1. Controller
The controller for data processing on this website is:
ToShift GmbH Am Sandtorkai 32 20457 Hamburg Germany
Represented by: André Käber, Managing Director Email: web@toshift.de Contact form: https://www.toshift.de/contact
2. Data Protection Officer
We have not appointed a data protection officer, as we are currently under no legal obligation to do so. For any questions about data protection, please contact us at web@toshift.de.
3. General Information on Data Processing
We process personal data only where necessary to operate a functional website and to provide our content and services. Depending on the activity, processing is based on one of the following legal bases:
- Art. 6(1)(a) GDPR (consent),
- Art. 6(1)(b) GDPR (performance of a contract and pre-contractual steps),
- Art. 6(1)(f) GDPR (legitimate interests),
- Section 26 of the German Federal Data Protection Act (BDSG) for job applications.
The specific legal basis is stated with each processing activity below.
Depending on the activity, recipients of your data may include hosting providers, email providers, our CRM provider and AI service providers. The specific recipients are named with each processing activity.
Where we transfer data to countries outside the EU or EEA, such transfers are based on the Standard Contractual Clauses adopted by the European Commission. You can request a copy of these safeguards at any time via web@toshift.de; the clauses are also available on the European Commission's website.
4. Your Rights
You have the right at any time to:
- obtain access to the data we hold about you (Art. 15 GDPR),
- have inaccurate data rectified (Art. 16 GDPR),
- have your data erased (Art. 17 GDPR),
- restrict processing (Art. 18 GDPR),
- receive your data in a portable format (Art. 20 GDPR),
- withdraw any consent you have given, with effect for the future; this does not affect the lawfulness of processing carried out before the withdrawal.
RIGHT TO OBJECT (ART. 21 GDPR): Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to that processing at any time on grounds relating to your particular situation. We will then stop processing the data unless we can demonstrate compelling legitimate grounds for continuing.
To exercise any of these rights, simply email web@toshift.de.
5. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI) (Hamburg Commissioner for Data Protection and Freedom of Information) Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany
6. Retention
We keep personal data only for as long as it is needed for the purposes described here, or as required by statutory retention obligations. Where possible, specific retention details are given with each processing activity.
7. Hosting and Technical Logs
Our website is hosted by Hetzner Online GmbH in its Falkenstein data center (Germany); technical operations are handled by Franke & Schwarz GmbH, Amsterdamer Straße 18, 13347 Berlin. The entire infrastructure — website, analytics, assessment and database — runs on a single server in Germany.
Our website is delivered exclusively over encrypted HTTPS connections.
At the application level, we do not keep a persistent access log containing your IP address; our applications write only minimal technical logs without storing it. As our hosting provider, Hetzner Online GmbH processes infrastructure-level log data on our behalf. This may include, in particular, the IP address, the time of access, the resource requested and technical connection data, to the extent necessary to keep the service secure and operational.
The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the secure and stable operation of the website.
8. Web Analytics with Umami
To understand how our website is used, we rely on Umami, a privacy-focused, cookieless analytics tool. We host Umami ourselves (at umami.toshift.de, on the same server in Falkenstein, Germany). We do not use Umami Cloud, and no data is passed to third parties. No cookies are set, and IP addresses are never stored in plain text.
We process: the page visited and the referrer, browser, operating system and device type, screen size, an approximate country of origin, and defined click events. No personal profiles are created.
We keep the analytics data for as long as it is needed for statistical analysis.
The legal basis is Art. 6(1)(f) GDPR (our legitimate interest in designing and improving our website based on how it is actually used). You can object to this processing at any time (see Section 4).
9. Cookies and Embedded Content
We do not use cookies for analytics, marketing or tracking purposes; our analytics tool Umami works without cookies.
The Digital Maturity Assessment uses local storage (localStorage) in your browser. It holds a randomly generated session ID (UUID), your current progress in the assessment (answers, scoring status and the format you selected) and the email address you entered. It does not hold your name, any tracking or user identifier, or any login token; the conversation itself is stored on our server, not in your browser (see Section 11). The embedded chat also sets one functional cookie whose sole purpose is to maintain your session (no login, no tracking). It expires after no more than 15 days and is transmitted over encrypted connections only. None of this information is used for analytics or marketing. Both are strictly necessary to provide the service you have requested, so no consent is required (Section 25(2) no. 2 of the German TDDDG).
We do not load any resources from third-party servers; our fonts are hosted locally (no Google Fonts).
10. Contact Form
If you contact us through the contact form, we process the details you provide: name, email address, company (optional) and your message. The fields marked as required are needed to handle your inquiry.
Your message is delivered solely by email to our mailbox web@toshift.de; the transmission is encrypted in transit (TLS), and the message is not stored in any database or file. The mailbox is operated by Fastmail (Fastmail Pty Ltd, Australia), with data processed on servers in the USA. This involves transfers to third countries (USA, Australia); they are based on the European Commission's Standard Contractual Clauses, which are incorporated into Fastmail's data processing agreement.
The legal basis is Art. 6(1)(b) GDPR where your inquiry relates to a contract, and otherwise Art. 6(1)(f) GDPR (our legitimate interest in responding to inquiries). We keep the data for as long as needed to handle your inquiry and any follow-up. We will delete your message on request, unless statutory retention periods (for example, for business correspondence) require us to keep it.
11. Digital Maturity Assessment
On our website we offer an AI-supported Digital Maturity Assessment. On the page toshift.de/assessment, you have a conversation with an AI assistant about your logistics and operations topics. The assessment produces a maturity result (score/level) and a PDF report. To receive the report, you need to provide an email address; without it, the report cannot be sent. You are under no legal or contractual obligation to provide it.
We process your conversation input, the metrics derived from it, and your email address.
AI service: the conversation is powered by Claude language models provided by Anthropic PBC via its cloud API. Your input is transferred to Anthropic in the USA for processing. The transfer is based on the European Commission's Standard Contractual Clauses, which are incorporated into Anthropic's data processing agreement. Under the terms of the commercial Anthropic API, your content is not used to train AI models.
Storage: the conversation history, the metrics, your email address and the generated PDF report are stored in a database (MongoDB) that we host ourselves on our server in Falkenstein (Germany). We keep this data for as long as needed to handle your assessment, but no longer than 12 months, after which it is deleted automatically. We will delete it earlier on request. The report is also sent by email to you and to an internal address at ToShift; that mailbox is operated via Fastmail (see Section 10). We keep those report copies for as long as needed to support your inquiry; if you request erasure, these copies are deleted as well.
The following data is transferred to Pipedrive, our CRM: name, email address, organization, the maturity result (score/level), individual company-related metrics and a link to the report (see Section 12). The full conversation history and the PDF itself are not transferred to Pipedrive.
Automated processing: the maturity result (score/level) and the report are generated automatically. There is no decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR).
The legal basis is Art. 6(1)(b) GDPR (carrying out the assessment you requested and sending you the report). For adding the contact and metric data to our CRM, the legal basis is Art. 6(1)(f) GDPR (our legitimate interest in maintaining and following up on business contacts, see Section 12).
12. Customer Relationship Management (Pipedrive)
To manage contacts and prospects, we use the CRM system Pipedrive (Pipedrive OÜ, Estonia). There we process contact and metric data, including from the Digital Maturity Assessment: name, email address, organization, the maturity result (score/level), individual company-related metrics (such as shipments per day, warehouse locations or carriers used) and a link to the report. The full conversation history and the PDF are not stored in Pipedrive.
Our Pipedrive account is hosted in an EU data center in Frankfurt, Germany; our contracting party is Pipedrive OÜ in Estonia. Since Pipedrive uses US-based sub-processors, transfers to the USA may still occur; these are based on Standard Contractual Clauses.
We keep contact and metric data in Pipedrive for as long as there is a business interest in maintaining the contact; we delete it on request.
The legal basis is Art. 6(1)(f) GDPR (our legitimate interest in managing our business contacts) or Art. 6(1)(b) GDPR where the processing serves to initiate or perform a contract.
13. Job Applications
For job applications, we direct you from our careers page to an application portal operated for us by Personio (Personio SE & Co. KG, Munich). You enter your application details there, not on toshift.de. Personio processes the data as our processor; its servers are located in the EU.
We process your application data solely to run the application procedure. The legal basis is Art. 6(1)(b) GDPR in conjunction with Section 26 BDSG.
Application data is deleted after 90 days. A separate privacy notice is shown on the careers portal before you submit your application.
14. Changes to This Privacy Policy
This privacy policy reflects the status stated above. We will update it whenever our data processing or the legal requirements change.
Note: this is a translation provided for convenience. In case of any discrepancy, the German version prevails.