This English translation is provided for convenience. The German version of this privacy notice is authoritative.
Halocline collects and processes personal data in order to operate the software products it offers and to provide support. This occurs when the software is first activated, while it is being used, and when support requests are made.
With all service providers that support us for these purposes and process data in this context, we have concluded the required data processing agreements (DPAs) pursuant to Art. 28 GDPR.
This privacy notice covers the processing operations for which Halocline is the controller. For content that customer organisations store in the Halocline cloud service (including DataSync synchronisation and files that users attach to support requests), Halocline acts as a processor pursuant to Art. 28 GDPR; in this respect, informing the data subjects is the responsibility of the respective customer organisation as controller.
Technical data are required to operate the software and to verify compliance with the licence terms.
The data categories based on legitimate interest – IP address, hardware ID/device fingerprint, machine name and operating system version, and the timestamps of server communication – serve to secure system access, to detect and defend against unauthorised access, and to ensure the traceability of security-relevant events. The legitimate interest follows from the need to safeguard the security and integrity of the software and of the data processed (cf. Recital 49 GDPR). Processing is limited to the technically necessary minimum; the data are not used for any other purposes. There are no overriding interests of the data subjects deserving protection: the data are technical in nature, are not used for profiling, and arise in the course of the professional use of the software.
For the login data (e-mail address, full name), the following applies: the contracting party is the respective customer organisation; the data subjects are its employees and thus not themselves party to the contract, so the processing is not based on Art. 6(1)(b) GDPR. It is based on Art. 6(1)(f) GDPR: the legitimate interest follows from providing and securing the software under the contract with the customer organisation; the processing is necessary for setting up and managing the user accounts and is foreseeable for employees to whom their employer provides the software. There are no overriding interests deserving protection.
| Data category | Legal basis | Service provider |
|---|---|---|
| E-mail address and full name (user login) | Art. 6(1)(f) GDPR (legitimate interest: providing and securing the software under the contract with the customer organisation) | Microsoft Ireland Operations, Ltd. (Azure) |
| IP address · hardware ID/device fingerprint · machine name · operating system version · timestamp of server communication | Art. 6(1)(f) GDPR (legitimate interest: data security) | Microsoft Ireland Operations, Ltd. (Azure) |
| Company name · application start time · licence type used and installed Halocline version | No personal reference without linkage to a user account; where linked: Art. 6(1)(f) GDPR (balancing of interests above) | Microsoft Ireland Operations, Ltd. (Azure) |
Company name, application start time, and licence type and version are primarily company- or contract-related information; a personal reference exists only insofar as they are linked to a user account – to that extent, the balancing of interests above applies accordingly.
Balancing of interests (Art. 6(1)(f) GDPR): The legitimate interest follows from the continuous improvement of the product, error analysis, and the optimisation of the licence cycle. Processing is limited to what is necessary for these purposes: the identifiers collected (customer, installation, licence, session and application ID) are pseudonymous technical identifiers; name and e-mail address are not collected. The IP address is nevertheless personal data; it is not evaluated to identify individual persons, and the user attribution of the analytics data is removed automatically after 18 months. The data are not used for any other purposes – in particular not to evaluate individual employees.
| Data category | Legal basis | Service provider |
|---|---|---|
| IP address · time the event was sent · type of interaction with the software · customer, installation, licence, session and application identifiers · general information on operating system and hardware (graphics card type, VR headset) | Art. 6(1)(f) GDPR (legitimate interest: software improvement, error analysis, customer success, licence optimisation) | Elastic International BV |
Halocline Cloud optionally offers synchronisation of planning data between devices (DataSync). If this feature is activated, synchronisation metadata are stored in a separate database infrastructure (Hetzner Online GmbH, Nuremberg, Germany/EU).
The synchronisation metadata are processed within the scope of processing on behalf of the controller under the data processing agreement with the respective customer organisation; the legal basis for the processing lies with the customer as controller, who in this respect is also responsible for informing the data subjects.
When users contact Halocline support, the data transmitted in the process are handled in our ticket system. Depending on the support case, further information may be included in addition to contact details (e.g. error descriptions, screenshots, system information).
For the support communication itself, Halocline is the controller. For files you attach to your request, Halocline acts as processor on behalf of your organisation (data processing agreement, Annex 1). Please attach only files that are necessary for handling the request.
Balancing of interests (Art. 6(1)(f) GDPR): The contracting party is the customer organisation; support requests are made by its employees. The legitimate interest follows from the performance of the contract with the employer (handling the support matters arising from the use of the software); processing is limited to the information submitted by the requesting person.
| Data category | Legal basis | Service provider |
|---|---|---|
| Name, e-mail address, content of the support communication (case description, correspondence) | Art. 6(1)(f) GDPR (legitimate interest: performance of the contract with the customer organisation) | Zendesk Inc. (EU data region) |
The following table provides a complete overview of all service providers that process personal data in the course of operating the product.
| Service provider | Registered office / data location | Purpose | Transfer basis |
|---|---|---|---|
| Microsoft Ireland Operations, Ltd. (Azure) | EU (Frankfurt, Germany) | Cloud infrastructure, blob storage, SQL database, authentication (Microsoft Entra External ID, B2C) | No third-country transfer; DPA concluded via the Microsoft Products and Services DPA |
| Elastic International BV | Netherlands (EU); data processing on Microsoft Azure infrastructure, West Europe region (EU) | Usage analytics and error/stability monitoring of the client software | No third-country transfer; DPA concluded |
| Hetzner Online GmbH (optional feature: DataSync) | EU (Nuremberg, Germany) | Infrastructure hosting for the DataSync metadata database | No third-country transfer; DPA concluded |
| Zendesk Inc. | EU (Ireland, Pod 29; EU data region configured) | Support ticket system; processing of support communication including contact details; attached files on behalf of the customer organisation | No third-country transfer; DPA concluded |
The Halocline software is based on the 3D engine of Unity Technologies S.F. (USA). As an independent controller, Unity collects pseudonymised data on software stability and error analysis in the course of engine operation (device information, telemetry and configuration data, and the IP address); no direct identifiers (name, e-mail address) are transmitted. The third-country transfer to the USA is based on Standard Contractual Clauses (Module 1, controller-to-controller).
| Data category | Retention period | Justification |
|---|---|---|
| Authentication and contract data (contact details, licence data, login) | Duration of the contractual relationship; deletion at tenant level at the end of the contract, backup copies rotate out within the defined retention period | Art. 6(1)(f) GDPR (see 1.1) |
| Usage analytics data (with user attribution) | 18 months, then automatic anonymisation | Art. 6(1)(f) GDPR; covers the full licence lifecycle |
| Anonymised usage data (after expiry of the 18 months) | Unlimited | No longer any personal reference (outside the scope of the GDPR) |
| DataSync metadata (optional feature) | Duration of the contractual relationship, then deletion | Processing on behalf of the controller under the DPA (see 1.3) |
| Support communication (Zendesk) | 3 years after closure of the support case | Art. 6(1)(f) GDPR (see 1.4); period based on the standard limitation period (Section 195 of the German Civil Code (BGB); interest in record-keeping and legal defence) |
| Support attachments (attached files, Zendesk) | With the respective ticket: 3 years after closure of the support case; deletion at the end of the contract in accordance with the data processing agreement | Processing on behalf of the customer organisation (see 1.4) |
Users whose personal data are processed in the course of using the software have the following rights:
Please send requests to: datenschutz@halocline.io. Requests are accepted with the name and a unique identifier (e.g. the registered e-mail address) in order to verify the identity of the requesting person. Halocline handles requests within the statutory period of one month pursuant to Art. 12(3) GDPR; for complex or multiple requests, the period may be extended by a further two months, of which the requesting person is informed in advance. Where Halocline processes personal data on behalf of a customer organisation, requests from data subjects are forwarded to the respective customer as controller; Halocline supports the customer in line with its obligations under the DPA.
Halocline occasionally makes changes to this privacy notice. In the event of material changes, key users are notified by e-mail.
| Controller | Halocline GmbH & Co. KG, Netter Platz 3, 49090 Osnabrück · datenschutz@halocline.io |
| Data Protection Officer (external) | datenschutz nord GmbH, Konsul-Smidt-Str. 88, 27217 Bremen · office@datenschutz-nord.de |
Version: September 2026
