Privacy Policy
Last updated: 15 June 2026
This English version is a convenience translation. In case of discrepancies, the German version of this policy prevails.
This policy explains how personal data is processed when you visit samla-hr.de. The site is currently a coming-soon page: it introduces the upcoming Samla HR product and lets you sign up with an email address to be notified at launch. You only actively provide personal data if you enter your email address for that notification. References to the GDPR (General Data Protection Regulation, EU 2016/679) and the German BDSG apply.
1. Controller
(1) The controller within the meaning of Art. 4 (7) GDPR is:
LOHN24 EXPERTS GmbH
Nunsdorfer Ring 15
12277 Berlin
Germany
Email: kontakt@samla-hr.de
Phone: +49 30 6840881-500
(2) The data protection officer can be reached at: David Schramm, 0xda7a consulting GmbH, Nunsdorfer Ring 15, 12277 Berlin, email: lohn24-experts@privacy.0xda7a.com.
2. Categories of data processed
(1) Depending on how you interact with us, we process the following categories of personal data:
- Access data when you visit the website: IP address, date and time of request, requested URL, referrer, user agent.
- Waitlist data when you sign up for the launch notification ("Get notified"): the email address you enter and the language you selected.
- Communication data when you contact us: email address and the content of your message.
(2) Beyond this we process no further personal data on this coming-soon page. In particular there are currently no user accounts, no sign-in, no payment/checkout, and no processing of product or customer data – those features will only become available when the service launches and will be described in an updated version of this policy at that time.
3. Launch notification sign-up ("Get notified")
(1) When you enter your email address in the "Get notified" section, we store it together with the language you selected in order to inform you about the launch of Samla HR. Providing it is voluntary; without your email address we cannot notify you.
(2) The legal basis is your consent under Art. 6 (1) (a) GDPR. You may withdraw it at any time with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal.
(3) After signing up you receive a confirmation email, which also contains an unsubscribe link.
(4) Unsubscribing. You can unsubscribe at any time – either via the unsubscribe link in every email we send, or via the form at /unsubscribe. For security reasons, after you enter your address in the form we first send you a confirmation email containing a link. We only delete your address once you click that link. This ensures that only the owner of an address can remove it. Once you unsubscribe, your email address is deleted from the waitlist entirely.
4. Analytics with Plausible Analytics
For audience measurement we use Plausible Analytics, a privacy-friendly, cookieless web analytics tool. We run Plausible as a self-hosted instance at analytics.lohn24-experts.de within the EU. Plausible sets no cookies and stores no personal data: it neither permanently stores IP addresses nor builds cross-device or cross-site profiles. From the IP address, user agent and a daily-rotating random value it only derives a non-reversible daily hash to count returning visits within a single day; the IP address itself is discarded and not logged. Only aggregated metrics such as page views, referrers, approximate origin (country), device type and browser are collected. The legal basis is Art. 6 (1) (f) GDPR – our legitimate interest in privacy-preserving statistics about the use of our site. As no information is stored on or accessed from your device, no consent under § 25 TDDDG is required.
5. Cookies
On this coming-soon page we set no cookies and use no comparable access to your device – neither for analytics nor for marketing purposes.
6. Server log files
When you access the website, our hosting provider automatically records data in server log files. This data is not merged with other data sources and is deleted after at most 30 days, unless retention is required to investigate a specific security incident. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure and reliable operation).
7. Recipients and processors
(1) We engage the following categories of processors under data processing agreements pursuant to Art. 28 GDPR:
- Hosting and infrastructure providers within the EU.
- Email delivery service for transactional emails (sign-up confirmation, unsubscribe confirmation).
- Software development and operations (0xda7a consulting GmbH, Berlin), which develops the website and administers the servers on which it runs (see Section 7.1).
(2) No processing takes place outside the EU/EEA; a list of currently engaged sub-processors is available on request.
7.1 Software development, operations and error monitoring (0xda7a)
(1) The website is developed by 0xda7a consulting GmbH (Nunsdorfer Ring 15, 12277 Berlin). 0xda7a also administers the servers of LOHN24 EXPERTS GmbH on which the site runs. In the course of operation, maintenance and troubleshooting, 0xda7a may therefore access system, log and error data and, in that context, personal data. This takes place as a processor under a data processing agreement pursuant to Art. 28 GDPR, bound by instructions and confidentiality; the data stays within Germany and is not disclosed to any third party.
(2) For error and stability monitoring we use Sentry, an open-source platform for error and performance monitoring, run as a self-hosted instance at sentry.0xda7a.com operated by 0xda7a. Sentry processes technical request data (e.g. requested URL, referrer, browser and operating system) and error context. In addition, only when an error occurs, a short session replay of the affected interaction is recorded (e.g. mouse movements, clicks and page interactions) to help reproduce the fault. Form inputs are masked and are not recorded; no analytics or marketing tracking takes place.
(3) The legal basis is Art. 6 (1) (f) GDPR – our legitimate interest in a stable, secure and user-friendly presence that is continuously developed and maintained.
8. Retention
We store personal data only for as long as necessary for the respective purposes:
- Server log files: up to 30 days.
- Waitlist data (email address, language): until you withdraw consent or unsubscribe, and at the latest until the Samla HR launch communication is complete.
- Communication data: until your request has been fully handled, unless statutory retention obligations apply.
9. Your rights
(1) Subject to the statutory requirements, you have the right to:
- access (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection (Art. 21 GDPR),
- withdrawal of consent at any time, with effect for the future (Art. 7 (3) GDPR).
(2) Please send requests to kontakt@samla-hr.de.
(3) You also have the right to lodge a complaint with a supervisory authority. The competent authority for our registered office is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin.
10. Changes to this policy
We may update this policy to reflect changes in the site, its scope of features or applicable law – in particular when the Samla HR service launches. The current version is always available at https://samla-hr.de/privacy.