This is a translation for convenience. The binding version is in German: GDPR.
At Bilendo, data protection has been an important component from the very beginning, both in the development of the software and in the associated storage and processing of data. In the context of the GDPR, we want to present the new regulation and show how data protection is implemented in the company and in the software.
The General Data Protection Regulation (GDPR) is an EU regulation adopted by the European Parliament in 2016 and in force in Germany since May 25, 2018, replacing the 1995 EU Data Protection Directive. Its aim is to improve the protection of personal data of all citizens in the European Union, binding companies and public bodies to much stricter rules when they collect and process personal data, increasing sanctions for violations and strengthening the rights of data subjects.
The GDPR applies in all EU member states and to all companies with European headquarters. It is much broader than the 1995 directive: it applies equally to companies based in third countries that store and process the data of EU citizens. In short, the GDPR creates a uniform legal framework for all EU members and strengthens the data sovereignty of EU citizens, especially vis-à-vis companies based outside the EU.
The complete legal text of the regulation can be found at dsgvo-gesetz.de.
Our website does not serve as a standard reference work on the GDPR nor as legal advice for other companies, and is not a guide for legally compliant compliance with it. It provides and summarizes relevant information so that everyone can understand how Bilendo internally handles data security and protection. This information is in no way a substitute for legal advice from a lawyer, and you may not rely on this document as a recommendation for a particular interpretation of applicable law.
One of the most important points in the GDPR is the processing and storage of personal data by companies and public bodies. Personal data is any information relating to an identified or identifiable individual — under Art. 4(1) GDPR, a person identifiable directly or indirectly by reference to an identifier such as a name, ID number, location data, an online identifier, or factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.
The GDPR tightens the conditions for effective consent (Art. 4(11), Art. 7 GDPR): the declaration of consent must be clear and simple, describe the purpose of processing, and be presented separately from other content — "hiding" consent inside terms & conditions or a privacy policy does not comply with the GDPR. In addition, consent must be:
Under the GDPR, companies must comply with extensive information obligations under Art. 13 and 14 GDPR towards data subjects, including:
Bilendo provides a detailed privacy policy that covers these points in full. Questions are always welcome at datenschutz@bilendo.de.
The GDPR strengthens the rights of information, rectification, restriction of processing, erasure, notification, data portability, objection, revocation of consent, and the right to complain to a supervisory authority. Under Art. 15 GDPR, a data subject has the right to information about the processing purpose, data categories, recipients, storage duration, their own rights, the origin of the data, and any automated decision-making. Under Art. 16 and 17 GDPR, a data subject can demand immediate correction of incorrect data and, in several defined cases, erasure ("right to be forgotten") — e.g. when the data is no longer necessary, consent is withdrawn, processing was unlawful, or a legal deletion obligation applies. Data subjects also have an information right under Art. 19 GDPR whenever a correction, deletion or restriction has been carried out.
IT security has gained considerably in importance under the GDPR. Art. 5(1)(f), Art. 24, Art. 25 and Art. 32 GDPR require appropriate technical and organizational measures both when planning and when carrying out the processing of personal data — "data protection by design" (Art. 25(1)) and "data protection by default" (Art. 25(2)), meaning systems are built to be privacy-friendly by construction and preconfigured to collect no more data than the purpose requires. Where a processor is engaged, Art. 28(1) GDPR requires that cooperation is only permitted if the processor can demonstrate sufficient technical and organizational measures — Bilendo provides these as an annex to the contract for commissioned processing, downloadable from your Bilendo account.
The GDPR makes processors jointly responsible for compliant processing, storage and collection of personal data. A contract for commissioned processing under Art. 28 GDPR must be concluded between client and processor, covering: data processing according to instructions, preservation of data secrecy, technical and organizational measures, use of subcontractors, requests from data subjects, support for those responsible, deletion/return obligations after termination, and information and audit rights. Bilendo provides this contract and all required attachments for download in the user account; questions go to your Bilendo contact or datenschutz@bilendo.de.
As a processor, Bilendo fully complies with all legal obligations: it maintains a directory of processing activities (Art. 30 GDPR) available to the supervisory authority on request, and assures extensive support and immediate cooperation with the competent supervisory authority (Art. 31 GDPR).
Bilendo has appointed both an internal and an external data protection officer, as required by Art. 37(1) GDPR:
Wolfgang Steger (external data protection officer)
Sapporobogen 6-8
D-80637 Munich
Phone: +49 89 21999 80
Florian Kappert (internal data protection officer)
Fürstenfelder Str. 9
D-80331 Munich
Phone: +49 89 3441321 00
All data managed and processed as part of service provision is stored exclusively in German data centers and subject to GDPR throughout further collection, storage and processing. Customer data resides in Frankfurt am Main, in a data center operated by Amazon Web Services Germany (AWS), certified to:
Every connection to and from Bilendo is encrypted — SSL encryption secures the website, the application itself and every transport route, including data exchanged with our service providers. Cloudflare Protection additionally secures the app.bilendo.de domain against attacks on the DNS system.
Bilendo's IT organization chart lists every service provider it works with and the IT structure underlying service delivery. Providers are selected under strict review for data security and data protection, and Bilendo has concluded a contract for commissioned data processing with each of them under § 28 GDPR. The list of approved subcontractors is attached to that contract, downloadable from the Bilendo account.
Further information is available in our Data Privacy notice.