Legal information for review before launch.
Privacy policy
Last updated
28 July 2026.
Controller
Desklix, Einzelunternehmen, owner: Dominik Bühren, Felix-Hollenberg-Weg 32, 46539 Dinslaken, Germany. Email: hello@desklix.com. Phone: +49 1575 1407091.
Scope
This privacy policy applies to the Desklix marketing website at desklix.com, demo and contact requests, and early product or pilot conversations. Customer tenants, signed pilot projects, and productive use of the Desklix workplace platform may require additional product privacy terms and a data processing agreement.
No appointed data protection officer
At this stage no statutory data protection officer has been appointed. Data protection requests can be sent to hello@desklix.com.
Website access and server logs
When you access the website, technically necessary access data may be processed by the hosting provider and by Desklix. This can include IP address, date and time of access, requested URL, referrer URL, browser and operating system information, HTTP status code, and transferred data volume. Processing is necessary to deliver the website, keep it secure, diagnose errors, and prevent misuse. The legal basis is Art. 6(1)(f) GDPR.
Demo and contact requests
If you request a demo, Desklix processes your first and last name, business email address, company, company size, preferred date, time, and language to answer the request and prepare a possible contract. The request is sent through a Vercel serverless endpoint and the email service Resend to hello@desklix.com. It is not stored in a separate marketing database. The legal basis is Art. 6(1)(b) GDPR for pre-contractual communication and Art. 6(1)(f) GDPR for documenting and following up business inquiries.
Local language preference
When you switch between German and English, the website stores the selected language in your browser's local storage under the key desklix-locale. This is used only to make redirects and language selection more convenient. No advertising tracking is connected to this storage. You can delete the entry at any time through your browser settings.
Cookies, analytics, and tracking
The current website does not use analytics cookies, advertising pixels, third-party tracking scripts, or embedded third-party fonts. If Desklix later adds analytics, CRM, chat, newsletter, or advertising tools, this privacy policy and any required consent mechanism must be updated before those tools are activated.
Product and pilot data
During a demo, pilot, or later SaaS use, Desklix may process workplace-related data such as account data, organization and team information, bookings, resources, check-ins, visitor data, workplace requests, usage reports, integration metadata, and Workday-related workforce data where configured by a customer. In that context, the customer may be the controller and Desklix may act as processor under Art. 28 GDPR. The exact roles, data categories, retention periods, subprocessors, and security measures must be documented in the customer contract and data processing agreement.
Recipients and processors
Personal data is only shared where necessary for operating the website, answering requests, providing services, fulfilling legal obligations, or protecting legal claims. Recipients may include hosting providers, email providers, CRM or support tools if configured, professional advisers, authorities where legally required, and product infrastructure providers for customer tenants. Processors are to be bound by data processing agreements.
Third countries
Desklix intends to use EU/EEA processing where reasonably possible. If personal data is transferred to a third country, Desklix will use an appropriate transfer mechanism, such as an EU adequacy decision, EU Standard Contractual Clauses, or another safeguard required by Art. 44 et seq. GDPR.
Retention
Server logs are kept only for as long as needed for technical operation, security, and abuse prevention. Contact and demo data is kept while the inquiry is active and then deleted or archived according to commercial and tax retention duties. Contract and accounting records may be retained for statutory retention periods. Product and pilot data is retained according to the applicable customer agreement and deletion concept.
Your rights
Subject to the statutory requirements, you have the right to access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of consent with future effect. You also have the right to lodge a complaint with a supervisory authority.
Supervisory authority
The competent supervisory authority for Desklix in North Rhine-Westphalia is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Postfach 20 04 44, 40102 Düsseldorf, Germany, email: poststelle@ldi.nrw.de, website: https://www.ldi.nrw.de.
Automated decisions
Desklix does not use automated decision-making within the meaning of Art. 22 GDPR on the marketing website.
External links and social profiles
The website links to external pages such as LinkedIn and X. Desklix does not control the data processing on those third-party websites. Their own privacy notices apply once you open those links.
Changes
Desklix may update this privacy policy if the website, product, legal requirements, or service providers change. The version published on this page is the current version.