Effective Date: September 2026
Jurisdiction: Federal Republic of Germany | Applicable Law: GDPR (Regulation (EU) 2016/679), German Federal Data Protection Act (BDSG), German Commercial Code (HGB), and German Tax Code (AO)
This Data Privacy Policy governs the collection, storage, processing, disclosure, and protection of personal data of all users, clients, visitors, and business partners accessing or utilizing the workspace platform, software, and related service offerings operated by Amkovoy. It is drafted in full compliance with European and German data protection statutory requirements, replacing all prior informal privacy statements and constituting a legally binding contractual supplement to our service terms.
1. Data Controller Identity & Official Contact Information
In accordance with Article 4(7) GDPR and § 5 BDSG, the sole data controller for all personal data processing activities herein is:
Amkovoy
Vlattenstraße 8, 40223 Düsseldorf-Stadtbezirk 3, Germany
Phone: +49 21124863336
Email: support@amkovoy.com
Website: amkovoy.com
For all data protection inquiries, subject right requests, and compliance communications, users shall exclusively contact the above official channels. No third-party individual or entity is authorized to act on behalf of the controller for data protection matters.
2. Scope of Application & Service Classification
This policy applies to all Workspace product and service scenarios provided by Amkovoy, including but not limited to cloud workspace management, online office collaboration tools, user account management, business operation support, customer technical support, and official website interactive services. It covers personal data processing of all natural persons who interact with our services, including registered users, trial users, enterprise clients’ employees, website visitors, and consulting partners.
This policy does not apply to anonymized or fully pseudonymized data that cannot be linked to an identifiable natural person under any technical or legal means.
3. Legal Basis for Personal Data Processing
All data processing activities are strictly based on valid legal grounds specified in Article 6 GDPR and relevant German national laws, without arbitrary processing beyond legal authorization:
- Contract Performance (Art. 6(1)(b) GDPR): Processing necessary for the performance of workspace service contracts, including account registration, service activation, function provision, order fulfillment, and after-sales support.
- Legitimate Interest (Art. 6(1)(f) GDPR): Processing for reasonable business operation needs, including service optimization, user experience improvement, security risk prevention, and legitimate business communication, provided that such interests do not override users’ fundamental data protection rights.
- Legal Compliance (Art. 6(1)(c) GDPR): Processing to fulfill statutory legal obligations under German commercial, tax, and regulatory laws, including mandatory data retention and compliance verification.
- Explicit Consent (Art. 6(1)(a) GDPR): Processing based on voluntary, specific, and informed user consent for non-mandatory service scenarios; consent may be withdrawn at any time with future effect.
4. Categories of Collected & Processed Personal Data
We only collect data that is necessary for the aforementioned service and compliance purposes, with no excessive data collection:
- Basic User Identification Data: Name, email address, contact phone number, job title (enterprise users), and user account credentials.
- Service Operation Data: Workspace usage records, function operation logs, service subscription information, and technical interaction data with the platform.
- Communication Data: Content of technical support consultations, business correspondence, and user feedback records.
- Statutory Compliance Data: Business transaction records, invoicing information, and other data required for German commercial and tax compliance.
5. Purpose of Data Processing
All personal data shall only be processed for the following explicit and limited purposes:
- To provide, maintain, update, and optimize the core functions of Amkovoy Workspace products and services;
- To verify user identity, manage user accounts, and ensure secure and standardized service access;
- To respond to user consultation, technical support, and service request demands;
- To fulfill statutory retention, tax filing, and commercial record-keeping obligations under German law;
- To prevent service risks, maintain platform security, and resist illegal or improper use of services;
- To conduct non-intrusive service optimization analysis based on pseudonymized data.
6. Data Retention & Erasure Rules
We implement tiered retention mechanisms in line with German HGB, AO statutory retention periods and GDPR minimization principles:
- Business & Tax Documents: Retained for 8 years in compliance with §147 AO and §257 HGB;
- General Commercial Correspondence & Service Records: Retained for 6 years as required by German commercial regulations;
- User Daily Usage Data: Automatically erased or fully pseudonymized within 12 months after service termination, unless legal retention obligations apply;
- Consent-Based Processing Data: Immediately ceased processing and erased after user consent withdrawal, subject to mandatory legal retention exceptions.
Upon the expiration of the retention period, all personal data will be permanently and securely erased or irreversibly anonymized to eliminate identification possibility.
7. User Data Subject Rights (GDPR & BDSG)
As a data subject, you hold the following enforceable rights under European and German data protection laws, which may be exercised free of charge by submitting a request via our official support email:
- Right of Access (Art. 15 GDPR): Request a full copy of your stored personal data and detailed processing records;
- Right of Rectification (Art. 16 GDPR): Demand correction of inaccurate or incomplete personal data;
- Right to Erasure (Right to be Forgotten, Art. 17 GDPR): Request permanent deletion of your data where processing is no longer lawful or necessary;
- Right to Restriction of Processing (Art. 18 GDPR): Suspend data processing during accuracy verification or legal dispute proceedings;
- Right to Data Portability (Art. 20 GDPR): Obtain your personal data in a machine-readable format for cross-platform transmission;
- Right of Objection (Art. 21 GDPR): Object to processing based on legitimate interest grounds, with legally defined exceptions;
- Right to Withdraw Consent (Art. 7 GDPR): Withdraw previously granted consent at any time, without retrospective impact on lawful past processing;
- Right to Lodge a Complaint (Art. 77 GDPR): File a complaint with the competent German data protection supervisory authority if you believe our processing violates applicable laws.
We will respond to all valid subject right requests within 30 calendar days; a maximum 60-day extension is permitted only for complex requests, with prior formal notification to the user.
8. Data Security & Sub-Processor Management
We adopt comprehensive technical and organizational security measures per Art. 32 GDPR to protect personal data against unauthorized access, disclosure, alteration, destruction, and leakage, including encryption storage, access permission control, regular security audits, and data backup mechanisms.
In the event of engaging third-party data sub-processors for service delivery, we will conduct strict qualification verification, sign standardized GDPR-compliant data processing agreements (DPAs), and fully supervise sub-processors’ data compliance behaviors. All sub-processing activities are limited to the scope authorized by this policy and applicable laws.
9. Cross-Border Data Transfer
Personal data collected via our workspace services is primarily stored and processed within the European Economic Area (EEA). Any cross-border data transfer to third countries outside the EEA will only be conducted if the target country possesses adequate data protection certification recognized by the European Commission, or we implement sufficient protective measures (including standard contractual clauses) to ensure equivalent data protection levels as required by GDPR.
10. Automated Decision-Making & Profiling
Amkovoy does not conduct unilateral automated decision-making or user profiling that produces legal or significant adverse effects on users. Limited technical data analysis for service optimization is fully pseudonymized and will not identify individual users or generate user-specific evaluation results.
11. Policy Update & Notification Mechanism
We reserve the right to update this policy to adapt to service adjustments, legal revisions, and regulatory requirements. Updated versions will be published on the official website amkovoy.com with a renewed effective date. Material changes affecting user core rights will be notified via official email or platform notice in advance. Continued use of our workspace services after policy updates constitutes acceptance of the revised terms.
12. Final Legal Provisions
This policy shall be governed by the laws of the Federal Republic of Germany, excluding conflict of law rules. Any disputes arising from data protection matters shall be subject to the exclusive jurisdiction of the competent courts and data protection authorities in Düsseldorf, Germany.
If any clause of this policy is deemed invalid or unenforceable due to legal revision, the validity of the remaining clauses shall remain unaffected.