Last updated and scope
Last updated: 7 September 2026. This notice covers the website desklix.com, contact and demo requests, and the Desklix platform including mobile applications and device interfaces. The sections below distinguish processing by Desklix for its own purposes from processing on behalf of a customer organisation. Visiting the website does not activate a platform integration. Additional storage and provider details: https://desklix.com/en/cookies/ and https://desklix.com/en/subprocessors/.
1. Controller and privacy contact
Dominik Büren, trading as Desklix, sole proprietorship. Felix-Hollenberg-Weg 32, 46539 Dinslaken, Germany. Email: hello@desklix.com. Phone: +49 1575 1407091. Please send privacy requests to hello@desklix.com. No data protection officer is currently appointed.
2. Website access and hosting
Cloudflare, Inc., USA, hosts the website and demo form. Processing includes IP address, time, requested URL, referrer where supplied, browser and operating system information, status and technical connection data. We use these data to deliver the website, resolve errors and prevent attacks. The basis is Art. 6(1)(f) GDPR; our legitimate interest is a secure and reliable website. Cloudflare operates international infrastructure; processing is not limited to Germany or the EU. Provider information: https://www.cloudflare.com/privacypolicy/ and https://www.cloudflare.com/cloudflare-customer-dpa/.
3. Contact and demo requests
The demo form submits your first and last name, business email, company, company size, preferred date, time and conversation language. When you contact us by email or telephone, we process the contact details and content you provide and necessary conversation notes. We use these data to respond, arrange a meeting and prepare a possible contract. A requested appointment is only agreed once personally confirmed.
Art. 6(1)(b) GDPR applies if you personally are the prospective contracting party. If you act for an organisation, Art. 6(1)(f) GDPR applies; our interest is communicating with business contacts and handling their inquiries. Submission does not constitute consent to newsletters or general promotional emails. You are not legally required to contact us. The fields requested by the form are necessary for that inquiry channel; you can alternatively contact us by email. Please do not submit unnecessary sensitive information.
4. Delivery and handling of inquiries
Our Cloudflare Worker sends the form content to the email service Resend (Plus Five Five, Inc., USA) for delivery to our business mailbox. The recipient address and message content are processed. The form does not create a separate lead or marketing database, but the inquiry remains in the mailbox and may be included in provider delivery logs. Resend provides information at https://resend.com/legal/privacy-policy and https://resend.com/legal/dpa. We use Microsoft 365 for our business mailbox; its European contracting entity is Microsoft Ireland Operations Limited, Ireland. Information: https://privacy.microsoft.com/en-us/privacystatement. Access is limited to persons who need to handle the inquiry.
5. Language preference and browser storage
Only when you explicitly select a language do we store “de” or “en” in local storage under “desklix-locale”. Entry pages without a language prefix read this preference to redirect you to the selected language. The entry has no user identifier or automatic expiry; it remains until overwritten or deleted in your browser. The access serves the language preference you requested (section 25(2), point 2 TDDDG). To the extent personal data are processed, Art. 6(1)(f) GDPR applies; our interest is providing your chosen language version. Without a stored choice we use the language reported by your browser. You can also access /de/ or /en/ directly.
6. Cookies, measurement and external content
The marketing website’s own code does not set cookies or use advertising pixels, analytics services or embedded social media plugins. Fonts and images are served as website files. No consent banner is displayed for the language storage described above. This statement concerns the marketing website; storage needed for the platform is described at https://desklix.com/en/cookies/. External checkout additionally has its own notices. Optional technologies requiring consent may only be activated after prior consent.
7. Contract preparation and online checkout
When a contract is concluded, we process business contact, contract, invoice and payment reference data to provide services and administer the contract. The bases are Art. 6(1)(b) GDPR for individuals as contracting parties, Art. 6(1)(f) GDPR for an organisation’s contacts and Art. 6(1)(c) GDPR for legal obligations. When you enter checkout, Stripe/Link also processes payment, billing, device and transaction data under the notices presented there. With Managed Payments, the Link seller identified at checkout acts as merchant of record. Details: https://stripe.com/privacy and https://link.com/privacy. Simply visiting the marketing site does not trigger checkout.
8. Accounts, authentication, security and support
For its own account and contract administration, Desklix processes business names, email addresses, organisation membership, permissions and authentication, session and security information. WorkOS provides authentication; SSO, multi-factor authentication and directory synchronisation depend on enabled features. The platform uses Cloudflare for web and API hosting and Convex for the backend, database and file storage. Resend delivers transactional messages.
Art. 6(1)(b) GDPR applies to individuals as contracting parties; Art. 6(1)(f) GDPR applies to business contact administration and prevention of misuse. Our legitimate interests are assigning authorised access, secure operation and handling support cases. For support and feedback, we process the content you submit, any attachments and necessary technical diagnostics on these bases. Legally required records are covered by Art. 6(1)(c) GDPR. Personal platform access requires the necessary identity and session information.
9. Processing on behalf of your organisation
Your organisation determines the purposes and legal bases of workplace use. Depending on agreed and enabled modules, processing may include names and business contact details, teams, roles and permissions, desk, room and parking bookings, attendance and check-ins, work locations, absences, visitor and host data, visitor documents, service requests, calendar events, integration identifiers, and usage and occupancy statistics. Data come from you, authorised people in your organisation and systems connected by the organisation. Your organisation determines required information, permitted access and permissible reporting within its legal obligations.
Desklix does not substitute a blanket legal basis of its own for the organisation’s basis. Its legal basis, instructions and data processing agreement govern this processing. A demo or pilot using real personal Customer Data also requires this agreement. Please primarily contact your organisation for access, correction, export and deletion of these data; Desklix assists it under the agreement. You may still contact us; your statutory rights remain unaffected. The basis is an agreement under Art. 28 GDPR. Provider information is available at https://desklix.com/en/subprocessors/.
10. Optional integrations, maps and AI
Microsoft 365 calendars, resources and connected HR systems such as Workday are connected only within the enabled scope and after the required authorisation. Identity, calendar, resource, absence or employment data needed for the function are exchanged between systems. The customer organisation manages its external accounts and permissions; processing within those services is also subject to its agreements with them.
Google Maps loads in building administration only after actively selecting “Load Google Maps”. Google may receive the IP address, technical connection data, search terms and coordinates. The building’s address, coordinates and Place ID can then be stored. Google also processes map data as an independent controller; https://policies.google.com/privacy and https://maps.google.com/help/terms_maps/ apply. This map feature is not a Google Workspace, Google Calendar or Google login integration.
The AI floor-plan optimiser sends the selected image, editing instructions and necessary request identifiers to the OpenAI API only at an authorised person’s request. Please remove unnecessary personal information from plans and prompts. These functions operate under your organisation’s legal bases and instructions; enabling an integration is not blanket privacy consent by everyone concerned. You can manage device permissions, such as location for an explicitly enabled location-based check-in or camera access, in browser or operating system settings.
11. Other recipients and data sources
Data normally come from you; your organisation or its authorised representative may also provide your business contact details. In addition to the technical providers named above, tax and legal advisers, courts and authorities may receive data where needed to comply with legal duties or establish, exercise or defend legal claims. Depending on the circumstances, Art. 6(1)(c) or (f) GDPR applies. We do not sell your inquiry data.
12. Processing outside the EEA
The services described in the provider overview, including Cloudflare, WorkOS, Resend, Microsoft, OpenAI, Google Maps and Stripe/Link may process data in the USA and other countries outside the European Economic Area. We do not promise exclusively European storage. The providers’ published data protection agreements provide in particular for EU Standard Contractual Clauses and, where applicable to the specific recipient and processing, adequacy decisions. Supplementary safeguards may be necessary where there is no adequacy decision. You can request details of a specific transfer and a copy of the relevant safeguards at hello@desklix.com.
13. Retention
Inquiries and related conversation notes are needed while handling, scheduling or concrete contract discussions are ongoing. Once these purposes end, they are to be deleted unless statutory retention or necessary legal defence requires otherwise. Not every demo inquiry is a business record subject to statutory retention. Relevant commercial correspondence is generally retained for six years, accounting vouchers for eight years and certain tax records for ten years (section 257 HGB and section 147 AO), depending on the document and statutory starting date. Pending proceedings may require longer retention. Retained records must be restricted to that purpose.
Technical access and delivery log retention depends on the hosting and email service and its retention settings; we do not promise one fixed period for all logs. Incident-specific data may be needed until a security incident is resolved. Language storage remains until you delete it. Platform data are additionally covered by the criteria below and customer agreements.
14. Retention of platform data
Personal platform data are processed according to documented customer instructions, agreed purposes and applicable retention obligations. Technical retention controls use explicitly approved rules for each data category and, where applicable, each customer organisation. We therefore do not promise a uniform period across all customers for visitor records, HR absences, notifications, operational logs, feedback diagnostics, booking and access history, signed visitor documents, temporary AI files or privacy exports. Please ask your organisation’s responsible contact for its applicable periods.
Without an approved rule there is no reliable promise of automatic age-based deletion. This does not release Desklix or the organisation from statutory deletion obligations; necessary deletion must be carried out through the available procedures. Return and deletion after termination follow the data processing agreement and mandatory law. Session, security credential and browser-storage expiry are separate controls; details are at https://desklix.com/en/cookies/.
15. Access, rectification and other rights
Subject to the legal requirements, you may request access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18) and portability (Art. 20). You may withdraw consent at any time for the future without affecting prior lawful processing. Send an informal request to hello@desklix.com. We only request additional information necessary to identify you if we have reasonable doubts about your identity. We generally respond within one month and inform you within that period of any legally permitted extension.
16. Your right to object
You may object at any time to processing based on Art. 6(1)(f) GDPR on grounds relating to your particular situation (Art. 21(1) GDPR). We will only continue if overriding compelling legitimate grounds exist or processing is needed to establish, exercise or defend legal claims. You may object to direct marketing at any time without giving reasons; processing for that purpose will stop. An email to hello@desklix.com is sufficient.
17. Complaints
You may complain in particular to a supervisory authority where you habitually reside, work or where the alleged infringement occurred (Art. 77 GDPR). The competent authority for Desklix is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen: Postfach 20 04 44, 40102 Düsseldorf, Germany; poststelle@ldi.nrw.de; https://www.ldi.nrw.de. You do not need to contact us first.
18. Automated decisions and external links
We do not make solely automated decisions producing legal or similarly significant effects under Art. 22 GDPR in the marketing and inquiry processing described here. External sites such as LinkedIn and X are reached through ordinary links. When you open them, the relevant provider’s processing also applies. This notice does not replace privacy information for the use of social networks.
19. Updates
We update this notice when the processing described changes. The revision date appears at the beginning. An update does not replace any consent that may be required.