Data Privacy Information

Halocline Software

Information pursuant to Art. 13 GDPR

This English translation is provided for convenience. The German version of this privacy notice is authoritative.

Halocline collects and processes personal data in order to operate the software products it offers and to provide support. This occurs when the software is first activated, while it is being used, and when support requests are made.

With all service providers that support us for these purposes and process data in this context, we have concluded the required data processing agreements (DPAs) pursuant to Art. 28 GDPR.

This privacy notice covers the processing operations for which Halocline is the controller. For content that customer organisations store in the Halocline cloud service (including DataSync synchronisation and files that users attach to support requests), Halocline acts as a processor pursuant to Art. 28 GDPR; in this respect, informing the data subjects is the responsibility of the respective customer organisation as controller.

1. Categories of personal data

1.1 Technical data (licensing & authentication)

Technical data are required to operate the software and to verify compliance with the licence terms.

The data categories based on legitimate interest – IP address, hardware ID/device fingerprint, machine name and operating system version, and the timestamps of server communication – serve to secure system access, to detect and defend against unauthorised access, and to ensure the traceability of security-relevant events. The legitimate interest follows from the need to safeguard the security and integrity of the software and of the data processed (cf. Recital 49 GDPR). Processing is limited to the technically necessary minimum; the data are not used for any other purposes. There are no overriding interests of the data subjects deserving protection: the data are technical in nature, are not used for profiling, and arise in the course of the professional use of the software.

For the login data (e-mail address, full name), the following applies: the contracting party is the respective customer organisation; the data subjects are its employees and thus not themselves party to the contract, so the processing is not based on Art. 6(1)(b) GDPR. It is based on Art. 6(1)(f) GDPR: the legitimate interest follows from providing and securing the software under the contract with the customer organisation; the processing is necessary for setting up and managing the user accounts and is foreseeable for employees to whom their employer provides the software. There are no overriding interests deserving protection.

Data categoryLegal basisService provider
E-mail address and full name (user login)Art. 6(1)(f) GDPR (legitimate interest: providing and securing the software under the contract with the customer organisation)Microsoft Ireland Operations, Ltd. (Azure)
IP address · hardware ID/device fingerprint · machine name · operating system version · timestamp of server communicationArt. 6(1)(f) GDPR (legitimate interest: data security)Microsoft Ireland Operations, Ltd. (Azure)
Company name · application start time · licence type used and installed Halocline versionNo personal reference without linkage to a user account; where linked: Art. 6(1)(f) GDPR (balancing of interests above)Microsoft Ireland Operations, Ltd. (Azure)

Company name, application start time, and licence type and version are primarily company- or contract-related information; a personal reference exists only insofar as they are linked to a user account – to that extent, the balancing of interests above applies accordingly.

Note on retention: Authentication and licence data are stored for the duration of the contractual relationship and deleted thereafter. Statutory retention obligations apply exclusively to accounting-relevant records; operating logs and authentication data are not subject to these periods.

1.2 Usage data (analytics)

Balancing of interests (Art. 6(1)(f) GDPR): The legitimate interest follows from the continuous improvement of the product, error analysis, and the optimisation of the licence cycle. Processing is limited to what is necessary for these purposes: the identifiers collected (customer, installation, licence, session and application ID) are pseudonymous technical identifiers; name and e-mail address are not collected. The IP address is nevertheless personal data; it is not evaluated to identify individual persons, and the user attribution of the analytics data is removed automatically after 18 months. The data are not used for any other purposes – in particular not to evaluate individual employees.

Data categoryLegal basisService provider
IP address · time the event was sent · type of interaction with the software · customer, installation, licence, session and application identifiers · general information on operating system and hardware (graphics card type, VR headset)Art. 6(1)(f) GDPR (legitimate interest: software improvement, error analysis, customer success, licence optimisation)Elastic International BV
Right to object (Art. 21 GDPR): You may object to the processing of usage data at any time. Every user can individually deactivate the collection of usage data in the software; deactivation takes effect immediately. Alternatively, an e-mail to datenschutz@halocline.io is sufficient.

1.3 DataSync metadata Optional feature

Halocline Cloud optionally offers synchronisation of planning data between devices (DataSync). If this feature is activated, synchronisation metadata are stored in a separate database infrastructure (Hetzner Online GmbH, Nuremberg, Germany/EU).

The synchronisation metadata are processed within the scope of processing on behalf of the controller under the data processing agreement with the respective customer organisation; the legal basis for the processing lies with the customer as controller, who in this respect is also responsible for informing the data subjects.

1.4 Support communication

When users contact Halocline support, the data transmitted in the process are handled in our ticket system. Depending on the support case, further information may be included in addition to contact details (e.g. error descriptions, screenshots, system information).

For the support communication itself, Halocline is the controller. For files you attach to your request, Halocline acts as processor on behalf of your organisation (data processing agreement, Annex 1). Please attach only files that are necessary for handling the request.

Balancing of interests (Art. 6(1)(f) GDPR): The contracting party is the customer organisation; support requests are made by its employees. The legitimate interest follows from the performance of the contract with the employer (handling the support matters arising from the use of the software); processing is limited to the information submitted by the requesting person.

Data categoryLegal basisService provider
Name, e-mail address, content of the support communication (case description, correspondence)Art. 6(1)(f) GDPR (legitimate interest: performance of the contract with the customer organisation)Zendesk Inc. (EU data region)

2. Service providers used

The following table provides a complete overview of all service providers that process personal data in the course of operating the product.

Service providerRegistered office / data locationPurposeTransfer basis
Microsoft Ireland Operations, Ltd. (Azure)EU (Frankfurt, Germany)Cloud infrastructure, blob storage, SQL database, authentication (Microsoft Entra External ID, B2C)No third-country transfer; DPA concluded via the Microsoft Products and Services DPA
Elastic International BVNetherlands (EU); data processing on Microsoft Azure infrastructure, West Europe region (EU)Usage analytics and error/stability monitoring of the client softwareNo third-country transfer; DPA concluded
Hetzner Online GmbH (optional feature: DataSync)EU (Nuremberg, Germany)Infrastructure hosting for the DataSync metadata databaseNo third-country transfer; DPA concluded
Zendesk Inc.EU (Ireland, Pod 29; EU data region configured)Support ticket system; processing of support communication including contact details; attached files on behalf of the customer organisationNo third-country transfer; DPA concluded

The Halocline software is based on the 3D engine of Unity Technologies S.F. (USA). As an independent controller, Unity collects pseudonymised data on software stability and error analysis in the course of engine operation (device information, telemetry and configuration data, and the IP address); no direct identifiers (name, e-mail address) are transmitted. The third-country transfer to the USA is based on Standard Contractual Clauses (Module 1, controller-to-controller).

3. Data retention and deletion

Data categoryRetention periodJustification
Authentication and contract data (contact details, licence data, login)Duration of the contractual relationship; deletion at tenant level at the end of the contract, backup copies rotate out within the defined retention periodArt. 6(1)(f) GDPR (see 1.1)
Usage analytics data (with user attribution)18 months, then automatic anonymisationArt. 6(1)(f) GDPR; covers the full licence lifecycle
Anonymised usage data (after expiry of the 18 months)UnlimitedNo longer any personal reference (outside the scope of the GDPR)
DataSync metadata (optional feature)Duration of the contractual relationship, then deletionProcessing on behalf of the controller under the DPA (see 1.3)
Support communication (Zendesk)3 years after closure of the support caseArt. 6(1)(f) GDPR (see 1.4); period based on the standard limitation period (Section 195 of the German Civil Code (BGB); interest in record-keeping and legal defence)
Support attachments (attached files, Zendesk)With the respective ticket: 3 years after closure of the support case; deletion at the end of the contract in accordance with the data processing agreementProcessing on behalf of the customer organisation (see 1.4)

4. Rights of data subjects

Users whose personal data are processed in the course of using the software have the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR) to processing based on legitimate interests – for usage analytics directly in the software with immediate effect (see the note under 1.2)
  • Right to lodge a complaint with a data protection supervisory authority

Please send requests to: datenschutz@halocline.io. Requests are accepted with the name and a unique identifier (e.g. the registered e-mail address) in order to verify the identity of the requesting person. Halocline handles requests within the statutory period of one month pursuant to Art. 12(3) GDPR; for complex or multiple requests, the period may be extended by a further two months, of which the requesting person is informed in advance. Where Halocline processes personal data on behalf of a customer organisation, requests from data subjects are forwarded to the respective customer as controller; Halocline supports the customer in line with its obligations under the DPA.

5. Changes to this privacy notice

Halocline occasionally makes changes to this privacy notice. In the event of material changes, key users are notified by e-mail.

6. Contact and responsibility

ControllerHalocline GmbH & Co. KG, Netter Platz 3, 49090 Osnabrück · datenschutz@halocline.io
Data Protection Officer (external)datenschutz nord GmbH, Konsul-Smidt-Str. 88, 27217 Bremen · office@datenschutz-nord.de

Version: September 2026