perfexcrm-module.com
DE EN
← Back to home

Data protection

Privacy Policy

This policy explains which personal data we process when operating the perfexcrm-module.com online shop, for what purpose and on which legal basis – in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

Last updated: 6 July 2026 18 sections The German version is authoritative
Imprint Privacy Terms Licensing

On this page

01 Controller 02 Principles 03 Your rights 04 Hosting 05 Server log files 06 Cookies & local storage 07 Account & registration 08 Orders & invoices 09 Payment processing (Stripe) 10 Module license validation 11 Newsletter 12 Uploads & malware scan 13 Reviews 14 Contacting us 15 Transfers to third countries 16 Retention periods 17 Data security 18 Changes

Questions?

Get in touch – we are happy to help.

hello@perfexcrm-module.com
Table of contents
01 Controller 02 Principles 03 Your rights 04 Hosting 05 Server log files 06 Cookies & local storage 07 Account & registration 08 Orders & invoices 09 Payment processing (Stripe) 10 Module license validation 11 Newsletter 12 Uploads & malware scan 13 Reviews 14 Contacting us 15 Transfers to third countries 16 Retention periods 17 Data security 18 Changes

01Controller

The controller responsible for data processing on this website within the meaning of the GDPR is:

Owner
Sven Gauditz (PixAgentur)
Address
Ringstr. 3, 24321 Behrensdorf, Germany
E-mail
hello@perfexcrm-module.com

A statutory data protection officer has not been appointed, as the legal requirements for this are not met.

02Processing principles

We process personal data only insofar as this is necessary to provide a functional website as well as our content and services. As a rule, processing only takes place with your consent or on the basis of a statutory permission. Personal data is any information relating to an identified or identifiable natural person.

The relevant legal bases are in particular: Art. 6 (1)(a) GDPR (consent), (b) (performance of a contract and pre-contractual measures), (c) (legal obligation) and (f) (legitimate interests).

03Your rights as a data subject

With regard to your personal data, you have the following rights against us:

  • Access to the data processed (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing (Art. 21 GDPR)
  • Withdrawal of a given consent with effect for the future (Art. 7 (3) GDPR)
Right to object: Insofar as we process data on the basis of legitimate interests (Art. 6 (1)(f) GDPR), you have the right to object at any time for reasons arising from your particular situation.

An informal message to hello@perfexcrm-module.com is sufficient to exercise these rights.

Right to lodge a complaint: Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:

Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, www.datenschutzzentrum.de

04Hosting

This website is operated on servers within the European Union at IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. IONOS processes data arising when you visit the website on our behalf. The legal basis is our legitimate interest in the secure and efficient provision of our offering (Art. 6 (1)(f) GDPR). A data processing agreement (Art. 28 GDPR) is in place with the provider.

05Server log files

When you access the website, the server automatically collects and stores information in so-called server log files that your browser transmits: browser type and version, operating system used, referrer URL, host name of the accessing computer, time of the server request and the IP address.

This data is not merged with other data sources. Processing is based on Art. 6 (1)(f) GDPR; we have a legitimate interest in the technically error-free presentation and security of our offering. For security reasons, log files are stored for a maximum of 14 days and then deleted, unless they are required to investigate a specific security incident.

06Cookies & local storage

We use only technically necessary cookies that are required for the operation of the website – in particular a session cookie to recognise your session, a CSRF token to protect against cross-site request forgery, your language selection, the contents of your shopping cart and – if active – a preview cookie.

No consent is required for storing this strictly necessary information pursuant to § 25 (2) no. 2 TDDDG; the associated processing is based on Art. 6 (1)(f) GDPR. No tracking, analytics or advertising cookies and no services for reach-based profiling are used.

07Account & registration

You can create a user account to purchase modules. We process your name, e-mail address, an encrypted password and your preferred language. The legal basis is Art. 6 (1)(b) GDPR (establishment and performance of the usage relationship).

You can have your account deleted at any time. Statutory retention obligations (e.g. for completed purchases) remain unaffected; the data concerned will be blocked from further use.

08Orders, licenses & invoices

As part of an order, we process the data required to perform the contract: purchased modules, order and invoice data including the billing address, issued license keys and associated activation information. For evidence purposes we also store your express consent to immediate performance given during the order process, together with its timestamp (§ 356 (5) BGB). The legal basis is Art. 6 (1)(b) GDPR and – for retention – Art. 6 (1)(c) GDPR in conjunction with commercial and tax law obligations.

We retain invoices and accounting records in accordance with statutory periods (generally up to 10 years pursuant to § 147 AO and § 257 HGB).

09Payment processing via Stripe

To process payments we use the payment service provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland; for certain processing also Stripe, Inc., USA). When you initiate a payment, we transmit to Stripe the order data required for processing (in particular the order reference, line items and invoice amount). Name, e-mail address and means of payment are entered by you directly on the payment page operated by Stripe; we do not receive these complete payment details.

Complete payment data such as credit card numbers is entered and processed exclusively by Stripe (PCI-DSS certified); we do not receive or store it. The legal basis is Art. 6 (1)(b) GDPR (performance of a contract) and our legitimate interest in secure payment processing (Art. 6 (1)(f) GDPR). Details can be found in Stripe’s privacy policy at stripe.com/privacy.

10Module license validation

Purchased modules contain a license client that communicates with our license interface (api.perfexcrm-module.com or perfexcrm-module.com/api) for activation and update checks. The following are transmitted: the license key, an installation identifier (derived from the domain/URL of the Perfex installation), the Perfex version and the PHP version. For technical reasons we additionally process the IP address of the requesting server; when retrieving signed update downloads, also the time and user agent. This connection is made by the buyer’s installed software (typically on the buyer’s own server).

The purpose is to enforce the licensing terms (activation limits per license type), to deliver signed updates within the update window and to protect against misuse. The legal basis is Art. 6 (1)(b) GDPR (performance of the license agreement) and Art. 6 (1)(f) GDPR (protection against misuse). Responses from the interface are cryptographically signed (Ed25519); no profiling beyond the stated purposes takes place.

11Newsletter & launch notifications

If you sign up for our newsletter or launch notifications, we process your e-mail address, your language selection, the IP address at the time of sign-up and timestamps of sign-up and unsubscribe. We use the double opt-in procedure: after sign-up we send a confirmation e-mail and only add you to the list after you confirm. We store the IP address and timestamps to document your consent (Art. 7 (1) GDPR).

The legal basis is Art. 6 (1)(a) GDPR (consent). You can withdraw your consent at any time with effect for the future, e.g. via the unsubscribe link in every e-mail. E-mails are sent via our own mail server; no external newsletter service provider is used.

12Module uploads & malware scan

The module packages offered for sale are stored on our servers and scanned for malware using the open-source antivirus software ClamAV before publication. This scan is performed locally on our infrastructure; no content is transmitted to third parties. The legal basis is our legitimate interest in the security of our offering (Art. 6 (1)(f) GDPR).

13Reviews

Buyers can review purchased modules. We process your display name, the rating (stars) and the review text as well as the information that it is a verified purchase. Published reviews are publicly visible. The legal basis is Art. 6 (1)(a) and (b) GDPR. You can have a review you submitted deleted at any time.

14Contacting us

If you contact us by e-mail, we process the data you provide in order to handle your enquiry and in case of follow-up questions. The legal basis is Art. 6 (1)(b) GDPR insofar as the enquiry relates to a contract, otherwise Art. 6 (1)(f) GDPR (interest in answering enquiries). We delete this data as soon as it is no longer required and no retention obligations prevent deletion.

15Transfers to third countries

Insofar as processing takes place outside the EU/EEA – in particular in the USA – within the scope of payment processing (Stripe), this is safeguarded by appropriate guarantees: the EU Commission’s standard contractual clauses (Art. 46 GDPR) and, where applicable, certification of the recipient under the EU-US Data Privacy Framework. We will provide a copy of the safeguards on request.

16Retention periods

We store personal data only for as long as is necessary for the respective purposes or as provided for by statutory retention periods. Once the purpose no longer applies and any retention periods have expired, the data is deleted or anonymised.

17Data security

We take appropriate technical and organisational measures to protect your data against loss, manipulation and unauthorised access. Data is transmitted exclusively in encrypted form via TLS (HTTPS). Passwords are stored only as a cryptographic hash. Our measures are continuously adapted in line with technological developments.

18Validity & changes

This privacy policy is currently valid and has the status indicated above. As our offering develops or due to changes in legal or regulatory requirements, it may become necessary to amend this policy. The current version can be accessed at any time on this page.

This document was last updated: 6 July 2026. In case of discrepancies between the German and English versions, the German version prevails.

Continue to: Imprint Terms Licensing