Privacy Policy
As of: 9 September 2026 · Version 6.0
This translation is provided for convenience. The German version is authoritative.
1. Controller and contact
The controller is BenchTrust GmbH, Lange Straße 75, 76530 Baden-Baden, Germany. Managing directors: Bernd Burkhardt and Holger Schmeding. Mannheim Local Court, HRB 758170. Contact: contact@benchtrust.com. Privacy requests: datenschutz@benchtrust.com.
This policy covers www.benchtrust.com and its BenchTrust functions. Linked external services and separate portals have their own notices. Internal administration access is additionally covered by internal privacy information.
2. Website, hosting and technical logs
Website delivery processes necessary access data, including IP address, time, resource, HTTP status, transferred volume and technical request information. This serves delivery, security and abuse prevention under Art. 6(1)(f) GDPR; our legitimate interest is secure operation.
We use Firebase Hosting, Google Cloud, Firestore and Cloud Storage. The server-side framework backend is configured for europe-west1 (Belgium). This does not mean all data remains in Belgium or the EU: hosting, authentication and other Google services may have other processing locations.
Operational and security logs are needed only for operation, troubleshooting, abuse prevention and necessary legal defence. Provider retention is distinct: Firebase describes a few months for hosting IP data and a few weeks for authentication IP logs. We do not promise a uniform 14-day deletion period for all Google logs.
Fonts and owned videos are delivered through our hosting infrastructure. Loading fonts does not contact Google Fonts. IONOS SE provides email/SMTP.
3. Consent and homepage personalization
Without consent we access or store device information only when strictly necessary for an explicitly requested service (§ 25(2) no. 2 TDDDG). A functional label alone is not an exemption. Processing personal data additionally requires a GDPR basis.
With voluntary consent to Homepage personalization, we remember only in your browser whether it has visited BenchTrust. The first considered visit shows the homepage. A later independent visit to / opens provider search at /tm-tech when required browser functions are available. Visits before consent are not counted retrospectively.
bt_home_visit contains only format version, first considered visit, last activity and fixed expiry timestamps. No names, contact details or unique visitor, user or session identifier. We use no fingerprinting or IP-, ETag-, cache- or user-agent-based recognition.
The visit state is not sent to the backend, analytics or third parties, linked to server logs, accounts, forms, leads or other data, or used for analytics, audience measurement, advertising, profiling or further personalization. This concerns the local visit state, not requests needed to deliver the website or chosen functions.
A new visit starts no earlier than after 30 minutes of inactivity. Reload, history and internal navigation do not trigger returning-visit redirection. Additional tabs during a visit share activity state. An idle tab left open does not prevent a new independent visit after inactivity. Deep links remain unchanged; an explicit Home click always shows the homepage. No permanent personalized 301 redirect is used.
Storage/access relies on § 25(1) TDDDG. Where personal-data processing cannot be excluded, Art. 6(1)(a) GDPR also applies. Without consent the visit state is neither stored nor read. The entire website, including provider search, remains usable.
Consent is not preselected. The first level offers equally presented Allow personalization, Required only and Settings actions. Closing or Escape is not consent. Cookie settings in the footer allow change or withdrawal at any time. Withdrawal immediately removes bt_home_visit and disables recognition; earlier lawful processing is unaffected.
Necessary consent management stores decision, decision/expiry timestamps, text and format versions separately in bt_home_consent solely to respect your choice (§ 25(2) no. 2 TDDDG; where necessary Art. 6(1)(f) GDPR). No identifier or transmission. Withdrawal replaces approval with rejection. Each explicit choice lasts up to 90 days, without extension by activity. Expiry or a changed required text version requires fresh explicit approval.
Visit state expires within 90 days and never later than consent. It is no longer read or used for recognition after expiry, and the browser is treated as first-time again. Active pages delete by timer. A closed browser or suspended page cannot execute deletion; physical removal then occurs on the next visit or resumption. Local Storage has no native expiry mechanism.
4. Functional storage and media
Depending on chosen functions, language, shortlist, comparison, filters, criteria and assessment progress are stored in the browser. They serve the requested function and are not linked to homepage visit state. The inventory below lists technical retention. Homepage consent does not cover other purposes.
Owned videos and previews are delivered through our hosting. External provider videos appear only as links without external thumbnails or embedded players. Only opening a link visits the external service under its own terms; these links send no referrer. We create no personal playback statistics.
Cookie settings manage homepage personalization only, not deletion of accounts, shortlist, comparison or project information. You can also remove browser data in browser settings, which may remove saved functional state.
5. Contact
We process supplied contact details, messages, documents and subsequent communication to handle your request. Art. 6(1)(b) GDPR applies to your own contractual/precontractual requests; Art. 6(1)(f) normally applies when communicating for a company. Our interest is handling communication properly.
Required information is identified; without it the requested service may not be possible. Optional details may be omitted. Unneeded request data is removed after completion unless follow-up communication, statutory retention or necessary legal defence requires it.
6. Administration, platform and documents
Admin Login is intended for internal or expressly authorized people, not ordinary visitor registration. Firebase Authentication is initialized through login/dashboard functions, not pre-emptively by the public AppProvider. An existing browser session may remain after using protected access.
Email/password or Google login involves authentication information, identifiers and security data. BenchTrust also uses the HttpOnly __session cookie. Google describes Firebase Authentication as operating exclusively in the USA. Authentication information is retained until customer-initiated account deletion, with removal from live/backup systems potentially taking up to 180 days according to Google; security IP logs last a few weeks.
Authorized access relies on Art. 6(1)(f) GDPR and, where applicable, § 26(1) BDSG, for secure attribution and permissions. Necessary session storage relies on § 25(2) no. 2 TDDDG. Authorization is revoked when no longer needed and account data removed under internal deletion procedures.
Platform functions process supplied requirements, company, profile, project, document and request data and resulting analyses, comparisons and reports. Art. 6(1)(b) applies to own contracts and Art. 6(1)(f) to representatives of company customers; our interest is delivering requested services. Content is retained for use and necessary completion, subject to legal obligations and defence.
Administrators can upload PDF, CSV and XLSX files for text extraction. This process does not permanently store original files, but adopted text may become stored provider knowledge used by AI. Do not submit special-category personal data, unnecessary third-party information or confidential content.
7. Profiles, scores, Showcase and Promotion
BenchTrust presents companies and products. Company scores use product, catalogue, company and review information, not personal contact details as scoring features. They are not assessments of natural persons’ creditworthiness or solely automated decisions with legal effects on them.
Showcase and Promotion provide enhanced/highlighted provider profiles. Paid placements must be identified. Profile, company, contract and billing data support these services, without personal visitor profiles or placement-delivery statistics.
Art. 6(1)(b) applies to own contracts and Art. 6(1)(f) to company representatives. Our interest is a comprehensible market overview and delivery of purchased services.
8. Listed contacts and provider acquisition
Business contacts may originate from company websites, public registers/directories, publications, company submissions and Apollo.io. Data includes name, role, company, business contact details, source and currency. Purposes are accurate company presentation and our own B2B provider acquisition under Art. 6(1)(f) GDPR after balancing interests.
Apollo is both source and recipient of search parameters: company domains, requested roles and Apollo person IDs. Customer enquiries, RFP content and platform projects are not submitted for this purpose. A research request nevertheless transfers its search parameters.
For indirectly obtained personal data, Art. 14 information is generally provided within one month, earlier at first communication or disclosure where applicable. Exceptions require documented individual assessment. Advertising uses only legally permissible channels under § 7 UWG.
Unneeded or demonstrably inaccurate contacts are removed/corrected. You can object to direct marketing at any time. Necessary minimum suppression-list data may remain solely to respect the objection, not for further advertising.
9. RFPs and requested analyses
When you expressly request an enquiry, contact transfer or analysis, we process the business contact and requirement data you release. Transfer is only to recipients shown before submission and selected by you, who then handle the enquiry under their own responsibility.
Analysis/RFP requests may store name, email, company, optional contact/company details, selected providers, criteria, goals, notes, verification/processing status and report data. This is entirely separate from local homepage personalization and uses its own request identifiers.
Art. 6(1)(b) applies to own contracts and Art. 6(1)(f) to company representatives. Our interest is requested business contact and delivery. After completion, unnecessary data is removed unless required for completion, legal obligations or defence. Verification-code validity is not the deletion period for the underlying request.
10. Payments
Paid services process contract, invoice, payment and transaction-status information. Stripe Payments Europe, Ltd., Ireland, provides payments as processor or, depending on function, independent controller for legal and fraud-prevention purposes. BenchTrust receives information required for attribution, billing and reversal.
Art. 6(1)(b) covers contracts and Art. 6(1)(c) statutory retention. Invoices/accounting vouchers generally last eight years, books/financial statements ten years and business correspondence six years, subject to document type and applicable law.
11. AI functions and transfers
AI supports provider questions, requirements/offer analysis, RFPs, comparisons and editorial research. Inputs, professional context, provider information, extracted document text and responses are processed. Art. 6(1)(b) covers requested own contractual services and Art. 6(1)(f) company representatives; our interest is providing the requested function.
We use the Gemini API under paid API use. In provider chat Gemini receives the current question, up to five previous messages, provider knowledge and website research. Other functions have their own context, such as up to twenty previous messages in the purchasing assistant. These flows do not use direct Gemini Files uploads or explicitly created Gemini Context Caches.
Under Paid Services terms Google does not use prompts/responses to improve its products, but describes limited content logging for safety, abuse prevention and required legal disclosures, plus technical usage metadata. We do not promise enabled Zero Data Retention or EU-only processing.
Internal editorial research uses Google Search Grounding. Gemini API terms provide for Google retaining prompts, context and output for 30 days for delivery, debugging and testing supporting Grounding systems. This provider retention is separate from BenchTrust storage.
Perplexity Sonar API with sonar-pro researches public sources. Provider chat sends it the current full question, provider name, domain/website context and optionally an official document link, not previous chat messages. Results and citations then support the Gemini response. Provider processing follows Sonar terms; we do not promise blanket non-retention of all technical metadata.
AI results may be inaccurate and require appropriate human review before consequential use. No solely automated decisions with legal or similarly significant effects on natural persons take place. Do not submit special-category data or unnecessary information about others.
12. AI storage, statistics and events
The displayed provider-chat history stays in memory while the chat view is open; it is not limited to five messages there. Only context transfer per request is limited. This flow has no separate permanent chat database and does not restore history after full reload. Production compilation removes application console calls; chat errors are handled without question/answer contents.
Operation/cost control may store API metadata: service, fixed endpoint, input/output length, success, fixed error code and timestamp. Research jobs store status, progress, counts and fixed messages rather than full answers. New records have expiry after 14 days; physical removal uses the configured cleanup procedure. Any legally/security-required extended retention must be separately justified.
AI content may become part of expressly stored profiles, analyses, RFPs, editorial drafts, published articles and versions. It would therefore be incorrect to claim that BenchTrust never stores AI input or output.
Google Analytics 4, previous browser event tracking, Sentry Session Replay and Sentry runtime telemetry are disabled. They create no new visitor identifiers or analytics events. Necessary hosting, authentication, security and business-operation data is unaffected. Historic identifiers are handled only for removal, not for new personalization.
13. Recipients and international transfers
Only people and providers needing data for the identified tasks receive access. Processors are bound under Art. 28 GDPR. Selected providers, payment services and Google-account functions may involve independent responsibility for further processing.
Data may be processed outside the EEA. Covered transfers to appropriately certified US recipients may rely on the EU-US Data Privacy Framework adequacy decision; other transfers require safeguards such as EU standard contractual clauses and necessary supplementary measures. Request the service-specific basis and a copy of safeguards at datenschutz@benchtrust.com. A German contracting partner or EU backend does not exclude international processing.
14. Retention, deletion and complaints
Personal data is deleted or anonymized when no longer needed. Required data for open matters, legal retention or defence remains purpose-restricted. Criteria include completion, end of authorization/use, statutory periods and limitation periods. Browser periods appear below; provider periods are explained particularly in sections 2, 6 and 11.
Complaints and disputes involve contact, content, evidence, communication and decisions. Art. 6(1)(c) applies to legal duties and Art. 6(1)(f) to platform protection and legal claims/defence. Retention follows the procedure and necessary remedy/limitation periods.
15. Your rights
Subject to legal requirements you have rights to access (Art. 15 GDPR), correction (16), erasure (17), restriction (18), recipient notification (19) and portability (20). Consent can be withdrawn prospectively under Art. 7(3). Contact datenschutz@benchtrust.com.
You may object on grounds relating to your situation to processing based on Art. 6(1)(f). You may object to direct marketing and related profiling at any time without reasons; data will no longer be used for that advertising.
You can complain to a supervisory authority, including the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg, Heilbronner Straße 35, 70191 Stuttgart, www.baden-wuerttemberg.datenschutz.de.
16. Security and changes
We use risk-appropriate technical and organizational safeguards under Art. 32 GDPR, including access restrictions, transport encryption and incident procedures, reviewed against technology, purposes and risks. No technology guarantees absolute security.
We update this policy when functions, data flows, providers or legal requirements change and communicate significant changes appropriately. The date above identifies this version.
Annex 1: Browser storage and retention
| Name / technology | Content and purpose | Retention / deletion |
|---|---|---|
| bt_home_consent / Local Storage | version, consentTextVersion, decision, decidedAt, expiresAt; local consent management only | 90 days from explicit choice. Withdrawal replaces approval with fresh rejection; expiry cleanup as in section 3. |
| bt_home_visit / Local Storage | version, firstVisitAt, lastActivityAt, expiresAt; homepage personalization | Up to 90 fixed days, no later than consent. Immediate deletion on withdrawal; no use after expiry, physical cleanup on an active website. |
| __session / HttpOnly cookie | Authorized administrator login, not visitor recognition | Public app: cookie maximum 7 days; token may expire earlier. Logout removes it. |
| Firebase Auth / IndexedDB or SDK fallback | firebaseLocalStorageDb, firebase:authUser:<API-Key>:<App-Name>; authorized login | SDK persistence until logout/deletion or according to mode. No new anonymous BenchTrust visitor ID. |
| NEXT_LOCALE / cookie | Website language | Session cookie; possible browser session restoration. |
| sidebar_state / cookie | Navigation display | 7 days where that sidebar is used. |
| benchtrust-shortlist, benchtrust-comparison-list, benchtrust.shortlist.v1 / Local Storage | Selected providers for shortlist/comparison | Until removed/cleared or browser-data deletion; no automatic expiry in the existing format. Empty main lists are not newly stored. |
| bt-assessment-<category>, bt-healthcheck-<ID> / Local Storage | Requested assessment progress | Until reset/browser-data deletion; no automatic expiry in the existing format. |
| tm-tech-filters, tm-tech-criteria, tm-service-filters, tm-service-criteria, benchtrust:provider-list-search:<domain> / Session Storage | Filters, criteria and search return navigation | Tab session; browser session restoration may retain it. |
| benchtrust.taxonomy.v1, benchtrust.quick-setup.draft, dashboard.nav.openState.v1/.v2 / Local Storage | Functional data, setup drafts and internal navigation | Until removal/browser-data deletion; internal access, not linked to visit state. |
Annex 2: Providers and recipients
| Recipient | Service / data | Location and responsibility |
|---|---|---|
| Google Ireland Ltd. / Google LLC: Firebase and Google Cloud | Hosting, database, files, backend, Secret Manager, authorized authentication and operational data | EU backend; global services/hosting, USA authentication. Processor and separate service/account processing under product terms. |
| Google: Gemini API | Questions, context, provider knowledge and answers; internal Search Grounding | Global infrastructure including USA. Content processing under Paid Services processor terms; technical account data under separate terms. |
| Perplexity AI, Inc.: Sonar API | Current research question and provider/website context | USA and contracted infrastructure; processing under Sonar contract. |
| Apollo.io | Company/contact research; domain, roles and Apollo person IDs | Source and recipient of search parameters; US provider under its contractual processing terms. |
| IONOS SE | Transactional email, contacts and requested reports | Germany/EU; email/SMTP processor. |
| Stripe Payments Europe, Ltd. | Payment, contract and billing data | Ireland and international group/provider processing; processor or independent controller according to function. |
| Providers you select | RFP/contact data displayed before sending | Selected provider’s location and processing; independent responsibility for the enquiry. |