Diese Website verwendet technisch notwendige Cookies. / This website uses technically necessary cookies.

GS Media

Privacy Policy

Information about the processing of personal data on our website, in contact and appointment processes, when using digital AI assistants, and in the customer portal, for orders, licences and support.

Transparency notice: The following sections apply to the extent that the relevant function is actually enabled or used on gs-media.eu or in a GS Media customer process. For new services, this Privacy Policy will be updated before productive use.

1. Controller

The controller responsible for data processing is:

GS Media
Owner: Guido Schulten
Wrangelstraße 3
40470 Düsseldorf
Germany
Telephone: +49 176 644 36 907
Email: gs@gs-media.eu

2. Principles and legal bases

We process personal data in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and, where access to terminal equipment or comparable technologies is concerned, the German TDDDG.

Depending on the process, we base processing in particular on Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract and pre-contractual measures), Art. 6(1)(c) GDPR (legal obligations) and Art. 6(1)(f) GDPR (legitimate interests, in particular secure, efficient and traceable business operations).

We observe the principles of data minimisation, purpose limitation, storage limitation and confidentiality. As a rule, special categories of personal data under Art. 9 GDPR should not be submitted to us via publicly accessible contact or AI functions unless this is expressly required and separately provided for.

3. Hosting, server log files and system security

The website is operated by an external hosting provider. In particular, the IP address, timestamp, requested URL, referrer, browser and device information, operating system, status codes and technical error data may be processed.

The processing serves technical provision, stability, error analysis, abuse detection and IT security. The legal basis is Art. 6(1)(f) GDPR.

Hosting provider: Namecheap, Inc. and/or the Namecheap services used for the hosting contract.

In addition, automated security and integrity checks may be used to detect unauthorised access, manipulation, malicious code, spam or unusual system activity.

4. Contact and forms

If you contact us by email, telephone or contact form, we process the data you provide in order to handle your enquiry. This may include your name, email address, telephone number, company, website, project information, requested services, message text and technical form and source data.

The legal basis is Art. 6(1)(b) GDPR where the enquiry relates to initiating or performing a contract; otherwise Art. 6(1)(f) GDPR.

For forms, the IP address, timestamp, user agent, source page, referrer, security status and transmitted URL parameters may also be processed in order to correctly assign the enquiry and prevent abuse.

5. Appointments and calendars

If you arrange an appointment via our website, a digital assistant or personal contact, we process the data required for scheduling. This includes in particular your name, contact details, requested appointment time, time zone, purpose of the meeting, responsible contact person and, where applicable, project-related notes.

The legal basis is Art. 6(1)(b) GDPR where the appointment serves to initiate or perform a contract; otherwise Art. 6(1)(f) GDPR.

Where an external calendar service, such as Google Calendar, is integrated, the information required for the appointment may be transferred to the respective calendar provider. For Google services, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, is generally the contact for users in the European Economic Area.

6. Digital assistants, AI assistants and automated communication

GS Media may use digital assistants or AI assistants on the website and in customer processes, for example for initial consultation, needs assessment, appointment scheduling, routing to the responsible contact person, answering technical questions and supporting service processes.

This may involve processing chat messages, contact or project data entered by you, conversation context, timestamps, session identifiers, technical metadata and – where initiated by you – handover information to staff, calendar, support or customer systems.

Depending on the context, processing is based on Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR. Where a function requires consent, processing is based on Art. 6(1)(a) GDPR.

To generate responses, external AI infrastructure or model providers may be used as processors or technical service providers depending on the selected model and technical configuration. Only the content required for the respective processing is transmitted. The specific providers used may vary depending on the model, product or availability.

Our AI assistants do not make solely automated decisions with legal or similarly significant effects within the meaning of Art. 22 GDPR. Contracts, approvals or other binding decisions are not made solely on the basis of AI output.

7. Quality learning, anonymisation and deletion of AI dialogue data

We may analyse dialogues and usage patterns to improve our digital assistants, analyse errors and optimise dialogue states and knowledge processes.

As a rule, raw website-chat dialogues that can be linked to an individual are deleted or irreversibly anonymised no later than seven days after the dialogue has ended, unless they remain necessary due to an appointment, contract initiation, order, support request, security check or legal obligation initiated by you.

If a conversation is transferred into a regular customer, appointment, contract or support process, the applicable retention periods for that process apply to the required data.

For longer-term learning, quality and statistical purposes, we use only data that has previously been anonymised or aggregated in such a way that a link to an individual can no longer reasonably be established. Pseudonymised data continues to be personal data and is therefore not treated as equivalent to anonymised data.

The anonymised quality data may be used in particular to identify typical questions, error classes, successful handovers, dialogue paths and knowledge gaps. It is not used to create personal user profiles.

8. Customer account, customer portal and login

If you use a customer account or customer portal, we process master and account data such as name, email address, user identifier, password hash, roles and permissions, login times, security information, language settings, account status and, where applicable, company and billing data.

The customer portal may additionally display or store messages, quotations, orders, purchases, downloads, support cases, licence information and other customer-related processes.

The legal basis is Art. 6(1)(b) GDPR and, for security and abuse prevention, Art. 6(1)(f) GDPR.

Where social login is enabled, login via external identity providers such as Google, Apple or Meta/Facebook may be offered. We typically receive a provider identifier and – depending on your authorisation – your name and email address. The privacy terms of the respective identity provider also apply to the login.

9. Orders, contracts and customer data

If you order services, digital products, modules, subscriptions, licences or other offers from GS Media, we process the data required for the order, contract processing and customer support.

This may include in particular:

  • name, company and contact person
  • billing address and – where required – delivery or service address
  • email address and telephone number
  • customer, order, quotation and contract numbers
  • ordered products, services, modules, editions, bundles or subscriptions
  • prices, discounts, tax information and currency
  • payment method, payment status, transaction references and refunds
  • contract term, cancellation, renewal and service status
  • communication relating to orders, contracts and support

The legal basis is Art. 6(1)(b) GDPR. Processing required under tax and commercial law is additionally based on Art. 6(1)(c) GDPR.

10. Licensing, entitlements and abuse prevention

For digital products and enabled functions, we may process licence, permission and entitlement data. This includes product identifiers, licence type, activation status, term, enabled functions, user or customer reference, device or installation identifier, domain or system assignment and technical verification and status data.

The processing serves to provide the purchased service, verify licences, restore authorised access and prevent licence abuse. The legal basis is Art. 6(1)(b) GDPR; for abuse and security checks, additionally Art. 6(1)(f) GDPR.

For permanently acquired usage rights, the minimum data required to restore the entitlement at a later date may be stored for as long as the usage right exists or legal or contractual evidence requirements make this necessary.

11. Payment processing

Depending on the payment method offered and selected by you, payment processing may be carried out by external payment service providers. The specific provider is shown during the respective checkout or payment process.

The payment service provider processes the data required for payment under its own responsibility or as a processor. GS Media generally receives only the information required for contract processing, such as payment method, transaction identifier, payment status, amount, currency and, where applicable, refund status. As a rule, we do not store full card details or online-banking access data where these are collected exclusively by the payment service provider.

The legal basis is Art. 6(1)(b) GDPR; where statutory evidence and accounting obligations apply, additionally Art. 6(1)(c) GDPR.

12. Invoices, accounting and tax retention

For invoicing, accounting and tax documentation, we process in particular the billing address, service data, invoice number, remuneration, tax information, payment information and related business documents.

The legal basis is Art. 6(1)(c) GDPR in conjunction with commercial and tax-law retention obligations.

Accounting records and invoices are generally retained for eight years. Commercial and business correspondence is generally retained for six years; longer statutory periods may apply to certain documents.

13. Support, CRM, email and messenger communication

For customer support, we may process communication and case data in internal customer, CRM, support or messaging systems. This includes in particular contact details, customer number, product and licence reference, technical information, error descriptions, attachments, previous communication, status and processing history.

If you contact us via WhatsApp or other external messengers, the privacy terms of the respective provider also apply. When clicking a messenger link, you may leave our website.

The legal basis is Art. 6(1)(b) GDPR where the communication serves to perform or initiate a contract; otherwise Art. 6(1)(f) GDPR.

14. Cookies, local storage and consent management

Technically necessary cookies or comparable access to storage may be used to provide login, shopping basket, language settings, security functions, sessions, consent status or functions expressly requested by you. Where Section 25(2) TDDDG applies, no prior consent is required for this.

Technologies that are not technically necessary, in particular for analytics, marketing or convenience purposes, are used only with your consent. The legal basis is Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR.

Your selection may be stored via our consent management or cookie banner and may be changed or withdrawn at any time with effect for the future.

15. Audience measurement, analytics and advertising

Where you have given consent, analytics and advertising services may be used, for example Google Analytics 4 or Google Ads Conversion Tracking. Page views, interactions, technical device information, referrers, approximate location data, campaign parameters and conversions may be processed.

The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. You may withdraw your consent at any time via the cookie settings.

16. Cloudflare Turnstile

We use Cloudflare Turnstile to protect our forms against spam, abuse and automated attacks. The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA.

This may involve processing the IP address, user agent, browser and device information, interaction and security characteristics, as well as information about the page accessed. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting our website, forms and IT systems.

17. External media, maps and embedded services

Where external content such as Google Maps, videos or other third-party modules is embedded, data such as the IP address, device information and usage data may be transferred to the respective provider. External content that is not technically necessary is loaded, where required, only after you have given consent.

For Google Maps, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, is the provider for users in the European Economic Area.

18. Local fonts and icons

Fonts and icons may be loaded locally from our own web server. In this case, no separate request is made to an external font or icon provider. The legal basis is Art. 6(1)(f) GDPR.

19. Recipients and processors

Depending on the function used, personal data may be transferred in particular to the following categories of recipients:

  • hosting, infrastructure and IT service providers
  • email, calendar and communication providers
  • AI infrastructure and model providers
  • CRM, support, customer portal and licence systems
  • payment service providers and financial service providers
  • accounting, tax and legal service providers
  • security, spam and abuse-prevention services
  • analytics and advertising service providers where consent has been given

Where a service provider processes data on our behalf, we enter into a data processing agreement in accordance with Art. 28 GDPR where required.

20. Transfers to third countries

Some technical providers may process data outside the European Union or European Economic Area. Such a transfer takes place only where the requirements of Art. 44 et seq. GDPR are met, for example on the basis of an adequacy decision, appropriate safeguards such as Standard Contractual Clauses, or another statutory exception.

For US providers, the EU-U.S. Data Privacy Framework may serve as a transfer basis where the respective provider is appropriately certified.

21. Retention periods and deletion concept

We store personal data only for as long as necessary for the respective purpose or where legal or contractual reasons require longer retention.

  • AI website chat: raw dialogues that can be linked to an individual are generally retained for no more than seven days after completion, after which they are deleted or irreversibly anonymised; transferred appointment, contract, support or security processes are excluded.
  • contact enquiries without a contractual connection: until final processing and, where applicable, beyond that period where necessary for evidence, security or limitation purposes.
  • customer account: generally for the duration of the account or contractual relationship and thereafter to the extent required for legal or contractual evidence.
  • contract and order data: for performance of the contract and, where applicable, until expiry of relevant limitation periods; the standard limitation period is generally three years.
  • invoices and accounting records: generally eight years.
  • commercial and business correspondence: generally six years.
  • permanent licences/entitlements: the minimum data necessary for as long as the usage right exists or evidence is required for restoration.
  • anonymised quality and statistical data: may be stored for longer where no link to an individual remains.

22. Backups and restoration

For operational security, personal data may temporarily also be contained in backup copies. Backups are replaced according to fixed rotation and deletion cycles and are generally used only for restoration, integrity and security purposes. Information deleted in the regular system may therefore remain for a limited period in backup copies that are not used in production.

23. Profiling and automated decisions

GS Media does not carry out solely automated decisions with legal or similarly significant effects under Art. 22 GDPR through the website, customer and AI processes described.

Where analytics or advertising services are used after consent has been given, they may create usage profiles for statistical or marketing purposes. The respective processing can be controlled and withdrawn via the consent settings.

24. Technical and organisational security measures

We implement appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access or unauthorised disclosure. These may include in particular TLS encryption, role and permission concepts, access controls, logging, security checks, backup and restoration procedures and protective mechanisms against automated attacks.

25. Your rights

Subject to the statutory requirements, you have in particular the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), objection (Art. 21 GDPR) and withdrawal of consent with effect for the future (Art. 7(3) GDPR).

To exercise your rights, it is sufficient to send a message to gs@gs-media.eu.

26. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. For our registered location in North Rhine-Westphalia, the competent authority is generally:

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2-4
40213 Düsseldorf
Germany

27. Updates and changes

We update this Privacy Policy when the services used, technical processes, business models or legal requirements change. The version published on this page at the relevant time is authoritative.

Last updated: August 2026

How can I help you?