Privacy Policy
for the websites and the BenchTrust platform
Privacy Policy for the Websites and the BenchTrust Platform
As of: July 2026 · Version 5.0
§ 1 Responsible Party and Data Protection Contact
Controller within the meaning of the General Data Protection Regulation (GDPR) is:
BenchTrust GmbH, Lange Straße 75, 76530 Baden-Baden, Germany
Represented by the managing directors Bernd Burkhardt and Holger Schmeding. Court of registration: Mannheim Local Court, HRB 758170. E-mail: contact@benchtrust.com.
Data protection contact: datenschutz@benchtrust.com.
Data Protection Officer
BenchTrust GmbH is not legally required to appoint a data protection officer (§ 38 para. 1 BDSG in conjunction with Art. 37 GDPR) and has therefore not appointed such a person. Compliance with data protection regulations is the responsibility of the management of BenchTrust GmbH.
For questions regarding the processing of your personal data as well as the exercise of your data subject rights, please contact the responsible party mentioned above directly:
E-mail: datenschutz@benchtrust.com
Mailing address: BenchTrust GmbH, Lange Straße 75, 76530 Baden-Baden
§ 2 Scope
(1) This privacy policy applies to the processing of personal data in connection with www.benchtrust.com, the forms offered there, and the BenchTrust platform, including the modules Analytics, Scores, Showcase, RFP, and Lead Engine.
(2) For external offers, to which only links are provided, the privacy notices of the respective provider apply. The terms used in this declaration correspond to Art. 4 of the GDPR.
Section 3 Principles and Legal Foundations
We process personal data only to the extent that there is a legal basis. In particular, the following are relevant:
- Art. 6 para. 1 lit. a GDPR — Consent;
- Art. 6 para. 1 lit. b GDPR — contract or pre-contractual measures, if the data subject is themselves a party to the contract;
- Art. 6(1)(c) GDPR — Fulfillment of legal obligations;
- Art. 6(1)(f) GDPR — legitimate interests after documented balancing of interests.
We pay particular attention to purpose limitation, data minimization, accuracy, storage limitation as well as integrity and confidentiality. Special categories of personal data according to Art. 9 GDPR should generally not be transmitted via the platform, unless this is expressly provided for and legally secured.
§ 4 Mandatory Information and Consequences of Non-Provision
To the extent that information is required for a contract, a desired contact initiation, or due to legal obligations, we cannot provide the relevant service without this information. Information marked as voluntary can be omitted without disadvantage.
§ 5 Websites, Hosting, Server Log Files and Local Fonts
(1) With each request, we process technical access data, in particular IP address, date and time, requested resource, amount of data transmitted, referrer, browser, device, and operating system information. The purpose is the secure, stable, and error-free provision. The legal basis is Art. 6 para. 1 lit. f GDPR; our legitimate interest lies in secure operation and in preventing abuse.
(2) Regular server log files are deleted after 14 days. In the case of specific security incidents, relevant log data may be stored separately until clarification, defense, and necessary legal prosecution.
(3) The websites are operated with the involvement of Vercel Inc. (hosting and function provision, processing region Frankfurt/fra1) and IONOS SE (email/SMTP, Germany). The exact allocation of roles, processing region, and third-country safeguards are specified in Annex 2.
(4) The web fonts we use are provided locally; no connection to Google Fonts is established.
§ 6 Cookies, local storage technologies and consent management
(1) We store or read information on end devices without consent only to the extent that this is strictly necessary for the explicitly requested digital service (§ 25 para. 2 TDDDG). The subsequent processing of personal data takes place on the respective specified legal basis, usually Art. 6 para. 1 lit. f GDPR.
(2) At present, we do not use any cookies or comparable technologies that are not strictly necessary and that would require consent under § 25 para. 1 TDDDG. Therefore, a consent banner (consent management) is not in use.
(3) If consent-required technologies are to be used in the future, we will obtain your consent beforehand, provide an appropriate management tool, and add an overview of the technologies used, providers, purposes, and durations.
§ 7 Contact
When making contact, we process the data provided in order to handle and document the request. For requests from the data subject regarding their own contract, Article 6(1)(b) GDPR applies; for business communication on behalf of a company, Article 6(1)(f) GDPR generally applies (interest in proper communication and business initiation). Data is deleted after the request has been completed, unless further communication, retention obligations, or necessary legal defense prevent this; standard period: 6 months.
§ 8 Registration, Organizational Accounts and User Management
(1) For user accounts, we process identity, business contact, company, role, permission, authentication, and account settings data as well as security-relevant usage logs.
(2) If the data subject is a contracting party themselves, Art. 6(1)(b) GDPR applies. If they are acting for a company, Art. 6(1)(f) GDPR applies; our legitimate interest lies in the execution of the user relationship with the company, a clear allocation, and secure authorization management.
(3) Account data is generally stored for the duration of the contract. After termination, deletion or blocking takes place according to the periods specified in Annex 1, insofar as legal retention, prevention of misuse, or legal defense require further storage.
§ 9 Platform Functions, Analytics, Match Score and BenchTrust Score
(1) Within the framework of the platform, we process user-provided demand, company, profile, document, inquiry, and interaction data, as well as analyses, comparisons, reports, and key figures generated from them.
(2) If the person concerned is themselves a contracting party, the processing takes place for the performance of a contract pursuant to Art. 6(1)(b) GDPR. For employees, corporate officers, and contacts of a corporate customer, Art. 6(1)(f) GDPR applies; our interest lies in providing the platform services commissioned by the company.
(3) BenchTrust Scores and Match Scores refer exclusively to legal entities. For natural persons, in particular sole proprietors, registered merchants, and freelancers, no key figures are created or provided. Personal data of board members, employees, or contact persons are not used as score characteristics.
§ 10 Showcase and Reach Statistics
(1) Showcase enables registered providers to access extended profile, display, and visibility features as well as company-related reach and performance statistics.
(2) Profile and company data, subscription and billing data, as well as statistical data such as impressions, profile views, and contact requests are processed. Personal user statistics are not disclosed to the provider unless this is necessary for a contact initiation triggered by the user.
(3) For contracting parties, Art. 6(1)(b) GDPR applies. For acting persons and the technical provision of aggregated statistics, Art. 6(1)(f) GDPR applies.
(4) The reach and usage statistics are carried out via a self-operated, aggregated evaluation. No permanent identifier is stored or read on the end device; therefore, consent is not required. The legal basis is Art. 6(1)(f) GDPR. Raw data are deleted after 14 days; anonymous, aggregated key figures can be retained beyond that.
§ 11 Listed Companies and Business Contacts (Art. 14 GDPR)
(1) BenchTrust represents companies, compares their offers, and exclusively evaluates legal entities. Insofar as data of business contacts is processed in this context, we do not always collect it directly from the person concerned.
(2) Data categories are name, business function, company, business contact information, and, where applicable, the source and the currentness. Sources are company websites, public registers, publicly accessible industry directories, press and professional publications, as well as information from the respective company.
(3) The purpose is the proper presentation of companies and the facilitation of business contact. The legal basis is Art. 6 para. 1 lit. f GDPR; our legitimate interest lies in an up-to-date, transparent B2B market overview. Recipients are users of the platform and the service providers named in Annex 2.
(4) We inform data subjects no later than within one month after obtaining the data, in the case of prior contact no later than at the time of the first communication, and in the case of prior disclosure no later than at the time of the first disclosure. Legal exceptions of Art. 14 para. 5 GDPR are only applied after a documented individual case review.
(5) Business contact data is regularly checked for accuracy and deleted or corrected if it is no longer required, demonstrably incorrect, or effectively disputed.
§ 12 RFP triggered by the buyer and contact forwarding
(1) If a buyer explicitly sends a request or initiates contact with selected suppliers, we transmit the approved requirement information and business contact details to these suppliers. Before sending, recipients and the extent of the data are displayed.
(2) If the purchaser is itself a contracting party, Art. 6 para. 1 lit. b GDPR applies. For employees or representatives of a business customer, Art. 6 para. 1 lit. f GDPR applies; the legitimate interest lies in the business initiation desired by the user.
(3) The selected providers then process the received data on their own responsibility. They are only allowed to use the data for the specific request and related communication, unless there is another legal basis.
§ 13 Lead Engine — Business Contacts and Lead Qualification
(1) As part of the Lead Engine, we research, review, qualify, and transmit business contacts to commissioning providers. Depending on the specific setup, BenchTrust acts as an independent controller, as a processor according to documented instructions, or is jointly responsible with the commissioning provider. When purposes and essential means are determined jointly, the parties conclude an agreement according to Art. 26 GDPR and provide the essential content of it to the data subjects.
(2) Only business-relevant data are processed, such as name, position, company, business email address or phone number, professional responsibility, origin and current status, as well as documented qualification characteristics. Private contact details and special categories of personal data are not specifically collected.
(3) Sources are publicly accessible directories and information from the commissioning provider as well as suitable enrichment services; the specific sources and services are definitively determined before the module is activated and listed in Appendix 2. Before transmission, we check the source, plausibility, business relevance, and currency. Data from illegal or incomprehensible sources are not used.
(4) The purpose is the identification and qualification of potentially relevant business contacts for specifically defined B2B offers. The legal basis for our own research and qualification is Art. 6(1)(f) GDPR, provided that the documented balancing of interests in the respective application case favors processing. In doing so, we particularly take into account source, function, predictability, scope of data, contact method, offer relevance, and objection options.
(5) Lead qualification can constitute profiling within the meaning of Art. 4 No. 4 GDPR. It is only used to assess business relevance and does not lead to a solely automated decision with legal or similarly significant effects. The qualification criteria are determined concretely and understandably before activation.
(6) Recipients are exclusively the contracting providers for whose specifically defined offer the business relationship has been checked, as well as the processors named in Annex 2. No transfer to general distribution lists or unnamed third parties takes place.
(7) The information pursuant to Art. 14 GDPR is provided no later than one month after obtaining the data, in the case of earlier contact no later than at the first communication, and in the case of earlier disclosure no later than before or with the first disclosure to the provider.
(8) A promotional approach may only be made via a contact method permitted under § 7 UWG. Advertising by e-mail or comparable electronic mail generally requires prior consent or a demonstrably applicable legal exception. Telephone advertising to other market participants requires at least documented presumed consent. BenchTrust and the commissioning providers document the respective permissibility before the approach.
(9) Affected persons can object to the processing for direct advertising, including related profiling, at any time without giving reasons. After that, the data will no longer be used for direct advertising or lead generation. To permanently observe the objection, we store the required minimum data in a suppression list.
(10) Leads that were not transmitted or not confirmed are regularly deleted no later than 6 months. Transmitted lead documents are deleted no later than 12 months after the last update or interaction, unless legal defense or contractual documentation requires a longer, restricted retention. Suppression list data is stored as long as this is necessary to comply with the objection.
§ 13a Own Business Initiation and Provider Acquisition
(1) To attract providers for the platform, we research business contact information of potential provider companies and contact them to initiate business. Only business data such as name, position, company, as well as business email address or telephone number are processed.
(2) The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in acquiring suitable providers for our B2B platform. Sources used are publicly accessible directories as well as the research use of the Apollo.io service (see Annex 2). Platform and customer data are not used for this purpose and are not transmitted to Apollo.io.
(3) Since we do not collect this data directly from the person concerned, we inform them in accordance with Art. 14 of the GDPR at the latest at the time of the first contact, in particular through a data protection notice in the first business communication.
(4) A commercial approach is made only via a contact method permissible under § 7 UWG. Those affected can object to the processing for the purposes of direct advertising at any time without giving reasons (datenschutz@benchtrust.com); to ensure permanent observance of the objection, we store the necessary minimum data in a blocking list.
(5) Contact information that is no longer used is regularly deleted at the latest 12 months after the last contact, provided that no legal defense or contractual documentation requires a longer, restricted retention.
§ 14 Payment Processing
For paid services, we process contract, invoice, and payment data. For contracting parties, Article 6(1)(b) GDPR applies; for tax and commercial law documents, Article 6(1)(c) GDPR applies. The payment service provider Stripe (Stripe Payments Europe, Ltd., Ireland) processes payment data regularly within the scope of its services on its own responsibility; in addition, its privacy policy applies. BenchTrust only receives the data necessary for status, assignment, billing, and reversal.
§ 15 Automated Analysis Functions and Use of Artificial Intelligence
(1) Part of our functions is based on rule-based evaluations of our own catalog and rating data stored in our database. The BenchTrust scores and match scores displayed on the platform refer exclusively to legal entities; no personal user input is transmitted to external AI providers for their display.
(2) In addition, we offer AI-based functions, in particular the AI assistant for provider profiles as well as generative smart analytics tools (for example, for demand and supply analysis, for RFP creation, and for comparison and recommendation functions). For these functions, we use external AI services: Google Gemini (Google Ireland Ltd. / Google LLC) for generating and summarizing responses, and the research service Perplexity (Perplexity AI, Inc.) for searching publicly accessible sources, in particular the official website of the respective provider. Google processes the submitted inputs within the framework of the paid Gemini API (Paid Services) as a data processor and does not use them for its own training purposes. Perplexity is also active on our behalf in a directive-bound manner within the framework of the paid API usage based on a data processing agreement and does not use the transmitted content for training purposes. Details on roles, processing region, and third-country basis of the AI services used are contained in Annex 2.
(3) When using these functions, the content you enter (such as your question or your inputs into the respective tool) as well as the associated professional context is transmitted to the mentioned services and processed there in order to generate the requested response. The AI assistant primarily bases its answers on publicly available information from the provider's official website as well as on our own catalog data. Please do not enter special categories of personal data or confidential information that is not required for the request into these functions.
(4) The legal basis in the case of a contract function requested by the data subject is Article 6(1)(b) GDPR; for acting persons of a corporate customer, it is Article 6(1)(f) GDPR (interest in providing the commissioned AI-based function). Providers, roles, processing regions, and third-country guarantees of the AI services used are set out in Annex 2.
(5) Analysis, evaluation, and AI results can be faulty and refer to legal entities. They are not used as the sole basis for decisions in legally or economically significant cases without appropriate human review. We provide transparency notices pursuant to Art. 50 of the AI Regulation from the time they become applicable.
§ 16 Moderation, Reports and Complaints
In cases of reports, complaints, and moderation decisions, we process contact details, report content, affected content, evidence, statements, as well as decision and communication data. The legal basis is Art. 6(1)(c) GDPR, to the extent that legal obligations, in particular under the Digital Services Act, are fulfilled, as well as Art. 6(1)(f) GDPR (interest in legal certainty, abuse prevention, and protection of the platform). The retention period depends on the procedure and the required legal remedy and limitation periods.
§ 17 Recipients and data protection roles
(1) Access is granted internally exclusively to persons who need it for their tasks. External service providers are bound according to Art. 28 GDPR, provided they act exclusively on our behalf and according to our instructions.
(2) Payment service providers, selected providers after a RFP transfer, and other entities can be responsible parties for their further processing. If BenchTrust and a partner jointly determine purposes and essential means, the allocation of responsibility is governed by Art. 26 GDPR.
(3) The current service provider and recipient overview, including role, service, location, and third-country basis, is included in Annex 2.
§ 18 Transfers to third countries
We prefer processing within the EU or the EEA. Transfer to a third country only takes place under the conditions of Articles 44 et seq. GDPR, in particular on the basis of an adequacy decision (including the EU-US Data Privacy Framework) or appropriate safeguards such as standard contractual clauses including the required transfer assessment and supplementary protective measures. Information or a copy of the relevant safeguards can be requested via datenschutz@benchtrust.com.
§ 19 Storage Duration and Deletion
(1) We only store personal data for as long as it is necessary for the respective purpose. Specific standard retention periods are contained in Annex 1. After that, data is deleted or, if deletion is not possible due to legal obligations or legal defense, blocked.
(2) For invoices and accounting vouchers, eight years generally apply, for commercial books, inventories, and annual financial statements, ten years, and for received and sent trade and business letters, six years. The relevant legal regulations and the specific document type are decisive.
§ 20 Rights of the persons concerned
(1) Affected persons have rights to information (Art. 15 GDPR), correction (Art. 16), deletion (Art. 17), restriction (Art. 18), notification to recipients (Art. 19), and data portability (Art. 20) in accordance with the legal requirements.
(2) Consent can be revoked at any time with effect for the future. The lawfulness of processing carried out until the revocation remains unaffected.
(3) Objections can be raised against processing based on Art. 6 para. 1 lit. f GDPR for reasons of the special situation. We will then no longer process the data, unless there are compelling legitimate reasons or the assertion, exercise, or defense of legal claims prevents this.
(4) Data subjects have the right to lodge a complaint with a data protection supervisory authority. In particular, the responsible authority is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, www.baden-wuerttemberg.datenschutz.de.
§ 21 Profiling and automated decision-making
(1) A decision based solely on automated processing, which has legal effects on a natural person or similarly significantly affects them, does not take place.
(2) Insofar as the optional Lead Engine automatically evaluates business relevance characteristics, this may constitute profiling. It is used solely to prepare a business relevance assessment; the data subject can object to the processing for direct marketing at any time.
§ 22 Data Security
We take risk-appropriate technical and organizational measures pursuant to Art. 32 GDPR. These include in particular transport encryption, role and authorization concepts, multi-factor authentication for privileged access, logging, data backups, client separation, vulnerability management, and procedures for handling data protection breaches. Specific security details are not published to the extent that this would impair their protective effect.
§ 23 Currency and Amendments
This privacy policy is current as stated above. We update it when processing operations, products, service providers, or legal requirements change. In the case of significant changes, we inform affected users in an appropriate manner.
Annex 1 — Public Overview of Processing Operations
This overview specifically clarifies purposes, legal bases, and standard retention periods. Deviating retention may result from security incidents, legal claims, or statutory obligations.
| Process | Data and Purpose | Legal basis | standard period |
|---|---|---|---|
| Website/Logs | Technical access data; secure provision | Art. 6(1)(f) | 14 days |
| Range statistics | Aggregated, anonymous usage data without persistent identifier | Art. 6(1)(f) | Raw data 14 days; aggregates anonymous |
| Contact | Request and communication data; processing | Art. 6(1)(b)/(f) | 6 months after completion |
| User account | Identity, contact, role, permissions; account and security | Art. 6(1)(b)/(f) | Contract duration + 90 days |
| Platform | Requirements, profiles, documents, usage, analyses; service delivery | Art. 6(1)(b)/(f) | Contract duration + 90 days |
| Showcase | Profile, statistics, and billing data; premium features | Art. 6(1)(b)/(f)/(a) | Subscription duration; statistics 14 months |
| Listed contacts | Name, function, business contact; B2B market overview | Art. 6(1)(f) | Until no longer needed; inspection annually |
| RFP | Needs and business contact; desired supplier approach | Art. 6(1)(b)/(f) | 12 months after completion |
| Provider acquisition | Business contact of potential suppliers; own B2B acquisition | Art. 6(1)(f) | 12 months after last contact; block list longer |
| Lead Engine (currently inactive) | Business contact and qualification; B2B lead generation | Art. 6(1)(f) | 6/12 months; blacklist longer |
| Payment | Contract, invoice, and payment status data | Art. 6(1)(b)/(c) | 6/8/10 years per document |
| Rule-based analyses/scores | Catalog/evaluation data of legal entities; no external AI service | Art. 6(1)(b)/(f) | Within the framework of the platform data |
| AI functions (assistant, generative tools) | User inputs and professional context; transmission to Google Gemini and Perplexity | Art. 6(1)(b)/(f) | Within the framework of the platform data |
| Moderation | Report, contact, content, decision; DSA/platform protection | Art. 6(1)(c)/(f) | Until the conclusion of the proceedings plus limitation periods |
Annex 2 — Overview of Service Providers, Recipients, and Third Countries
The information will be updated in the online version in case of changes. The exact company name and the current DPF/SCC status of the US-related service providers must be verified before publication based on the respective valid contracts and subcontractor lists.
| Position | Performance and Role | Processing | Third-country basis |
|---|---|---|---|
| Vercel Inc. | Website / Function Hosting; Data Processor | Frankfurt (fra1), EU | US corporation; DPF and/or SCC |
| IONOS SE | Email/SMTP and, if applicable, hosting; data processor | Germany/EU | No third-country transfer |
| Google Ireland Ltd. / Google LLC (Firebase, Google Cloud) | Database, backend functions, and file storage; data processor | Firestore and Functions: Belgium (europe-west1); File Storage: Frankfurt (europe-west3); EU | Any support/administrative accesses: DPF and/or SCC (Google Cloud DPA) |
| Stripe Payments Europe, Ltd. | Payment processing; own responsible person | Ireland; Corporation USA | DPF and/or SCC |
| Apollo.io | Data research of business contacts for acquiring providers; own responsible person/recipient; no platform/customer data | USA | DPF and/or SCC |
| Google Ireland Ltd. / Google LLC (Gemini API) | AI response generation for AI assistant and generative smart analytics tools; processor (Gemini API Paid Services, not used for training purposes) | Google infrastructure, e.g., USA (Gemini Developer API, no EU region binding) | EU-US Data Privacy Framework (Google LLC certified); additionally Google Cloud DPA |
| Perplexity AI, Inc. | AI-based web search on publicly accessible provider sources (Sonar-API); data processor (DPA; no use for training purposes) | USA/worldwide (sub-processors, e.g., AWS) | EU Standard Contractual Clauses (Modules 2/3) + UK Addendum; supplementary measures |
As of July 1, 2026