Privacy Policy

Last updated: July 6, 2026

Protecting your personal data is important to us. With the following Privacy Policy we inform you, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR), about the type, scope and purpose of the processing of personal data when you use our website at https://www.prgmtc.tech, including the Event Scout service delivered under this domain (together, the "Website").

When processing your personal data we comply with the applicable data protection laws, in particular the GDPR, the German Federal Data Protection Act ("BDSG") and the German Telecommunications Digital Services Data Protection Act ("TDDDG"). Where processing is based on Art. 6 (1)(f) GDPR, the purposes stated also represent our legitimate interests.

"Personal data" means any information relating to an identified or identifiable natural person. If our data processing changes, we will update this Privacy Policy; the current version always applies to your next visit.

1. Controller

The controller within the meaning of the GDPR is:
Pragmatic Technologies GmbH, Pappelallee 64, 10437 Berlin, Germany.
Email: hello@prgmtc.tech.

2. Data protection officer

We are not legally required to appoint a data protection officer and have therefore not designated one. For any data protection question, or to exercise the rights set out in section 17, you can reach us at hello@prgmtc.tech.

3. Informative use of the Website (server log files)

During mere informative use of the Website — i.e. if you do not sign in, subscribe or otherwise transmit information to us — your browser automatically sends information to our hosting provider's server, which is stored temporarily in so-called log files. The following is recorded in particular:

- the IP address of the requesting device

- the date and time of access

- the name and URL of the file retrieved

- the website from which access is made (referrer URL)

- the browser used and the operating system

This processing serves to ensure a smooth connection, the convenient use of the Website and the evaluation of system security and stability. The legal basis is our legitimate interest in the technical provision and security of the Website (Art. 6 (1)(f) GDPR).

4. Hosting, content delivery and security (Cloudflare)

The entire Website — including the Event Scout service — is hosted on and delivered exclusively via the infrastructure, content delivery network and application platform of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. On our behalf, Cloudflare processes, among other things, the server log data mentioned above and your IP address in order to host and deliver the Website's content, ensure its security (e.g. defending against attacks and filtering malicious traffic) and accelerate delivery.

The legal basis is our legitimate interest in the secure and efficient provision of the Website (Art. 6 (1)(f) GDPR). We have concluded a data processing agreement with Cloudflare pursuant to Art. 28 GDPR. As personal data may be transferred to the USA in this context, the transfer is based on Cloudflare's certification under the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and, additionally, on the European Commission's Standard Contractual Clauses (Art. 46 GDPR). For more information, see Cloudflare's privacy policy.

5. Content management and media hosting (Sanity)

The editorial content and images on this Website are managed in the headless content-management system Sanity and delivered via Sanity's media/asset CDN (cdn.sanity.io). The provider is Sanity AS, Trondheimsveien 2K, 0560 Oslo, Norway. When your browser loads images or other assets from the Website, your IP address is technically processed by Sanity's CDN in order to deliver those assets.

The legal basis is our legitimate interest in providing the Website with its content efficiently and reliably (Art. 6 (1)(f) GDPR). We have concluded a data processing agreement with Sanity pursuant to Art. 28 GDPR. Sanity AS is established in Norway (within the EEA) and offers EU/EEA data residency; it uses Google Cloud as an infrastructure subprocessor. Insofar as personal data is processed in the USA via subprocessors or Sanity's US affiliate, this is safeguarded by the European Commission's Standard Contractual Clauses (Art. 46 GDPR). For more information, see Sanity's privacy policy.

6. Consent and cookies

Insofar as we use cookies or comparable technologies, or use services that store or read information on your device, we obtain your prior consent for this via a consent banner – unless this is technically necessary. The legal basis is § 25 (1) TDDDG in conjunction with Art. 6 (1)(a) GDPR. Your consent is voluntary and can be withdrawn at any time with effect for the future, for example via the settings of the consent banner. Technically necessary cookies that are required to operate the Website — including the session cookie set when you sign in (see section 11) — are exempt from consent under § 25 (2) TDDDG; the associated processing is based on our legitimate interest (Art. 6 (1)(f) GDPR). You can adjust or withdraw your choice at any time via the Cookie settings button at the bottom of this page.

7. Web analytics (Google Analytics)

This Website uses – exclusively after your consent – Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google). Google Analytics uses cookies and similar technologies to analyse the use of the Website (e.g. pages visited, time spent, approximate location, device used). The information generated is generally transferred to and stored on Google servers; this may involve a transfer to Google LLC in the USA.

The legal basis is your consent pursuant to § 25 (1) TDDDG and Art. 6 (1)(a) GDPR. Processing only takes place after you have consented via the consent banner; you can withdraw your consent at any time with effect for the future. For the data transfer to the USA, we rely on Google's certification under the EU-U.S. Data Privacy Framework and, additionally, on the Standard Contractual Clauses. For more information, see Google's privacy policy.

8. Tag management (Google Tag Manager)

To manage the tags used on the Website (such as Google Analytics), we use Google Tag Manager, provided by Google Ireland Limited. Google Tag Manager serves to manage and deploy other services and does not itself set analytics or tracking cookies. However, when it loads, a connection to Google's servers is established and your IP address is processed. Google Tag Manager and the services triggered via it are only activated after your consent (§ 25 (1) TDDDG, Art. 6 (1)(a) GDPR).

9. Newsletter and subscription sign-up (Brevo)

If you sign up for our newsletter, or subscribe to the Event Scout service or another update via a form on this Website, we process the data you provide (in particular your email address and, where applicable, your name and company) in order to send you the newsletter or the requested information. Registration takes place using the double opt-in procedure: after signing up, you receive an email in which you must confirm your registration. This ensures that the registration was actually made by you.

The legal basis for sending the newsletter / requested communications is your consent pursuant to Art. 6 (1)(a) GDPR. You can unsubscribe and withdraw your consent at any time, for example via the unsubscribe link in every email. To document the registration, we store the time of registration and confirmation as well as your IP address; the legal basis for this is our legitimate interest in being able to demonstrate that consent was duly given (Art. 6 (1)(f) GDPR).

For sending, we use the Brevo service provided by Sendinblue SAS, 17 rue Salneuve, 75017 Paris, France. Brevo processes your data on our behalf within the European Union on the basis of a data processing agreement pursuant to Art. 28 GDPR. For more information, see Brevo's privacy policy.

10. Transactional emails (Brevo)

We also use Brevo (Sendinblue SAS) to send transactional emails — that is, service messages directly connected to your use of the Website, such as sign-in confirmations, subscription and payment confirmations, account notifications and other operational messages. For this purpose we process your email address and the content of the respective message.

The legal basis is the performance of our contract with you or the taking of steps at your request prior to entering into a contract (Art. 6 (1)(b) GDPR) and, insofar as the message is not strictly contractual, our legitimate interest in communicating with you about the service you use (Art. 6 (1)(f) GDPR). Brevo processes this data on our behalf within the European Union on the basis of a data processing agreement pursuant to Art. 28 GDPR.

11. Authentication and access management (Cloudflare Access / Zero Trust)

Access to protected areas of the Website and to the Event Scout service is secured using Cloudflare Access, part of the Cloudflare Zero Trust platform provided by Cloudflare, Inc. When you sign in, Cloudflare Access verifies your identity — in particular your email address (for example via a one-time verification code or a connected identity provider) — and, once verified, issues a signed session token (a cookie) that grants you access for the duration of your session. In this context, Cloudflare processes your email address, your IP address, and technical metadata about the sign-in and your device.

The legal basis is the performance of our contract with you or the taking of steps prior to entering into a contract (Art. 6 (1)(b) GDPR) as regards providing you with access to the service, and our legitimate interest in protecting the Website and restricting access to authorised users (Art. 6 (1)(f) GDPR). Cloudflare acts as our processor on the basis of a data processing agreement pursuant to Art. 28 GDPR. Insofar as personal data is transferred to the USA, this is safeguarded by Cloudflare's certification under the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and, additionally, the Standard Contractual Clauses (Art. 46 GDPR). For more information, see Cloudflare's privacy policy.

12. Payments (Stripe)

If you purchase a paid subscription or another paid service via the Website, the payment is processed by Stripe. Depending on the payment method you choose, we process — or Stripe processes on our behalf — the data required to complete the payment, in particular your name, email address, billing address, the chosen payment method and transaction data. Card numbers and comparable sensitive payment details are entered directly with Stripe and are not stored by us.
The provider is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, which may involve Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA. Stripe acts in part as our processor on the basis of a data processing agreement pursuant to Art. 28 GDPR (processing the payment on our behalf) and in part as an independent controller (in particular for fraud prevention and to comply with its own legal and regulatory obligations).

The legal basis for the payment processing is the performance of our contract with you (Art. 6 (1)(b) GDPR); the legal basis for fraud prevention and the fulfilment of legal obligations is our and Stripe's legitimate interest and legal compliance (Art. 6 (1)(f) and (c) GDPR). Insofar as personal data is transferred to the USA, this is safeguarded by Stripe's certification under the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and, additionally, the Standard Contractual Clauses (Art. 46 GDPR). For more information, see Stripe's privacy policy.

13. Contacting us by email

If you contact us by email – for example at hello@prgmtc.tech – we process the data you provide (your email address, your name and the content of your message) in order to handle your request. The legal basis is Art. 6 (1)(b) GDPR insofar as your request is aimed at concluding or performing a contract, and otherwise our legitimate interest in responding to your enquiry (Art. 6 (1)(f) GDPR). We delete this data as soon as it is no longer required to achieve the purpose for which it was collected, unless statutory retention obligations prevent this.

14. Recipients of your data

We use external service providers to process personal data. In part they act as processors on our behalf, on our instructions and under our supervision, exclusively for the purposes described in this Privacy Policy (Art. 28 GDPR). We only pass data to other third parties where we are legally obliged to do so or where this is necessary to assert, exercise or defend legal claims. We do not sell your data. The recipients are:
- Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA) — hosting, CDN, security/proxy and authentication/access management (Cloudflare Access / Zero Trust) for the entire Website including Event Scout. USA; safeguarded by the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.

- Sanity AS (Trondheimsveien 2K, 0560 Oslo, Norway) — headless CMS and media/asset hosting (CDN). EEA (Norway); any US sub-processing is safeguarded by Standard Contractual Clauses.

- Google Ireland Limited / Google LLC (Gordon House, Barrow Street, Dublin 4, Ireland; 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) — web analytics (Google Analytics) and tag management (Google Tag Manager). EU, with possible transfer to the USA; safeguarded by the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.

- Sendinblue SAS (Brevo) (17 rue Salneuve, 75017 Paris, France) — newsletter and subscription email (double opt-in) and transactional emails. EU.

- Stripe Payments Europe, Limited / Stripe, Inc. (1 Grand Canal Street Lower, Dublin, Ireland; 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA) — payment processing. EU, with possible transfer to the USA; safeguarded by the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.

15. International data transfers

Some services we use are provided by providers based or with servers in the USA (in particular Cloudflare, Google and Stripe). Our content-management provider Sanity AS is based in Norway (EEA); a transfer to the USA only occurs at the subprocessor level. Insofar as personal data is transferred to the USA or other third countries, this takes place on the basis of an adequacy decision (EU-U.S. Data Privacy Framework, Art. 45 GDPR) for correspondingly certified providers and/or the European Commission's Standard Contractual Clauses (Art. 46 GDPR):
- Cloudflare, Inc. — USA — EU-U.S. Data Privacy Framework (Art. 45) and SCC (Art. 46).

- Google LLC — USA — EU-U.S. Data Privacy Framework (Art. 45) and SCC (Art. 46).

- Stripe, Inc. — USA — EU-U.S. Data Privacy Framework (Art. 45) and SCC (Art. 46).

- Sanity (via US sub-processors) — USA, where applicable — Standard Contractual Clauses (Art. 46).

You can request a copy of the Standard Contractual Clauses at hello@prgmtc.tech. Our newsletter/transactional-email provider Brevo (Sendinblue SAS) processes your data within the European Union.

16. Retention period

We process and store personal data only for as long as is necessary to fulfil the respective purposes or as required by statutory retention periods (e.g. commercial and tax law obligations — payment and invoicing data in particular is retained for the statutory periods). Once the respective purpose ceases to apply or these periods expire, the data is deleted.

17. Data security

We take appropriate technical and organisational measures to protect your data against loss, destruction, manipulation and unauthorised access. This Website uses TLS/SSL encryption, recognisable by the padlock symbol in your browser and the address bar beginning with https://. Our fonts are served locally from our own infrastructure; external font services (e.g. Google Fonts) are not used.

18. Your rights as a data subject

With regard to the personal data concerning you, you are entitled to the following rights free of charge:

- Right of access (Art. 15 GDPR). You can obtain information as to whether and what personal data we process about you, including the purposes, the storage period, the origin of the data and the recipients, and you can request a copy of that data.

- Right to rectification (Art. 16 GDPR). You can request that we correct inaccurate data without undue delay and complete incomplete data.

- Right to erasure (Art. 17 GDPR). You can request erasure of your data, in particular where it is no longer necessary for the purposes for which it was collected, where you withdraw your consent and there is no other legal basis, or where it has been processed unlawfully. Statutory retention obligations remain unaffected.

- Right to restriction of processing (Art. 18 GDPR). You can request that we restrict processing, for example while the accuracy of your data is being verified.

- Right to data portability (Art. 20 GDPR). You can receive the data you provided to us in a structured, commonly used and machine-readable format, or have it transmitted to a third party.

- Right to object (Art. 21 GDPR). Where we process personal data on the basis of legitimate interests (Art. 6 (1)(f) GDPR), you may object at any time on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims. You may object to processing for direct marketing purposes at any time.

- Right to withdraw consent (Art. 7 (3) GDPR). You can withdraw any consent you have given us at any time with effect for the future. The lawfulness of processing carried out up to that point remains unaffected.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority competent for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59–61, 10555 Berlin, Germany. You may also lodge a complaint with the supervisory authority at your place of residence.

19. Obligation to provide personal data

The provision of your personal data is neither legally nor contractually required; you are not obliged to provide us with data. However, without the respective necessary data we cannot handle certain requests – for example creating an account or granting access, processing a payment, sending the newsletter or responding to an enquiry.

20. Automated decision-making

No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.

21. Changes to this Privacy Policy

We reserve the right to amend this Privacy Policy so that it always complies with current legal requirements or in order to reflect changes to our services. The current version then applies to your next visit.