Skip to Content

° Privacy Policy

for our website, the customer portal and 36T Cloud · Version: October 2026

This English version is provided for convenience. Only the German version is legally binding.

This policy describes how 36T Solutions GmbH processes personal data when you visit our website, use our customer portal, request a demo or order 36T Cloud.

1. Controller

36T Solutions GmbH, Hungerbühlstraße 33, 73614 Schorndorf, Germany · E-mail: [email protected] · Managing Director: Renan Maier Ferreira. For questions about data protection, please contact us at this e-mail address.

2. Website

2.1 Visiting the website

When you visit our website, our servers process technically necessary data: IP address, date and time, page requested, amount of data transferred, browser and operating system, and the previously visited page. This data is stored in log files in order to deliver the website, detect errors and fend off attacks.

The legal basis is our legitimate interest in secure and functioning operation (Art. 6 (1) (f) GDPR). The logs are deleted as soon as they are no longer required for these purposes. For fast and secure delivery we use a provider of network and security services through which requests are routed.

2.2 Cookies and local storage

We set no cookies for a mere visit to our website. Only if you agree in the banner do we store your language choice in a cookie so that you land in your language on your next visit; your decision itself is kept in your browser’s local storage (§ 25 (1) TDDDG, Art. 6 (1) (a) GDPR). You can withdraw your consent at any time by deleting the stored website data in your browser.

When you sign in (customer portal, section 4), we set a technically necessary session cookie without which signing in does not work (§ 25 (2) no. 2 TDDDG).

2.3 Audience measurement

To understand which content is read, we use an analytics tool that we operate ourselves. It sets no cookies, stores nothing on your device and does not recognise you across other websites. It records page views, the referring page, browser, device type, country and events on the page such as clicks on buttons and links, form submissions and technical errors. We analyse aggregated figures; we do not create profiles of individual visitors, and individual visits are not recorded.

The legal basis is our legitimate interest in improving our offering (Art. 6 (1) (f) GDPR). You can object by blocking scripts in your browser.

2.4 Contact form and e-mail

If you write to us via the contact form or by e-mail, we process your details (name, e-mail address, company, phone number, your message) in order to answer your enquiry and, where applicable, prepare an offer. The details are stored in our customer management system.

The legal basis is the initiation or performance of a contract (Art. 6 (1) (b) GDPR) or our legitimate interest in answering enquiries (lit. f). We delete the data when it is no longer required, or after statutory retention periods have expired if a contract results.

3. Demo instances

If you request a demo, we process your name, e-mail address, company and language in order to set up a time-limited demo instance for you, send you the access details and accompany you through the demo (Art. 6 (1) (b) GDPR). The demo instance is deleted, including all data stored in it, when its period ends. Your request remains as a contact in our customer management system as long as there is a business interest (Art. 6 (1) (f) GDPR); you may object to this at any time.

4. Customer portal

For the customer portal we process the data of your user account (name, e-mail address, language, password as a hash, two-factor settings where applicable), your membership of organisations and your permissions, and the content you create in the portal (e.g. tickets, messages, files, approvals). We log sign-ins and security-relevant events.

The portal sends e-mails about your account (invitation, password, security) and notifications whose frequency you can set in the portal. The legal basis is the contract with you or your organisation (Art. 6 (1) (b) GDPR) or our legitimate interest in secure operation (lit. f). The data is deleted when the account is removed, unless retention obligations prevent this.

5. 36T Cloud: order, payment, billing

If you order 36T Cloud, we process the data of your organisation and of the person ordering (company, address, VAT ID, contact person, e-mail address), the order and contract data and the invoices (Art. 6 (1) (b) and (c) GDPR). We keep invoice and accounting data for the periods required by commercial and tax law (up to ten years).

Payment is handled by a payment service provider. You enter your payment details (e.g. card number, bank details) directly there; we only receive the information we need for allocation and billing (e.g. payment status, payment method, last digits). The payment service provider is itself responsible for its own processing.

Data in your Odoo instance we process not as controller but as processor for your organisation under our data processing agreement. Your organisation is responsible for this data; its privacy policy provides information about it.

6. Recipients

We only pass on your data to the extent required for the purposes stated, to:

  • providers of hosting, data centre and backup services,
  • providers of network and security services,
  • providers of e-mail delivery,
  • payment service providers,
  • tax advisers and authorities, where we are legally obliged to.

Our providers process data on our behalf and according to our instructions, unless, like payment service providers, they are themselves responsible.

7. Transfers to third countries

Some providers are based outside the EU or may process data outside the EU. Such a transfer only takes place if the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision of the EU Commission (for the USA, for example, the EU-U.S. Data Privacy Framework) or EU standard contractual clauses. On request we will tell you the basis concerned.

8. Retention

We store personal data for as long as is necessary for the respective purpose. Statutory retention obligations (in particular six or ten years under HGB and AO) remain unaffected; for this period the data is restricted and kept only for that purpose.

9. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to withdraw consent at any time with effect for the future (Art. 7 (3)).

Right to object (Art. 21 GDPR): Where we process data on the basis of legitimate interests, you may object at any time on grounds relating to your particular situation. You may object to processing for direct marketing at any time without giving reasons.

You also have the right to lodge a complaint with a data protection supervisory authority, for example the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.

You are not obliged to provide your data. Without the details required for the contract, portal or demo, however, we cannot provide these services. No automated decision-making, including profiling, takes place.

10. Changes

We adapt this policy when our services, the services we use or the law change. The version published on this page applies.