Legal
Privacy Policy
As of 1 September 2026
1. Controller
The controller within the meaning of the GDPR is:
BCCM Inkubator GmbH
Bahnhofstraße 32
09648 Mittweida, Germany
Email: datenschutz@biberware.com
A data protection officer does not have to be designated under Section 38 BDSG. For data protection enquiries, please write to the address above.
2. Scope: data in our customers' workspaces
This privacy policy covers our website and processing for which we ourselves determine the purposes and means.
For personal data that customers process within their workspace on the Biber DPP platform, in particular data of their employees, their suppliers and data contained in product documents, the respective customer is the controller. In that respect we act exclusively as a processor on the basis of a data processing agreement under Article 28 GDPR and process that data only on the customer's documented instructions. Data subjects should address their rights to the respective customer; if such requests reach us, we forward them.
3. Hosting and provision
Our website and the platform are operated in data centres of Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, at the Falkenstein site in Germany.
When the site is accessed, access data is automatically processed in server log files: IP address, date and time, resource requested, volume of data transferred, status code, referrer, browser type and operating system. This processing is necessary to provide the service, to ensure system security and to defend against attacks; the legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in secure and stable operation. Log files are deleted after 30 days, unless an incident requires longer retention.
4. User account and login
A user account is required to use the platform. We process name, business email address, organisational affiliation, role, and login and log data. The legal basis is Article 6(1)(b) GDPR insofar as the processing serves the performance of the contract, and otherwise Article 6(1)(f) GDPR for securing access.
Authentication is provided by the Zitadel Cloud service of CAOS Ltd., Switzerland. An adequacy decision of the European Commission under Article 45 GDPR is in place for Switzerland.
Technically necessary cookies and comparable storage techniques are used for the session and login. The legal basis is Section 25(2) no. 2 TDDDG; no consent is required for this.
5. Email delivery
We send system notifications and invitations via Brevo (Sendinblue SAS), 106 boulevard Haussmann, 75008 Paris, France. We process the email address as well as sending and delivery information. The legal basis is Article 6(1)(b) GDPR, and otherwise Article 6(1)(f) GDPR.
6. Error diagnostics
To detect and remedy technical faults we operate self-hosted error diagnostics on our own infrastructure in Germany. No transfer to third parties takes place. We process technical error and diagnostic data, in particular time, error message, feature accessed, and browser and system information. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in the stability and security of the platform.
7. Database and storage
We use managed services of Aiven Oy, Helsinki, Finland, to operate the databases. Processing takes place on infrastructure of UpCloud Ltd., Finland, in the Frankfurt am Main data centre in Germany.
8. Contacting us
If you contact us by email, telephone or form, we process the information you provide in order to handle your enquiry. The legal basis is Article 6(1)(b) GDPR for enquiries relating to the initiation of a contract, and otherwise Article 6(1)(f) GDPR. The data is deleted once the enquiry has been fully dealt with and no statutory retention obligations apply.
9. Recipients at a glance
| Recipient | Seat | Service | Place of processing |
|---|---|---|---|
| Hetzner Online GmbH | Germany | Server infrastructure, object storage for documents, DNS | Falkenstein, Germany |
| Aiven Oy | Finland | Managed PostgreSQL and managed Valkey (cache), operated on infrastructure of UpCloud Ltd. (Finland) | Frankfurt am Main, Germany |
| CAOS Ltd. (Zitadel Cloud) | Switzerland | Identity and access management | EU |
| Brevo (Sendinblue SAS) | France | Transactional email (invitations, system notifications) | France |
10. Retention
We process personal data only for as long as it is necessary for the respective purpose. We then delete the data, unless statutory retention obligations under commercial and tax law apply or the data is required for the establishment, exercise or defence of legal claims. In those cases we restrict the processing.
11. Rights of data subjects
Data subjects have the right of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20), as well as the right to withdraw consent at any time with effect for the future (Article 7(3)).
Right to object
Insofar as we process personal data on the basis of legitimate interests under Article 6(1)(f) GDPR, data subjects have the right to object to that processing at any time on grounds relating to their particular situation (Article 21 GDPR).
Right to lodge a complaint
Data subjects have the right to lodge a complaint with a supervisory authority. The authority competent for us is: Die Sächsische Datenschutz- und Transparenzbeauftragte, Devrientstraße 5, 01067 Dresden, Germany.