Data protection

Last updated: July 2026

Ulysta Software und Consulting GmbH takes the protection of personal data seriously. This Privacy Policy explains how we collect, use, disclose and protect personal data when you visit our website, contact us, use our online forms, communicate with us, apply for a position with us, or interact with us in a business context.

This Privacy Policy applies to our website and to general business, sales, support, customer communication and applicant management activities. Where Ulysta processes personal data on behalf of a customer as part of a project, support service, cloud service, software service or consulting engagement, such processing is governed by the applicable customer agreement and, where required, by a separate data processing agreement.

1. Controller

The controller responsible for the processing of personal data under this Privacy Policy is:

Ulysta Software und Consulting GmbH
Steinheilstraße 4
85737 Ismaning
Germany

Email: kontakt@ulysta.com

Data Protection Officer

You can contact our Data Protection Officer at: datenschutz@ulysta.com
or by post at the address above, marked “Data Protection Officer”.

2. Personal data we process

Depending on how you interact with us, we may process the following categories of personal data:

  • contact details, such as name, business email address, telephone number, company name and postal address;
  • communication data, such as the content of messages, inquiries, emails and related correspondence;
  • business relationship data, such as your role, department, company, project affiliation, customer or supplier relationship and areas of interest;
  • contract and billing data, such as order details, invoice information, tax-relevant information and payment-related information;
  • technical website data, such as IP address, browser type, operating system, date and time of access, pages visited, referring URLs and log files;
  • support and project-related contact data, where you interact with us in relation to support, consulting, software implementation or customer services;
  • applicant data, if you apply for a position with us, such as your CV, cover letter, qualifications, professional history and communication with us.

Please do not provide special categories of personal data, such as health data, religious beliefs or similar sensitive information, unless this is necessary for your request. If such data is provided, we process it only where a legal basis under Art. 9 GDPR applies.

3. Purposes and legal bases of processing

We process personal data only where we have a legal basis to do so. The following table summarizes the main processing activities.

Processing activity  Purpose  Legal basis 
Website access and server logs  Operation, security, error analysis and protection of the website  Legitimate interest, Art. 6(1)(f) GDPR 
Contact requests and email communication  Responding to inquiries and communicating with you  Legitimate interest, Art. 6(1)(f) GDPR; contract initiation or performance, Art. 6(1)(b) GDPR 
Customer and supplier communication  Managing business relationships, projects, offers, orders and services  Contract performance, Art. 6(1)(b) GDPR; legitimate interest, Art. 6(1)(f) GDPR 
Contract, order and billing processing  Preparing offers, concluding and performing contracts, invoicing and accounting  Contract performance, Art. 6(1)(b) GDPR; legal obligation, Art. 6(1)(c) GDPR 
Support and consulting services  Providing support, implementation, maintenance, consulting and project services  Contract performance, Art. 6(1)(b) GDPR; legitimate interest, Art. 6(1)(f) GDPR 
Applicant management  Reviewing and managing applications and deciding whether to enter into an employment relationship  Art. 6(1)(b) GDPR in conjunction with §26 BDSG; where applicable Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR 
Compliance and legal defense  Fulfilling legal obligations, preventing misuse, enforcing claims and defending legal rights  Legal obligation, Art. 6(1)(c) GDPR; legitimate interest, Art. 6(1)(f) GDPR 

We do not use Google Analytics, marketing cookies or newsletter service providers on our website.

4. Website hosting and server logs

Our website is hosted on systems operated by Ulysta. Where we use infrastructure, network, data center or IT service providers for the technical operation of these systems, such providers process data only to the extent necessary to provide the relevant infrastructure or support services. When you access our website, technical information is automatically processed to deliver the website to your device and to ensure stability, security and functionality.

This may include:

  • IP address;
  • date and time of access;
  • requested page or file;
  • browser type and version;
  • operating system;
  • referring URL;
  • access status;
  • transferred data volume.

We process this data to operate the website, prevent misuse, diagnose technical issues and maintain information security. Server log data is normally deleted or anonymized after 30 days, unless longer retention is required to investigate security incidents, prevent misuse or comply with legal obligations.

5. Contact forms and communication

If you contact us by email, contact form, telephone or other communication channels, we process the information you provide to respond to your request.

This may include your name, company, email address, telephone number, message content and any additional information you choose to provide.

We use this data to handle your inquiry, communicate with you and, where applicable, prepare or perform a contract. We retain such communication for as long as necessary to handle the inquiry and to meet contractual, statutory or documentation requirements.

6. Customers, suppliers and business partners

If you are a customer, prospective customer, supplier, partner or other business contact, we process personal data required to manage the business relationship.

This may include contact details, role and company information, project information, offer and order data, contract correspondence, billing information and service-related communication.

We process this data for contract preparation, contract performance, project delivery, support, account management, invoicing, compliance and business administration.

7. Customer content and processor activities

In some services, projects or support scenarios, Ulysta may access or process data provided by or stored in customer systems. This may include customer content, system data, log data, configuration data, project data or support information.

Where Ulysta processes such data on behalf of a customer and according to the customer’s instructions, Ulysta acts as a processor within the meaning of Art. 28 GDPR. In such cases, the processing is governed by the relevant customer agreement and, where required, a data processing agreement. This Privacy Policy does not replace such contractual arrangements.

8. Cookies and similar technologies

Our website does not currently use cookies, analytics cookies, marketing cookies or comparable tracking technologies.

We do not use Google Analytics.

If we introduce cookies, analytics tools or marketing technologies in the future, we will update this Privacy Policy and, where required by law, request your consent before using such technologies.

9. Newsletter

We do not currently use a newsletter provider and do not currently offer a newsletter subscription through our website.

If we introduce a newsletter in the future, we will update this Privacy Policy accordingly and process newsletter-related personal data only on the basis of your consent or another applicable legal basis.

10. Applications

If you apply for a position with us, we process the personal data you provide as part of your application.

This may include:

  • your name and contact details;
  • your CV;
  • cover letter;
  • certificates and qualifications;
  • professional history;
  • salary expectations, if provided;
  • availability;
  • communication with us during the application process.

We use applicant data only to manage the application process and to decide whether to enter into an employment relationship.

If your application is unsuccessful, we delete your applicant data six months after completion of the application process, unless you have consented to longer retention or legal claims require longer storage.

If your application is successful, relevant application data may be transferred to your personnel file and processed for employment purposes.

11. Recipients of personal data

We disclose personal data only where necessary and legally permitted. Recipients may include:

  • IT service providers supporting our internal systems;
  • email and communication service providers;
  • CRM, project management, support and collaboration tool providers;
  • tax advisors, auditors, banks and payment service providers;
  • legal advisors and other professional advisors;
  • public authorities, courts or regulators where legally required;
  • affiliated companies or business partners where necessary for project delivery or business administration;
  • customers, where required for support, consulting or project delivery.

Service providers processing personal data on our behalf are contractually bound to process data only according to our instructions and to implement appropriate technical and organizational safeguards.

12. International data transfers

Personal data may be processed in countries outside the European Economic Area if this is necessary for the purposes described in this Privacy Policy, for example where we use international IT, support, communication or collaboration service providers.

Where personal data is transferred to a country outside the European Economic Area, we ensure that an appropriate level of protection is in place. This may include:

  • an adequacy decision by the European Commission;
  • EU Standard Contractual Clauses;
  • supplementary technical, organizational or contractual safeguards, where required;
  • participation of the recipient in an approved data transfer framework, where applicable.

For transfers to the United States, we may rely on the EU-US Data Privacy Framework where the recipient is certified under that framework. Where this is not the case, we use other appropriate safeguards, such as EU Standard Contractual Clauses, where required.

13. Retention periods

We retain personal data only for as long as necessary for the purposes for which it was collected, unless statutory retention obligations or legal claims require longer storage.

In general:

  • website log data is normally deleted or anonymized after 30 days, unless longer retention is required to investigate security incidents, prevent misuse or comply with legal obligations;
  • contact inquiries are retained for the duration necessary to handle the inquiry and for a reasonable follow-up period, normally no longer than 24 months unless the communication becomes part of a contractual or legal record;
  • contract, invoice and business correspondence data may be retained for the statutory commercial and tax retention periods;
  • applicant data is deleted six months after completion of the application process, unless longer retention is legally required or you have consented to longer retention;
  • support and project data is retained according to the applicable customer agreement and documentation requirements.

After expiry of the applicable retention period, personal data is deleted or anonymized unless further retention is legally permitted or required.

14. Provision of personal data

The provision of personal data is generally voluntary when you visit our website. However, certain personal data may be necessary to respond to an inquiry, process an application, prepare or perform a contract, or comply with legal obligations. If you do not provide the data required for these purposes, we may not be able to respond to your request, process your application, or enter into or perform a contract with you.

15. Your rights

Subject to the conditions under applicable data protection law, you have the following rights:

  • the right of access to your personal data;
  • the right to rectification of inaccurate or incomplete personal data;
  • the right to erasure of your personal data;
  • the right to restriction of processing;
  • the right to data portability;
  • the right to object to processing based on legitimate interests;
  • the right to withdraw consent at any time with effect for the future;
  • the right to lodge a complaint with a competent data protection supervisory authority.

To exercise your rights, please contact us at:

kontakt@ulysta.com

We may need to verify your identity before responding to your request.

16. Right to object

Where we process personal data based on legitimate interests under Art. 6(1)(f) GDPR, you have the right to object to such processing at any time on grounds relating to your particular situation.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defense of legal claims.

You may object to direct marketing at any time. If you object to direct marketing, we will no longer use your personal data for that purpose.

17. Withdrawal of consent

Where processing is based on your consent, you may withdraw your consent at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

18. Supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. For companies based in Bavaria, the competent supervisory authority is generally:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany

Website: www.lda.bayern.de

19. Data security

We use appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration or disclosure.

These measures include access controls, security procedures, IT safeguards and contractual controls with service providers.

Our security measures are reviewed and adjusted where appropriate, taking into account the nature, scope, context and purposes of processing as well as the associated risks.

20. Links to third-party websites

Our website may contain links to third-party websites. We are not responsible for the content or privacy practices of such third-party websites. Please review the privacy policies of the relevant third-party websites before providing personal data.

21. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect legal, technical or business changes. The current version is available on our website. The date of the latest update is shown at the beginning of this Privacy Policy.

22. Contact

If you have questions about this Privacy Policy or about how we process personal data, please contact us:

Ulysta Software und Consulting GmbH
Steinheilstraße 4
85737 Ismaning
Germany

Email: kontakt@ulysta.com

Address

Social Media

Contact