Privacy Policy
As of September 14, 2026
1. Introduction
In the following, we inform you about the processing of personal data when using:
-
our website
-
our social media profiles.
Personal data means all data that can be related to a specific natural person, e.g., your name or IP address.
1.1 Contact Details
The Controller pursuant to Art. 4 (7) of the EU General Data Protection Regulation (GDPR) is Tektit Consulting GmbH, Schönhauser Allee 45, Berlin, Germany, Email: contact@tektitconsulting.com. We are legally represented by Jacob Fahrenkrug, Timo Römer.
Our Data Protection Officer can be reached via heyData GmbH, Schützenstraße 5, 10117 Berlin, Email: datenschutz@heydata.eu.
1.2 Scope of Data Processing, Purposes of Processing and Legal Bases
We detail the scope of data processing, processing purposes, and legal bases below. In principle, the following legal bases for data processing are applicable:
-
Art. 6 (1) sentence 1 lit. a GDPR serves as the legal basis for processing operations for which we obtain consent.
-
Art. 6 (1) sentence 1 lit. b GDPR is the legal basis insofar as the processing of personal data is necessary for the performance of a contract, e.g., if a site visitor purchases a product from us or we perform a service for them. This legal basis also applies to processing operations required for pre-contractual measures, such as inquiries about our products or services.
-
Art. 6 (1) sentence 1 lit. c GDPR applies if we fulfill a legal obligation by processing personal data, as can be the case in tax law, for example.
-
Art. 6 (1) sentence 1 lit. f GDPR serves as the legal basis if we can rely on legitimate interests for the processing of personal data, e.g., for cookies required for the technical operation of our website.
1.3 Data Processing Outside the EEA
Insofar as we transfer data to service providers or other third parties outside the EEA, adequacy decisions of the EU Commission pursuant to Art. 45 (3) GDPR guarantee the security of the data during the transfer, provided these exist, as is the case for the UK, Canada, and Israel, for example.
When transferring data to service providers in the USA, the legal basis for the data transfer is an adequacy decision of the EU Commission if the service provider has additionally certified under the EU-U.S. Data Privacy Framework.
In other cases (e.g., if no adequacy decision exists), the legal basis for the data transfer is generally, unless we state otherwise, standard contractual clauses. These are a set of rules adopted by the EU Commission and are part of the contract with the respective third party. According to Art. 46 (2) lit. b GDPR, they ensure the security of the data transfer. Many providers have provided contractual guarantees that go beyond the standard contractual clauses to protect the data. These are, for example, guarantees regarding data encryption or a duty of the third party to notify data subjects if law enforcement agencies seek to access the data.
1.4 Storage Duration
Unless expressly stated in this privacy policy, the data stored by us will be deleted as soon as it is no longer required for its intended purpose and no statutory retention obligations prevent its deletion. If the data is not deleted because it is necessary for other and legally permissible purposes, its processing will be restricted, i.e., the data will be blocked and not processed for other purposes. This applies, for example, to data that we must retain for commercial or tax law reasons.
1.5 Rights of Data Subjects
Data subjects have the following rights against us with regard to personal data concerning them:
-
Right to information (access),
-
Right to rectification or erasure,
-
Right to restriction of processing,
-
Right to object to processing,
-
Right to data portability,
-
Right to withdraw consent granted at any time.
Data subjects also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of their personal data. Contact details of the data protection supervisory authorities can be found online through the Federal Commissioner for Data Protection and Freedom of Information.
1.6 Obligation to Provide Data
Customers, prospects, or third parties only need to provide us with the personal data necessary for establishing, executing, and terminating a business relationship or other relationship, or which we are legally required to collect, within the scope of a business relationship or other relationship. Without this data, we will generally have to refuse to conclude a contract or provide a service, or we will no longer be able to carry out an existing contract or other relationship.
Mandatory information is marked as such.
1.7 No Automated Individual Decision-Making
We generally do not use fully automated decision-making according to Article 22 GDPR to establish and carry out a business relationship or other relationship. Should we use these procedures in individual cases, we will inform you separately, provided this is required by law.
1.8 Contact
When contacting us, e.g., by email or telephone, the data communicated to us (e.g., names and email addresses) will be stored by us in order to answer questions. The legal basis for processing is our legitimate interest (Art. 6 (1) sentence 1 lit. f GDPR) in responding to inquiries addressed to us. We delete the data arising in this context once storage is no longer required, or we restrict processing if statutory retention obligations exist.
2. Data Processing on our Website
2.1 Notice for Website Visitors from Germany
Our website stores information in the terminal equipment of website visitors (e.g., cookies) or accesses information already stored in the terminal equipment (e.g., IP addresses). Details on what information this is can be found in the following sections.
This storage and access take place based on the following provisions:
-
Insofar as this storage or access is absolutely necessary so that we can provide the service of our website explicitly requested by website visitors (e.g., to operate a chatbot used by the website visitor or to ensure the IT security of our website), it takes place on the basis of Section 25 (2) No. 2 of the Telecommunications Digital Services Data Protection Act (TDDDG).
-
Otherwise, this storage or access takes place based on the consent of the website visitors (Section 25 (1) TDDDG).
Subsequent data processing occurs in accordance with the following sections and based on the provisions of the GDPR.
2.2 Informational Use of the Website
During the informational use of the website, i.e., if site visitors do not transmit information to us separately, we collect the personal data that the browser transmits to our server to ensure the stability and security of our website. This constitutes our legitimate interest, so the legal basis is Art. 6 (1) sentence 1 lit. f GDPR.
This data is:
-
IP address
-
Date and time of the request
-
Time zone difference to Greenwich Mean Time (GMT)
-
Content of the request (specific page)
-
Access status/HTTP status code
-
Amount of data transferred in each case
-
Website from which the request comes
-
Browser
-
Operating system and its interface
-
Language and version of the browser software.
This data is also stored in log files. It will be deleted when its storage is no longer required, at the latest after 14 days.
2.3 Web Hosting and Provision of the Website
Our website is hosted by Wix. The provider is Wix.com Ltd., 40 Namal Tel-Aviv St., Tel Aviv, Israel. The provider processes the personal data transmitted via the website (e.g., content, usage, meta/communication data, or contact data) depending on the function used, in the EU, the USA, and Israel. Further information can be found in the provider's privacy policy.
It is our legitimate interest to provide a website, so the legal basis for the described data processing is Art. 6 (1) sentence 1 lit. f GDPR.
Insofar as processing takes place in the EU, no separate legal basis for a third-country transfer is required.
Insofar as processing takes place in the USA or Israel, the legal basis for transferring to a country outside the EEA is an adequacy decision. The security of the data transferred to the respective third country is guaranteed because the EU Commission has determined within the framework of an adequacy decision pursuant to Art. 45 (3) GDPR that both the USA (for companies certified under the EU-U.S. Data Privacy Framework) and Israel offer an adequate level of protection.
2.4 Contact Form
When you contact us via the contact form on our website, we store the data requested there and the content of the message. The legal basis for processing is our legitimate interest in answering inquiries directed to us. Therefore, the legal basis for processing is Art. 6 (1) sentence 1 lit. f GDPR. We delete the data arising in this context once storage is no longer required, or restrict processing if statutory retention obligations exist.
2.5 Technically Necessary Cookies
Our website uses cookies. Cookies are small text files that are stored in the web browser on the terminal device of a site visitor. Cookies help to make the offer more user-friendly, effective, and secure. Insofar as these cookies are necessary for the operation of our website or its functions (hereinafter "Technically necessary cookies"), the legal basis for the associated data processing is Art. 6 (1) sentence 1 lit. f GDPR. We have a legitimate interest in providing customers and other site visitors with a functional website. Specifically, we set:
-
technically necessary cookies,
-
cookies that adopt language settings.
2.6 Third-Party Providers
For our self-assessment tool "AI Readiness Check", we use several services in combination: The inputs are processed via Make, a PDF report is generated via CustomJS and sent via Google Workspace, the contact data is stored in Copper CRM for follow-up, and a pseudonymized dataset for industry benchmarks is stored in Google Sheets. The individual processing steps are detailed below.
2.6.1 Make
We use Make for automation between applications. The provider is Celonis SE, Theresienstraße 6, 80333 Munich, Germany. The provider processes usage data (e.g., visited websites, interest in content, access times) and meta/communication data (e.g., device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6 (1) sentence 1 lit. f GDPR. We have a legitimate interest in easily connecting the applications in our company and thus optimizing operations.
The data is deleted when the purpose for its collection has ceased to exist and no retention obligation stands in the way. Further information is available in the provider's privacy policy.
2.6.2 Google Workspace
We use Google Workspace for collaboration at work, cloud storage, and drafting documents. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The provider processes usage data (e.g., visited websites, interest in content, access times), content data (e.g., inputs in online forms), meta/communication data (e.g., device information, IP addresses), and master data (e.g., names, addresses) in the USA.
The legal basis for the processing is Art. 6 (1) sentence 1 lit. f GDPR. We have a legitimate interest in working together, creating, and storing documents cost-effectively and efficiently.
The transfer of personal data to a country outside the EEA takes place on the legal basis of an adequacy decision. The security of the data transferred to the third country (i.e., a country outside the EEA) is guaranteed because the EU Commission has decided within the framework of an adequacy decision pursuant to Art. 45 (3) GDPR that the third country offers an adequate level of protection.
The data is deleted when the purpose for its collection has ceased to exist and no statutory retention obligations apply. Further information is available in the provider's privacy policy.
2.6.3 Google Sheets
As part of our "AI Self Check" and our "Maturity Check", we store all data collected during the runs in a Google Sheet in addition to the CRM entry. This includes technical details (such as score, role, industry profile, language, and date) and the technical identifier (submissionId) as well as your full contact details (such as email address, name, and company name) and proof of the consent you provided. Since direct identifiers are stored here, this fully constitutes personal data within the meaning of the GDPR.
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The provider processes the aforementioned data in the USA.
The legal basis for the processing is Art. 6 (1) sentence 1 lit. f GDPR. We have a legitimate interest in creating pseudonymized benchmark evaluations across industries and maturity levels without retaining more personal data than necessary on a permanent basis.
The transfer of personal data to a country outside the EEA takes place on the legal basis of an adequacy decision (Google is certified under the EU-U.S. Data Privacy Framework).
The data is deleted when the purpose for its collection has ceased to exist and no retention obligations stand in the way. Further information is available in the provider's privacy policy.
2.6.4 GitHub Pages
We use GitHub Pages to provide our self-assessment tools "AI Self Check" and "Maturity Check," which are operated under a separate subdomain and linked from our website. The provider is GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA (part of the Microsoft Corporation). The provider processes usage data (e.g., visited websites, access times) and meta/communication data (e.g., IP addresses, device information) in the USA.
The legal basis for the processing is Art. 6 (1) sentence 1 lit. f GDPR. We have a legitimate interest in providing our self-assessment tools "AI Self Check" and "Maturity Check" reliably and cost-effectively.
The transfer of personal data to a country outside the EEA takes place on the legal basis of an adequacy decision. The security of the data transferred to the third country (i.e., a country outside the EEA) is guaranteed because the EU Commission has decided within the framework of an adequacy decision pursuant to Art. 45 (3) GDPR that the third country offers an adequate level of protection, and GitHub, Inc. is independently certified under the EU-U.S. Data Privacy Framework.
The data is deleted when the purpose for its collection has ceased to exist and no statutory retention obligations apply. Further information is available in the provider's privacy policy.
2.6.5 Copper CRM
We use Copper CRM to manage customer and prospect relationships. The provider is Copper CRM, Inc., 101 Mission Street, San Francisco, CA 94105, USA. The provider processes master data (e.g., names, addresses), contact data (e.g., email addresses, phone numbers), and content data (e.g., communication history) in the USA.
The legal basis for the processing is Art. 6 (1) sentence 1 lit. f GDPR. We have a legitimate interest in efficiently managing our customer and prospect relationships.
The transfer of personal data to a country outside the EEA takes place on the legal basis of an adequacy decision. The security of the data transferred to the third country (i.e., a country outside the EEA) is guaranteed because the EU Commission has decided within the framework of an adequacy decision pursuant to Art. 45 (3) GDPR that the third country offers an adequate level of protection, and Copper CRM, Inc. is certified under the EU-U.S. Data Privacy Framework.
The data is deleted when the purpose for its collection has ceased to exist and no statutory retention obligations apply. Further information is available in the provider's privacy policy.
2.6.6 CustomJS
We use CustomJS to execute automation and data processing steps via custom JavaScript code that are required in conjunction with our other website and automation tools (e.g., Make), such as for generating documents or processing data received via the website. The provider is TechnologyCircle GmbH, Karolinenstraße 24, Haus 4, 20357 Hamburg, Germany. The provider processes content data (e.g., form or automation data submitted for processing), usage data, and meta/communication data (e.g., IP addresses, timestamps) in Germany/the EU.
The legal basis for the processing is Art. 6 (1) sentence 1 lit. f GDPR. We have a legitimate interest in implementing automations and data processing steps on our website efficiently and reliably. Since the provider is based in Germany and processes data there, to our current knowledge, no third-country transfer takes place.
The data is deleted when the purpose for its collection has ceased to exist and no statutory retention obligations apply. Further information is available in the provider's privacy policy.
2.6.7 heyData
We have integrated a data protection seal on our website. The provider is heyData GmbH, Schützenstraße 5, 10117 Berlin, Germany. The provider processes meta/communication data (e.g., IP addresses) in the EU.
The legal basis for the processing is Art. 6 (1) sentence 1 lit. f GDPR. We have a legitimate interest in providing website visitors with confirmation of our data protection compliance. At the same time, the provider has a legitimate interest in ensuring that only customers with existing contracts use their seals, which is why a mere image copy of the certificate is not a viable alternative for confirmation.
The data is masked after collection so that there is no longer any personal reference. Further information is available in the provider's privacy policy.
3. Data Processing on Social Media Platforms
We are represented in social media networks to present our organization and our services there. The operators of these networks regularly process their users' data for advertising purposes. Among other things, they create user profiles based on online behavior, which are used, for example, to display advertising that corresponds to the users' interests on the network's pages and elsewhere on the Internet. For this purpose, the operators of the networks store information about user behavior in cookies on the users' computers.
It cannot be ruled out that the operators combine this information with other data. Users can find further information and instructions on how to object to processing by the site operators in the privacy policies of the respective operators. It may also be that the operators or their servers are located in non-EU countries, so they process data there. This may result in risks for users, e.g., because enforcing their rights may be more difficult or government agencies may access the data.
If users of the networks contact us via our profiles, we process the data communicated to us in order to respond to the inquiries. This constitutes our legitimate interest, so the legal basis is Art. 6 (1) sentence 1 lit. f GDPR.
3.1 LinkedIn
We maintain a profile on LinkedIn. The operator is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. An option to object to data processing is available via the advertising settings on their platform.
4. Changes to this Privacy Policy
We reserve the right to amend this privacy policy with future effect. A current version is always available here.
5. Questions and Comments
For questions or comments regarding this privacy policy, we are happy to assist you via the contact details provided above.
