 25, 2018.

In particular, these Conditions define our obligations so that you can continue to employ LucaNet as a contractor (“processor”, within the meaning of EU GDPR), even after the new data protection regulation comes into effect.

If you are not in agreement with our terms and conditions, or should you have any questions, please get in touch with us at:

Data Protection Terms (Website)

The website at (hereinafter: “Website”) is operated by LucaNet AG, Alexanderplatz 1, 10178 Berlin, Germany (“LucaNet” or “We”) on behalf of LucaNet (UK) Limited, a subsidiary of LucaNet AG. Protecting your personal data is extremely important to us. This privacy policy sets out the method, extent, and purpose of our collection, processing, and use of your personal data.


1 Basic Principles

We collect, process, and use your personal data in compliance with the applicable data protection regulations.

Personal data include any information that relates to an identified or identifiable natural person. This includes, for example, your name, your address, your e-mail address and your telephone number.

Within the meaning of the applicable provisions of data protection law, the data controller for collection, processing, use, access, revocation, and deletion in connection with your personal data is:

LucaNet AG
Alexanderplatz 1
10178 Berlin
Phone: +49 30 469910-0
Fax: +49 30 469910-29


2 Scope of Data Collection, Processing, and Use

When you access our web pages, LucaNet receives access data that is stored for security purposes and generally enables identification. This includes the names of the web pages accessed, the date and time of access, the volume of data transferred, notification of successful retrieval, the browser type and version, the user‘s operating system, the referrer URL (the previous page visited), and the requesting provider. LucaNet assesses these data (known as the click path), which enables us to optimize our Internet presence and better personalize our content.

It is not necessary for you to provide us with any personal data, such as your name or your e-mail address, just to visit our Website.

If you provide us with personal data, we collect, process, and use this information only for the purposes of providing our Website and the services offered on it. In addition, we collect, process, and use your personal data only if you have explicitly given your consent for us to do so.


3 Transfer of Personal Data to Third Parties

In the context of your use of our Website, your personal data will be transferred to third parties only within the scope defined in this privacy policy.

Any transfer of personal data beyond that scope will be considered only if there exists the legal authority to do so or such transfer is necessary for the enforcement of LucaNet’s rights, particularly for the enforcement of its claims resulting from the contractual relationship.


4 Contact Forms

You can use the contact forms provided on our Website to contact us directly or to request current information from us. We collect, process, and use the information you provide by means of a contact form for the exclusive purpose of processing your request.

Users’ details are stored in our marketing automation software Act-On from Act-On Software Inc., 121 SW Morrison St, #1600, Portland, Oregon 97204, USA (hereinafter “Act-On”). For this purpose, we have concluded a commissioned data processing contract with Act-On, in accordance with the applicable data protection regulations.

For more information on data protection at Act-On, see Act-On’s privacy policy at:

In addition, Act-On is also certified under the Privacy Shield agreement and thereby meets European data protection standards.

Information about the EU-U.S. Privacy Shield Framework from Act-On:


5 Newsletters

If you register for one of our newsletters, we collect, process, and use the information you enter to send the newsletter in question. By registering, you consent to receiving the newsletter and to the process described in the following.

Our newsletter registration process comprises a double-opt-in procedure. After registration, you will receive an e-mail requesting that you confirm your registration. Newsletter registrations are logged so that proof of the registration process is retained. For this purpose, the time of registration, time of confirmation, and IP address are stored.

However, you have the option to revoke your consent at any time for sending the newsletter by terminating the relevant newsletter subscription. You can revoke your consent by sending an e-mail, postal letter, personally delivered letter, or fax to LucaNet (see the data controller details above). You can unsubscribe from any newsletter using the link provided at its end.

The use of e-mail marketing service providers, the collection of statistics and their analysis, and the logging of the log-in process is made on the basis of our legitimate interests in accordance with Article 6(1)(f) of the GDPR. Our aim is to provide a user-friendly and secure newsletter system that serves our business interests and meets the expectations of users.

Newsletters are sent by us using the marketing automation software Act-On from Act-On. For details on the collection of statistics and their analysis, and for the purpose of the data processing involved, see Section 15 of this document.


6 Observance of Do Not Track

We observe the Do Not Track feature in your browser. If Do Not Track is activated, tracking by third parties will be deactivated and web fonts from external resources will not be embedded.

Please note that turning off cookies completely may cause malfunctions when using our Website and may also not reliably prevent the transfer of data to Google Analytics. We therefore advise using your browser’s Do Not Track (DNT) option. DNT is either a button in your program settings, or a module that needs to be additionally installed (‘add-on’ or ‘plug-in’). If this option is activated, your browser will indicate to our web server that you do not want tracking measures without your explicit consent. As a result, all of our tracking functions will be deactivated automatically on the server side. This also means that our Website will be delivered free of code for Google Analytics. This guarantees the best possible data protection without you needing to take further measures in relation to our Website.


7 Cookies

We use cookies on our Website in order (for example) to provide you with certain functions, display content in more attractive ways, and make ongoing improvements to the site. Cookies are small text files that are stored in your browser’s cache and enable us to recognize your browser for a certain length of time. It is possible to use our Website without cookies. However, this may lead to certain restrictions in the function and user-friendliness of our Website.

7.1 Types of Cookies

The following types of cookies may be used on our Website:

Required cookies: These cookies are necessary and are always used to make it easy for you to navigate our Website and make use of its special functions (when accessing password-protected areas, for example). Without these cookies, we are unable to provide you with certain services when requested. We also use necessary cookies to uniquely identify and log attempts to access our Website, which helps safeguard our ability to provide our services.

Tracking cookies: The use of these cookies is optional and requires your prior consent. Providing your consent essentially enables us to present external content relevant to you (such as videos, maps, and job advertisements) in more attractive ways on our Website, make ongoing improvements to the site using anonymized usage data and analyses, and display relevant advertisements and other content on our partners’ websites based on pseudonymized information.

7.2 Consent to the Use of Tracking Cookies

We will use tracking cookies only if you have actively consented to their use. When visiting our Website, active consent can be granted by either clicking “I Agree” in the cookie notice that appears, or by adjusting the Website’s cookie settings accordingly (via the link in the footer) and then saving them. This agreement is logged and results in the storage of a corresponding cookie.

7.3 Opt-out on the Website (in Browser Settings)

You can revoke your consent to our Website's use of tracking cookies at any time. To do so, click the “Cookie Settings” link on the Website’s footer, choose “Do not allow tracking cookies” in the window that opens, and save your selection by clicking “Save and close”. You can also limit or deactivate the use of cookies in your browser's settings whenever you wish.

The following sections provide further details on the cookies used in specific cases and the respective ways to opt out.


8 Google Analytics

This Website uses Google Analytics, a web analysis service by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter “Google”).

Google Analytics uses cookies, which are text files placed on your computer, to help analyze how users use the Website. The information generated by the cookies about your use of this Website are generally transmitted to and stored on Google servers in the United States. If IP anonymization is activated on this Website, however, Google first truncates and thereby anonymizes your IP address if you are located in a Member State of the European Union or other state that is party to the Agreement on the European Economic Area. Only in exceptional cases will the complete IP address be sent to a Google server in the United States and truncated there. Google uses this information on behalf of the operator of this Website for the purpose of evaluating your use of the Website, compiling reports on Website activity, and providing other services relating to website activity and Internet usage to the Website operator. Google may also transfer this information to third parties where required by law or where this data is processed by third parties on behalf of Google. Google has reported that it does not associate your IP address with any other data it holds. You may prevent the storage of cookies by making the appropriate settings in your browser; however, please note that this may prevent you from using the full functionality of this Website. Further, you can prevent Google’s collection of data created by cookies and data related to your use of the Website (including your IP address) and Google’s processing of this data by downloading and installing the browser plug-in available at

For more information on the terms and conditions of use and on data protection, visit or Please note that on this Website, Google Analytics is supplemented by the code gat._anonymizeIp(); to ensure that IP addresses are collected in anonymized form (IP masking).

We also use Google Analytics for analyzing data from AdWords and the DoubleClick cookie for statistical purposes. If you wish, you can deactivate this using the Ad Preferences Manager at


9 Google Remarketing

Our Website uses remarketing, a service of Google. With Google’s remarketing, advertisements can be displayed to users who have already visited our Website in the past. Google's remarketing uses cookies for analytical purposes. This enables us to recognize our Website's visitors when they visit websites within the Google advertising network. As a result, advertisements can be displayed within Google’s advertising network based on content that the visitor has accessed on other websites in said network. Google has reported that it does not collect personal data during this process. You can deactivate this function by visiting and choosing the appropriate settings.


10 Google Ads

We use Google’s advertising tool Google Ads to promote our Website. In this context, we use Google’s conversion tracking analysis service on our Website. If you access our Website by clicking on a Google advertisement, a cookie is stored on your computer. These cookies, known as conversion cookies, expire after 30 days and do not serve to identify you. If you access certain pages on our Website and the cookie has not yet expired, we and Google can recognize that you, the user, have clicked on an advertisement that we placed with Google and were forwarded to our Website.

The information obtained using conversion cookies allow Google to generate visitor statistics for our Website. These statistics tell us the total number of users who have clicked on our advertisements and also which pages on our Website were then accessed by which user. Neither we nor other Google AdWords advertisers receive information with which users can be personally identified.

You can prevent conversion cookies from being set by making the appropriate settings in your browser, for example by deactivating the automatic saving of all cookies, or just cookies from the domain

Google’s data protection notice for this is located at


11 Google Tag Manager

Our Website makes use of Google Tag Manager, which is a solution from Google Inc. that enables companies to manage website tags through an interface. Google Tag Manager is a cookie-free domain that does not collect any personal data. We expressly point out here that Google Tag Manager does, however, trigger other tags that may collect information. Google Tag Manager does not access this information. If a given user has opted for deactivation at the domain or cookie level, this will apply to all tracking tags implemented using Google Tag Manager.


12 Lead Forensics

We use Lead Forensics' data processing tool on our website. The Lead Forensics product is a market leading B2B sales and marketing enablement tool. It is SaaS (Software as a Service) and provides businesses with insight relating to their website visitors.

Lead Forensics works on the basis of reverse business IP tracking. A small tracking code is placed on our website which then enables them to identify the business IP addresses of the website visitors. Lead Forensics matches the identified business IP address to a wholly owned global database of businesses and business information.

The Lead Forensics software is almost entirely focused on leveraging business-related information to effectively match a business IP address with wider business data to provide valuable business-related visitor information to our customers.

Lead Forensics does not identify any personal IP addresses, mobile devices or any other data than that associated with the business. Business related data is not applicable under GDPR - which has the intention of protecting personal data. In relation to the software it provides, it is a Data Processor, not a Data Controller. In addition to information about the business, Lead Forensics provides information about the date and duration of the user’s visit, and the web pages which the user visits. Lead Forensics does not provide information on specific, identifiable individuals visiting a website; nor does it use cookies to identify and track visitors. Information is not provided about visitors that use dynamic IP addresses.

The information obtained using Lead Forensics allows us to generate visitor statistics and behaviour on our Website. These statistics tell us the total number of business users who have interacted with our content and also which pages on our website were then accessed by which place of business. Neither we nor Lead Forensics control data, it is only used for processing information with which users can be identified.


13 YouTube (Privacy-Enhanced Mode)

We use services from YouTube LLC, 901 Cherry Ave, San Bruno, CA 94066, USA (hereinafter “YouTube”) to embed videos. YouTube is a Google company. YouTube uses cookies to collect data on the visitors to its website. When you access sections of our Website that include embedded YouTube videos, we first check whether you have consented to the use of tracking cookies on our website. If you have, your visit to our site will establish a connection to Google's DoubleClick network and data will be transferred. Otherwise, an alternative image will be displayed in place of the video thumbnail in question along with information on how you can activate the cookies necessary to watch the video.

If you play the video, additional data processing processes may be started. We have no influence on this. For more information on data protection at YouTube, see YouTube’s privacy policy at


14 Vimeo

For the integration of videos on our website, we use plug-ins from the video portal Vimeo. The provider is Vimeo, Inc., with headquarters at 555 West 18th Street, New York, New York 10011, USA. If you visit one of our web pages that has one or more Vimeo videos embedded in it, a direct connection is established between your browser and Vimeo's servers. The particular web pages you have visited are thereby transmitted to the Vimeo server. Your IP address will also be stored.

If you interact with the embedded Vimeo plug-in (e.g. by playing the video by clicking the start button), this information is also transmitted to Vimeo and stored in the USA. If you have a Vimeo user account and are logged onto Vimeo while visiting our site, Vimeo will assign this information to your personal user account. You can prevent such assignment by logging out of your Vimeo user account before using our website and deleting the corresponding cookies from Vimeo.

Further information on data processing and data privacy by Vimeo can be found at

Moreover, Vimeo is certified according to the Privacy Shield Framework and thus complies with the European level of data protection:


15 Webinars

When you register for a webinar, the following information is required to aid the registration process:

  • First name, last name
  • E-mail address
  • Street name and number, town, and postal code
  • Phone number
  • Company

To provide webinars, we use the GotoWebinar service by Citrix, Citrix Headquarters, 4988 Great America Parkway, Santa Clara, CA 95054, USA (hereinafter “Citrix”). Citrix is the data controller for the provision of this service and the associated data processing performed by Citrix. Citrix’s privacy policy is located at

To provide each webinar, we transfer e-mail address, first name, and last name to Citrix. Aggregated statistical data are provided to LucaNet when the webinar is complete. If you ask a question during a webinar, we also receive information on the question asked such as first name, last name, and e-mail address to further process your inquiry when the webinar is complete. LucaNet is the data controller for data stored at and by LucaNet in the course of this process.

If you register to take part in a webinar, you will receive additional information and reminders about the event by e-mail before and after the event.


16 Act-On

The LucaNet Website and the LucaNet newsletter contain what is known as a ‘web beacon’, i.e. a pixel-sized file that is retrieved from the server of the software vendor Act-On upon visiting the LucaNet Website or when opening the LucaNet newsletter. During this retrieval, technical information such as information about your browser and your system is initially collected, in addition to your IP address and the time of the retrieval. This information is used to improve the technical performance of our services. The statistics collected also include the following details: the time our Website was visited and what links were clicked; whether our newsletters were opened and when; and what links contained in the newsletter were clicked. These details may be attributed to the individual Website visitors. The analyses assist us to identify the reading habits of our users and to adapt our content accordingly, or to send differing content in accordance with our users’ interests.

To statistically evaluate visits to the Website, information relating to marketing purposes and to identify companies is collected, processed, and stored in Germany in the data center of Act-On Software, Inc., using the Act-On tool. Act-On identifies the IP addresses of company networks on the basis of this data.

In addition, Act-On collects information about Internet usage behavior for those individuals who have submitted a form or who have registered for an e-mail service. The following information is collected: pages visited at, newsletters that are opened, LucaNet documents that are downloaded, forms that are submitted. This information is stored for as long as the individual’s data are processed in accordance with the stated purposes. We use this information to continually improve our services and to optimize the user experience on our Website.


17 Oktopost

We use a service from Oktopost Technologies Inc., Tuval Street 34, Tel Aviv, Israel (hereinafter “Oktopost”) for publishing social media posts and analyzing reach and interaction with them. Oktopost collects details on whether a post of ours has been shared, liked, commented on, or mentioned. Oktopost will evaluate this information for us to generate anonymous reports about the reach and usage of our posts. If Oktopost also processes data in the USA, suitable measures are taken to ensure the observance of European data protection standards. The data are stored in pseudonymized form and are anonymized after 24 months. You can object to the collection of your data by Oktopost by configuring your browser in such a way that it blocks the acceptance of cookies from third parties.

For more information on data protection at Oktopost, see:

You can deactivate link tracking by opting out at the following link:


18 LinkedIn

We use the LinkedIn Insight Tag and the retargeting function from LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland (hereinafter “LinkedIn”). By using the retargeting technology, users of the LucaNet Website can be shown personalized advertisements on LinkedIn. Furthermore, the LinkedIn Insight Tag makes it possible to generate anonymous reports on the performance of advertisements, in addition to information about interaction with websites. The LinkedIn Insight Tag is embedded in our Website and generates a unique LinkedIn browser cookie on the visitor’s browser. It enables the following data to be collected: Metadata (such as IP address, time stamp, page-related events such as page views) and demographic information from the user’s LinkedIn profile. Data is collected as soon as a user visits the LucaNet Website with an embedded member cookie from The data collected is encrypted and anonymized within seven days, with the anonymized data being deleted within 90 days. LinkedIn does not share any personal data with the Website owner, but provides only summarized reports about the target group for the Website and advertising performance.

You can prevent the storage of cookies using a browser setting. You can deactivate the LinkedIn Insight Tag and the retargeting function by opting out at the following link: If you are a LinkedIn member, you should click on “Opt Out on LinkedIn”. Other visitors should click on “Opt Out”.

For more information on data protection at LinkedIn, see:


19 Hotjar

We use Hotjar, a service of Hotjar Ltd, Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta (hereinafter “Hotjar”) to understand the needs of our users better and to optimize the offering on our Website. By using the technology from Hotjar, we gain a better understanding of the behavior of our users (e.g. how much time users spend on which pages, what links they click, what they like and dislike etc.). This information helps us to adapt our offering based on the feedback from our users. Hotjar uses cookies and other technologies to collect information about the behavior of our users and their devices (in particular, the IP device of the device (collected and stored in anonymized form only), screen size, type of device (Unique Device Identifiers), information about the browser used, location (country only), preferred language for using our Website). Hotjar stores this information in a pseudonymized user profile. The information is used neither by Hotjar, nor by us to identify individual users; nor is said information associated with other data about individual users. For more information, see Hotjar’s privacy policy at:

You may object to the storage of a user profile and the storage of information about your visit to our Website by Hotjar, in addition to the setting of Hotjar tracking cookies on other websites. Please use the following link to do so:


20 Questions About Data Protection

We will be happy to answer any further questions you have on data protection and the processing of your personal data. Please direct these inquiries to


21 Rights of Data Subjects


21.1 Rights of Withdrawal and Objection

Independent of the information provided above, you can object to the use of your data and revoke any related consent you have granted at any time (right of revocation pursuant to Art. 7, para. 3 of GDPR).

If you revoke your consent to having your data processed or object to how your data is being used, this will not affect the legality of any data processing that has taken place up to that point (right of objection pursuant to Art. 21 of GDPR).

21.2 Rights to Rectification, Erasure, Blocking, and Restriction

In addition, you can have the data that is collected and stored by LucaNet corrected, blocked, or deleted at any time. Here, we wish to make it clear that in some situations, our legal obligations may require us to continue storing your data; in such cases, the data in question will only be blocked (right to rectification pursuant to Art. 16, right to be forgotten pursuant to Art. 17, and right to restriction of processing pursuant to Art. 18 of GDPR).

21.3 Right of Data Portability, Right to Lodge a Complaint with a Supervisory Authority

As of May 25, 2018, you will have the right to data portability (pursuant to Art. 20 of GDPR) and the right to lodge a complaint with the supervisory authority responsible (pursuant to Art. 77 of GDPR).

21.4 Right to Data Access

You are entitled to know which of your personal data we have stored (right of data access pursuant to Art. 15 of GDPR).


22 Contact Person for Data Protection

For questions on the collection, processing, or use of personal data; for requests for information; or for corrections, erasure, or blocking of data and the revocation of consent granted, data subjects you can contact LucaNet AG’s external data protection officer

Mr. Roman Maczkowsky
GnuPG key ID: 0xD9EB7CC11197D778
m-privacy GmbH
Werner-Voß-Damm 62
12101 Berlin
Phone: +49 30 469910-0