Transparency Statement for Customers
Basic information
Data subjects
This privacy statement is directed at all persons who can be classified as potential, active, or former customers. This applies regardless of whether the service is provided for remuneration or free of charge. All references to persons refer to all genders and the associated linguistic forms, in particular diverse, female, male. Every reference to a person is to be understood with the addition "(m/f/d)".
Controller
The controller for the processing described here is: Adbaker GmbH, Kalscheurener Str. 19A, 50354 Hürth, mail@adbaker.de, T: +49 (0) 221 99983680, e-mail: mail@adbaker.de, represented by the managing director Simon Mader.
Rights
(1) With regard to the data stored about their person, data subjects have the following rights: the right of access, the right to rectification of inaccurate data, the right to erasure of data for which there is no longer any reason for retention, the right to restriction of processing, and the right to data portability. Furthermore, they have the right to lodge a complaint with the supervisory authority responsible for the controller.
(2) Insofar as the processing is based on the consent of the data subjects, the data subjects may revoke their consent at any time with effect for the future; for example, by informal message to one of the above-mentioned contact channels (Controller).
(3) Insofar as the processing is based on the pursuit of a legitimate interest, i.e. on Article 6 (1) sentence 1 lit. f GDPR, the data subjects may object to the processing at any time; for example, by informal message to one of the above-mentioned contact channels (Controller). If the objection is justified, the processing will be terminated. If the legitimate interest lies in direct marketing, the objection is always justified.
Transfer to countries outside the European Union
(1) If personal data is transferred to bodies outside the European Union, the controller must communicate supplementary safeguards pursuant to Article 44 et seq. GDPR.
(2) If the controller refers in the following privacy statement to a so-called adequacy decision, this means that the receiving body is located in a country, territory, or specific sector for which the EU Commission has decided that it offers an adequate level of data protection. The safeguard then follows from Article 45 GDPR.
(3) If the controller refers in the following privacy statement to the so-called EU Standard Contractual Clauses, this means that the receiving body has contractually committed itself to respecting the EU data protection principles, and this on the basis of the so-called EU Standard Contractual Clauses. The safeguard then follows from Article 45 GDPR.
(4) If the controller refers in the following privacy statement to so-called binding corporate rules, this means that the competent supervisory authority has approved the transfer. The safeguard then follows from Article 47 GDPR.
(5) If the controller refers in the following privacy statement to the fact that the data subjects have expressly consented to the transfer to a country outside the European Union, this means that they nevertheless consent to the transfer in full knowledge of all associated risks. The safeguard then follows from Article 49 (1) lit. a GDPR. In this context, we point out the following risks: In the USA, the Republic of India, and the Russian Federation, no data protection law comparable to the GDPR has been codified. The state authorities there have granted themselves extensive data access, whereby the principle of proportionality regulated in the EU is not applied. Furthermore, there is no effective legal protection for EU citizens in these countries.
(6) The above notices are provided only as a precaution. They apply only if and insofar as reference is made to them in the following privacy statement.
Further notices
(1) Automated decision-making, including profiling, does not take place.
(2) A legal obligation to process exists only insofar as reference is made below to Article 6 (1) sentence 1 lit. c GDPR.
Processing of data in the initiation phase.
(1) The controller receives the data from the initial contact. The legal basis is Article 6 (1) sentence 1 lit. b GDPR. According to this, the processing is permissible even without consent, as it serves the initiation, performance, and/or termination of a contractual relationship. In this case, the data will be deleted as soon as the respective purpose has been fulfilled, unless other legal bases and reasons for retention prevent this.
(2) In this phase of processing, the controller uses the following third-party providers, which it has commissioned pursuant to Article 28 GDPR:
- An external tax consultancy firm is entrusted with the bookkeeping. Insofar as data is processed there, this does not constitute processing on behalf (cf. DSK Short Paper 13), but a data transfer, which in turn is justified by Article 6 (1) sentence 1 lit. f GDPR.
- The cloud tool "Google Workspace" and the downstream tool "Google Docs" of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4 (Ireland) are used, whereby data traffic with Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 (USA) cannot be ruled out. The provider was commissioned pursuant to Article 28 GDPR. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The project management tool "Asana" of Aana Inc., 1550 Bryant St #200, San Francisco, CA 94103, 6399 (USA) is used. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The CRM tool "HubSpot" of HubSpot, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- In connection with automation, the interface tool "Zapier" of Zapier, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. Further details on the manner of processing by this third-party provider are described here: https://zapier.com/how-it-works. In short: With Zapier, the controller can connect applications so that customer and prospect data can be exchanged automatically between the various applications. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The accounting tool "Lexoffice" of Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg (Germany) is used. The provider was commissioned pursuant to Article 28 GDPR.
- The customer service tool "Zendesk" of Zendesk, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The video communication tool "Loom" of Loom, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The project management tool "Slack" of Slack Technologies Limited (Ireland – EU) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that it cannot be ruled out that Slack Technologies Inc. (USA) obtains access to the data. For it has committed itself in accordance with the EU Standard Contractual Clauses.
- The online fax service sipgate of sipgate GmbH (Germany) is used, in that fax messages are received and sent there in the context of contract-related communication.
- The feedback tool "Leapsome" of Leapsome GmbH (Germany) is used.
- The signature tool "PandaDoc" of Pandadoc, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. Further details on the manner of processing by this third-party provider are described here: https://www.pandadoc.com/de/electronic-signature-software/. The commissioning of this provider is also not precluded by the fact that it is based outside the European Union. For the processing of personal data takes place only if the data subjects consent to the associated data transfer to the USA (cf. Article 49 (1) lit. a GDPR). In this respect, the risk notices mentioned above (Basic information / Transfer to countries outside the European Union) are decisive.
- The platform tool "KAJABI" of Kajabi LLC (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The chat software "Miro" of RealtimeBord, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The following payment service providers are used:
- elopage GmbH (Germany).
- easybill GmbH (Germany).
- Fino Data Services GmbH (Germany). The processing is not precluded by the fact that it cannot be ruled out that GetMyInvoices Inc. (USA) can also access the data. For the providers act as independent controllers, so that no transfer within the meaning of Article 44 GDPR takes place on our part.
- We work with Mark Becker IT-Dienstleistungen e. K. to increase the efficiency of our marketing and sales activities. Mark Becker IT-Dienstleistungen e. K. helps us analyze user data, in particular when there are changes to contacts in the CRM system. Your personal data is not stored on the servers of Mark Becker IT-Dienstleistungen e. K. All data transfers take place in encrypted form to protect your privacy.
Processing of data in the phase of the active contractual relationship.
(1) The controller processes all data required for the performance of the contractual relationship, in particular for the fulfillment of its contractual obligations. The legal basis is Article 6 (1) sentence 1 lit. b GDPR. According to this, the processing is permissible even without consent, as it serves the initiation, performance, and/or termination of a contractual relationship.
(2) Furthermore, the controller stores all tax and commercial law information (here, the invoice and delivery data) arising from the conduct of the data subjects. The legal basis is Article 6 (1) sentence 1 lit. c GDPR in conjunction with § 147 AO (German Fiscal Code), § 257 HGB (German Commercial Code). According to this, the processing is permissible even without your consent, as the controller in this case fulfills its legal obligation to retain the data in accordance with tax and commercial law provisions. Accordingly, there is an obligation:
- to retain data about the data subjects arising from books and records, inventories, annual financial statements, individual financial statements pursuant to § 325 (2a) HGB, consolidated financial statements, management reports and group management reports, opening balance sheets, accounting vouchers, documents pursuant to Article 15 (1) and Article 163 of the Union Customs Code, commercial books, as well as the work instructions and other organizational documents necessary for their understanding, for ten years, whereby the retention period generally begins at the end of the calendar year in which the relevant document was created (Article 6 (1) sentence 1 lit. c GDPR in conjunction with § 147 AO or in conjunction with § 257 HGB),
- to retain data about the data subjects arising from commercial or business letters received, from reproductions of the commercial or business letters received, as well as from other documents relevant for taxation, for six years, whereby the retention period generally begins at the end of the calendar year in which the relevant document was created (Article 6 (1) sentence 1 lit. c GDPR in conjunction with § 147 AO or in conjunction with § 257 HGB).
After expiry of the periods, all data will be deleted, unless other legal bases and reasons for retention prevent this. Data processed on the basis of consent will be deleted by the controller as soon as the consent is revoked (Article 6 (1) sentence 1 lit. c GDPR in conjunction with Article 5 (1) lit. e GDPR).
(3) The controller will use the name, the e-mail address, order-related communication content, and information on reading and click behavior to address the data subjects for advertising purposes. The advertising contact takes place by e-mail. In terms of content, the advertising contact comprises any statement made by the controller in the exercise of its specific trade with the aim of promoting the sale of its goods or the provision of its services. This includes in particular, but not exhaustively, regular and irregular newsletters, invitations, customer satisfaction surveys, and offers for specific products and services. Furthermore, the advertising contact includes the controller being permitted to draw the data subjects' attention by e-mail to the free and paid products and services offered by its cooperation partners. In doing so, the data is not transferred to these cooperation partners. Rather, the controller merely recommends their products to the data subjects, whereby it can edit these messages itself. Here, Article 6 (1) sentence 1 lit. f GDPR is the legal basis. According to this, the controller may process the data of the data subjects for advertising purposes even without your consent. Its legitimate interest follows from the fact that a contractual relationship exists between it and the data subjects, from the fact that it has informed the data subjects about this in advance, and from the fact that the data subjects can object to processing for advertising purposes at any time and without giving reasons. In this context, the data subjects are advised that they may object to the use at any time, without incurring any costs other than the transmission costs according to the basic rates.
(4) In this phase of processing, the controller uses the following third-party providers, which it has commissioned pursuant to Article 28 GDPR:
- An external tax consultancy firm is entrusted with the bookkeeping. Insofar as data is processed there, this does not constitute processing on behalf (cf. DSK Short Paper 13), but a data transfer, which in turn is justified by Article 6 (1) sentence 1 lit. f GDPR.
- The cloud tool "Google Workspace" and the downstream tool "Google Docs" of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4 (Ireland) are used, whereby data traffic with Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 (USA) cannot be ruled out. The provider was commissioned pursuant to Article 28 GDPR. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The project management tool "Asana" of Aana Inc., 1550 Bryant St #200, San Francisco, CA 94103, 6399 (USA) is used. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The CRM tool "HubSpot" of HubSpot, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- In connection with automation, the interface tool "Zapier" of Zapier, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. Further details on the manner of processing by this third-party provider are described here: https://zapier.com/how-it-works. In short: With Zapier, the controller can connect applications so that customer and prospect data can be exchanged automatically between the various applications. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The accounting tool "Lexoffice" of Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg (Germany) is used. The provider was commissioned pursuant to Article 28 GDPR.
- The customer service tool "Zendesk" of Zendesk, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The project management tool "Slack" of Slack Technologies Limited (Ireland – EU) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that it cannot be ruled out that Slack Technologies Inc. (USA) obtains access to the data. For it has committed itself in accordance with the EU Standard Contractual Clauses.
- The online fax service sipgate of sipgate GmbH (Germany) is used, in that fax messages are received and sent there in the context of contract-related communication.
- The feedback tool "Leapsome" of Leapsome GmbH (Germany) is used.
- The signature tool "PandaDoc" of Pandadoc, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. Further details on the manner of processing by this third-party provider are described here: https://www.pandadoc.com/de/electronic-signature-software/. The commissioning of this provider is also not precluded by the fact that it is based outside the European Union. For the processing of personal data takes place only if the data subjects consent to the associated data transfer to the USA (cf. Article 49 (1) lit. a GDPR). In this respect, the risk notices mentioned above (Basic information / Transfer to countries outside the European Union) are decisive.
- The platform tool "KAJABI" of Kajabi LLC (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The chat software "Miro" of RealtimeBord, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The following payment service providers are used:
- elopage GmbH (Germany).
- easybill GmbH (Germany).
- Fino Data Services GmbH (Germany). The processing is not precluded by the fact that it cannot be ruled out that GetMyInvoices Inc. (USA) can also access the data. For the providers act as independent controllers, so that no transfer within the meaning of Article 44 GDPR takes place on our part.
Processing of data after the end of the contractual relationship.
(1) After the end of the contractual relationship, the controller retains the data. The legal basis is Article 6 (1) sentence 1 lit. c GDPR in conjunction with § 147 AO (German Fiscal Code), § 257 HGB (German Commercial Code). According to this, the processing is permissible even without consent, as the controller in this case fulfills its legal obligation to retain the data in accordance with statutory provisions. Accordingly, there is an obligation:
- to retain data about the data subjects arising from books and records, inventories, annual financial statements, individual financial statements pursuant to § 325 (2a) HGB, consolidated financial statements, management reports and group management reports, opening balance sheets, accounting vouchers, documents pursuant to Article 15 (1) and Article 163 of the Union Customs Code, commercial books, as well as the work instructions and other organizational documents necessary for their understanding, for ten years, whereby the retention period generally begins at the end of the calendar year in which the relevant document was created (Article 6 (1) sentence 1 lit. c GDPR in conjunction with § 147 AO or in conjunction with § 257 HGB),
- to retain data about the data subjects arising from commercial or business letters received, from reproductions of the commercial or business letters received, as well as from other documents relevant for taxation, for six years, whereby the retention period generally begins at the end of the calendar year in which the relevant document was created (Article 6 (1) sentence 1 lit. c GDPR in conjunction with § 147 AO or in conjunction with § 257 HGB).
After expiry of the periods, all data will be deleted, unless other legal bases and reasons for retention prevent this. Data processed on the basis of consent will be deleted by the controller as soon as the consent is revoked (Article 6 (1) sentence 1 lit. c GDPR in conjunction with Article 5 (1) lit. e GDPR).
(2) In this phase of processing, the controller uses the following third-party providers, which it has commissioned pursuant to Article 28 GDPR:
- An external tax consultancy firm is entrusted with the bookkeeping. Insofar as data is processed there, this does not constitute processing on behalf (cf. DSK Short Paper 13), but a data transfer, which in turn is justified by Article 6 (1) sentence 1 lit. f GDPR.
- The cloud tool "Google Workspace" and the downstream tool "Google Docs" of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4 (Ireland) are used, whereby data traffic with Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 (USA) cannot be ruled out. The provider was commissioned pursuant to Article 28 GDPR. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The project management tool "Asana" of Aana Inc., 1550 Bryant St #200, San Francisco, CA 94103, 6399 (USA) is used. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The CRM tool "HubSpot" of HubSpot, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- In connection with automation, the interface tool "Zapier" of Zapier, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. Further details on the manner of processing by this third-party provider are described here: https://zapier.com/how-it-works. In short: With Zapier, the controller can connect applications so that customer and prospect data can be exchanged automatically between the various applications. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The accounting tool "Lexoffice" of Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg (Germany) is used. The provider was commissioned pursuant to Article 28 GDPR.
- The customer service tool "Zendesk" of Zendesk, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The video communication tool "Loom" of Loom, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The project management tool "Slack" of Slack Technologies Limited (Ireland – EU) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that it cannot be ruled out that Slack Technologies Inc. (USA) obtains access to the data. For it has committed itself in accordance with the EU Standard Contractual Clauses.
- The online fax service sipgate of sipgate GmbH (Germany) is used, in that fax messages are received and sent there in the context of contract-related communication.
- The feedback tool "Leapsome" of Leapsome GmbH (Germany) is used.
- The signature tool "PandaDoc" of Pandadoc, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. Further details on the manner of processing by this third-party provider are described here: https://www.pandadoc.com/de/electronic-signature-software/. The commissioning of this provider is also not precluded by the fact that it is based outside the European Union. For the processing of personal data takes place only if the data subjects consent to the associated data transfer to the USA (cf. Article 49 (1) lit. a GDPR). In this respect, the risk notices mentioned above (Basic information / Transfer to countries outside the European Union) are decisive.
- The platform tool "KAJABI" of Kajabi LLC (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The following payment service providers are used:
- elopage GmbH (Germany).
- easybill GmbH (Germany).
- Fino Data Services GmbH (Germany). The processing is not precluded by the fact that it cannot be ruled out that GetMyInvoices Inc. (USA) can also access the data. For the providers act as independent controllers, so that no transfer within the meaning of Article 44 GDPR takes place on our part.
Processing in the event of a sale of the company by way of spin-off or merger.
(1) There is the possibility that the controller's company or parts of it may undergo changes under company law. In this context, the controller has, among other things, the possibility of reorganizing itself by selling parts of the company (spin-off) or by combining with other companies (merger). In a spin-off, it continues to exist as a company and transfers part of its assets to one or more other, already existing or new legal entities. In a merger, it transfers its entire company to another legal entity, either already existing or to be newly founded.
(2) Regardless of which variant of the change under company law the controller chooses, there is the possibility that the data it stores will be transferred along with it to the respective new legal entity, possibly also for remuneration. There is even the possibility that this is the main reason for the change under company law and a significant, price-determining factor.
(3) However, the consent of the data subjects is not required for the transfer of data described in paragraph 2. For the data protection principle according to which any processing of personal data requires a legal basis is not applicable to this transfer. This legal principle, which derives from Article 5 (1) lit. a GDPR, requires processing of the data. What could be considered here is a disclosure by transmission, dissemination, or another form of making available. But the elements "transmission", "dissemination", as well as "making available in another form" all presuppose that the data leaves the controller and reaches a body outside the controller. And in the case of a spin-off or merger, the new legal entity would not be a third party within the meaning of Article 4 (10) GDPR with regard to the data.
Processing in the event of a sale of the company by way of an asset deal.
(1) There is the possibility that the controller's company or parts of it may undergo changes under company law. In this context, there would be the possibility of a so-called asset deal. An asset deal is understood to mean the acquisition of a company through the transfer of its respective assets, i.e. when companies are "bought".
(2) If, at the time of the transfer of the data, the controller still has contractual obligations towards the data subjects relating to the use of its products and services, the processing of personal data associated with the asset deal is justified by Article 6 (1) sentence 1 lit. f GDPR. According to this provision, the processing involved is permissible if it is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. Such a processing interest exists here. The question of whether such an interest exists is to be measured against the purpose of the processing and must, on the one hand, take into account legal, economic, and non-material interests and, on the other hand, be interpreted broadly, taking into account (Union) fundamental rights. Here, the interest that the controller's customers continue to be served even after the asset deal is decisive. This also corresponds to the interest of the data subjects. Of course, they can object to this processing at any time, by informal message to one of the above-mentioned contact channels ("Controller").
(3) If, at the time of the transfer of the data, the controller has already fulfilled all contractual obligations towards the data subjects, the transfer of the data will only take place insofar as there are post-contractual obligations or it is likely that the data subjects may still have queries. For then the processing of your personal data associated with the asset deal is justified by Article 6 (1) sentence 1 lit. f GDPR. The interest here follows from the fact that there is a transfer interest in the potential fulfillment of post-contractual obligations and queries on the part of the data subjects.
(4) The controller reserves the right to additionally request consent from the data subjects if other cases of data transfer for the purpose of carrying out a reorganization under company law come into consideration. In this respect, it processes the contact data of the data subjects in order to ask them for their consent to the transfer. The legal basis for this processing is Article 6 (1) sentence 1 lit. c GDPR. According to this provision, the controller may process the data if this is necessary to fulfill a legal obligation to which it is subject. The legal obligation here follows from Article 7 (1) GDPR and Article 5 (1) GDPR. For according to these provisions, the controller is legally obligated to document the obtaining of consent. It stores the data on the status of the consent for as long as this is necessary for evidentiary purposes.