Skip to main content

Data protection

Privacy notice

This notice explains what personal data Direct Software processes, why we use it, who may receive it and which rights you have. It covers this website, email enquiries, appointment scheduling and AI-assisted work.

Last updated: 10 September 2026

Controller

The person responsible for processing personal data under the General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP), where it applies, is:

Brian Johannes Catharina Elisabeth Timmermans

Direct Software

Waldtruderinger Str. 24A

81827 München

Deutschland

brian.timmermans@direct-software.com

Direct Software is not entered in a commercial register. No VAT identification number has been issued.

Data processed through this website

Hosting and security logs

Vercel hosts and delivers the website. Cloudflare provides DNS services for the domain. When you request a page, Vercel may process technical data needed to deliver and protect the service. Cloudflare processes the technical data needed to answer DNS requests.

  • IP address, date and time of the request
  • Requested address, referrer and response status
  • Browser, device and operating-system information
  • Security and diagnostic information

We process this data to provide a secure and reliable website, prevent misuse and diagnose faults. The legal basis is our legitimate interest under Article 6(1)(f) GDPR.

Scenario-selection tool

The assessment processes the options you select in your browser and places them in the page address so that you can keep or share the result. It does not ask for your name or contact details and does not create a user profile. The full address, including the selections, may nevertheless appear in hosting and security logs. Do not place confidential or personal information in a shared address.

We provide this tool to offer a relevant recommendation without requiring contact details. The legal basis is our legitimate interest under Article 6(1)(f) GDPR.

Cookies and language settings

The website uses two first-party cookies for its language settings. NEXT_LOCALE stores the selected or automatically determined website language for one year. LOCALE_CONFIRMED is set for one year after you confirm the language choice. Neither cookie is used to follow you across websites:

  • NEXT_LOCALE remembers the selected website language.
  • LOCALE_CONFIRMED remembers that you confirmed the language choice.

These cookies are strictly necessary to provide the language choice you requested and are set under Section 25(2)(2) of the German Telecommunications-Digital-Services Data Protection Act (TDDDG). The website does not currently use advertising cookies or visitor analytics. We will update this notice and request consent where required before introducing non-essential tracking.

Google Calendar appointment scheduling

The schedule page embeds a Google Calendar appointment scheduler. The embed connects to Google when the page opens, so Google may receive your IP address, browser information, referrer and cookie or device information. If you book, Google also processes the details you submit, such as your name, email address, chosen time and information you add to the booking. Google may process this data outside the European Economic Area.

When you request a meeting as a step towards entering into a contract with us, we process the booking under Article 6(1)(b) GDPR. In other business contexts, we rely on our legitimate interest in arranging and preparing relevant business meetings under Article 6(1)(f) GDPR. The Google scheduler loads when you open the schedule page. You can avoid the connection to Google by contacting us directly by email.

Enquiries, meetings and business relationships

When you email us, book a meeting or communicate with us in another business context, we process the information needed to understand and answer the request, prepare the meeting and manage the relationship.

  • Name, role, organisation and contact details
  • Message, appointment and meeting information
  • Information about the software, systems, work processes or decision you describe
  • Subsequent correspondence, proposals, agreements and project records

Where processing is necessary to take steps at your request before entering into a contract with you, or to perform a contract with you, the legal basis is Article 6(1)(b) GDPR. For other relevant business communications, including contact with representatives of an organisation, we rely on our legitimate interest under Article 6(1)(f) GDPR. Statutory record-keeping may also require processing under Article 6(1)(c) GDPR.

AI-assisted work and client information

Direct Software may use Google Workspace Gemini and GitHub Copilot Business to assist with analysing an enquiry or approved project material, structuring requirements, drafting or reviewing documents, designing software, writing code and tests, and reconstructing technical documentation. An accountable person reviews relevant output and makes the decisions. We do not use AI for solely automated decisions that produce legal or similarly significant effects for you.

  • We limit submitted information to what is needed for the task and avoid personal or confidential data where it is not necessary.
  • Client instructions, confidentiality duties, access controls and agreed project restrictions continue to apply.
  • Sensitive or proprietary material is only submitted where the service and account controls are suitable for the agreed work.
  • AI output is treated as unverified working material until a person reviews it.

We use managed business accounts. Under the applicable terms, Google does not use Google Workspace customer data to train or fine-tune its generative AI models without the customer's permission or instruction. GitHub does not use Copilot Business data to train its models. Direct Software does not submit client enquiries or proprietary business data to public AI services that use that data for model training.

Where this processing is necessary to prepare or perform a contract with you, the legal basis is Article 6(1)(b) GDPR. In other business contexts, including work for an organisation you represent, we rely on our legitimate interests in quality, security and efficient software delivery under Article 6(1)(f) GDPR. Contractual restrictions take priority where they are stricter.

Service providers and other recipients

We disclose personal data only when this is necessary for a stated purpose, required by law or authorised by you. Depending on how you interact with us, recipients may include:

  • Vercel for website hosting and delivery, and Cloudflare for DNS services
  • Google Workspace for email, documents, calendar, meetings and managed Gemini services
  • GitHub and GitHub Copilot Business for approved source-control and AI-assisted engineering work
  • Professional advisers, selected project specialists or client-designated parties where required for the work
  • Public authorities or courts where disclosure is legally required

Where a service provider processes personal data on our behalf, that processing is governed by the applicable data-processing terms. A provider may process some data for its own stated purposes where its terms and the law permit this. Freelance specialists receive only the access needed for their role and remain subject to confidentiality and data-protection obligations. We do not sell personal data.

International data transfers

Some providers are headquartered in, or use infrastructure and support teams in, countries outside the European Economic Area or Switzerland, including the United States. This means personal data may be processed in those countries.

Where required, transfers are based on an adequacy decision, participation in an applicable recognised framework such as the EU-US Data Privacy Framework, or contractual safeguards such as the European Commission's Standard Contractual Clauses. We also consider provider security and supplementary safeguards where appropriate. You may contact us for information about the safeguard relevant to a particular transfer.

How long we keep data

We keep personal data only for as long as needed for the purpose for which it was collected, to establish or defend legal claims, and to meet applicable German commercial and tax record duties. The period therefore depends on the record:

  • Hosting and security logs are kept for the provider's configured operational and security period.
  • Enquiries that do not lead to work are deleted when they are no longer needed for follow-up or the establishment or defence of claims.
  • Appointment and correspondence records are kept while the conversation or business relationship remains relevant.
  • Contracts, invoices and records with commercial or tax relevance are kept for the statutory retention period that applies to that record.
  • Project material is deleted or returned under the agreement and applicable legal duties.

Your privacy rights

Subject to the legal conditions and exceptions, you may:

  • Ask for access to your personal data and a copy of it.
  • Ask us to correct inaccurate or incomplete data.
  • Ask us to erase data or restrict its processing.
  • Receive data you provided in a portable format where the right applies.
  • Object, on grounds relating to your particular situation, to processing based on legitimate interests.
  • Object at any time to the use of your data for direct marketing, if we carry out such marketing.
  • Withdraw consent at any time where processing is based on consent, without affecting earlier lawful processing.
  • Lodge a complaint with a data-protection authority.

Send a request to the privacy contact shown above. We may need to verify your identity and may retain information needed to document and answer the request.

If the Swiss FADP applies, you also have the rights provided by that law, including rights to information, correction, deletion or destruction, and data portability where its conditions are met.

Complaints

You may complain to a supervisory authority, particularly in the EU or EEA country where you live, work or believe an infringement occurred. The authority responsible for this German establishment is the Bavarian State Office for Data Protection Supervision. In the Netherlands you may contact the Autoriteit Persoonsgegevens. In Switzerland you may contact the Federal Data Protection and Information Commissioner.

Security

We use organisational and technical measures intended to protect personal data against unauthorised access, alteration, loss and disclosure. Access is limited according to role and purpose. No internet transmission or storage system can be guaranteed to be completely secure.

Changes to this notice

We update this notice when our processing, providers or legal obligations change. The current version and its revision date are published on this page.