Privacy Policy
1. Controller
The controller responsible for data processing on this website and in the KS CRM service within the meaning of the General Data Protection Regulation (GDPR) is:
Khan Solutions (sole proprietorship)
Owner: Bilal Khan
Martin-Luther-Straße 30
46284 Dorsten
Germany
VAT ID: DE366406489
Email: [email protected]
Web: https://kscrm.de
2. General Information
We process personal data only to the extent necessary to provide a functional website and our content and services. Depending on the processing operation, the legal bases are your consent (Art. 6(1)(a) GDPR), the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR), legal obligations (Art. 6(1)(c) GDPR) or our legitimate interests (Art. 6(1)(f) GDPR). We state the applicable legal basis for each individual processing operation.
Important distinction: For data relating to you as a visitor to our website or as a customer (contract and account data), we are the controller. For the data our customers store within their CRM workspace about their own contacts, we act as a processor — see section 10 for details.
3. Hosting and Server Log Files
This website and the service are hosted in a German data center (Nuremberg). Each time the site is accessed, our server automatically records technical data and stores it temporarily in a log file:
- IP address of the requesting device (truncated)
- Date and time of access
- Name and URL of the requested file
- Volume of data transferred
- Browser used and, where applicable, operating system
- Referrer URL
This processing serves to deliver the website, ensure operation and defend against attacks. The legal basis is Art. 6(1)(f) GDPR. Log data is stored for a maximum of 14 days and then deleted automatically.
Cloudflare (DNS, CDN, DDoS protection)
DNS resolution and an upstream CDN/DDoS protection layer are provided by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). In this role, Cloudflare processes technical connection data (in particular the IP address). The legal basis is Art. 6(1)(f) GDPR (interest in secure and performant delivery). Transfers to the USA take place on the basis of the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and the EU-US Data Privacy Framework, under which Cloudflare is certified.
4. Cookies, Local Storage and Consent Management
Our website uses only technically necessary storage access and — solely with your express consent — optional services for audience measurement (Google Analytics).
When you first visit the website, a notice allows you to accept or decline optional services. We store your decision locally in your browser (localStorage entry kscrm_consent_v1) so that you are not asked again. The legal basis for technically necessary storage access is Section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG); for optional services, your consent (Section 25(1) TDDDG, Art. 6(1)(a) GDPR).
You may revoke your consent at any time with effect for the future by deleting the kscrm_consent_v1 entry in your browser's local storage or by contacting us by email.
5. Google Analytics 4 (with Consent Mode v2)
This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
What we do
- We use Google Consent Mode v2: before you give consent, no personal tracking data is transmitted to Google — Google receives only anonymized, aggregated pings without identifiers.
- Cookies are set and tracking data transmitted to Google only after your express consent (clicking "OK" in the cookie notice).
- IP addresses are truncated before storage (IP anonymization).
Data processed
- Anonymized IP address
- Referrer URL, page visited, browser, operating system, device type, screen resolution
- Click and scroll behavior within the website
- Geographic region (country/city, not precise location)
Legal basis and transfers
The legal basis is your consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG). Transfers to the USA take place exclusively on the basis of the EU Standard Contractual Clauses and the EU-US Data Privacy Framework.
Storage period
Cookies set by Google Analytics have a maximum lifetime of 13 months. Aggregated data is retained longer for analysis purposes but can no longer be attributed to individual persons.
Withdrawal
You may withdraw your consent at any time by clearing your browser's localStorage or by installing the Google Analytics opt-out browser add-on.
6. Google Fonts
To display fonts consistently, this website embeds fonts from Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). When you access a page, your browser loads the required fonts from Google servers; in the process, your IP address is transmitted to Google. The legal basis is Art. 6(1)(f) GDPR (interest in a consistent and appealing presentation); transfers to the USA take place on the basis of the EU Standard Contractual Clauses and the EU-US Data Privacy Framework. Further information is available in Google's privacy policy.
7. Registration and User Account
When you create an account, we process the data you provide — name, email address, company and password (stored exclusively as a salted hash) — for the performance of the contract pursuant to Art. 6(1)(b) GDPR. We also use your email address to send the confirmation email and for service-related communications (e.g. security and maintenance notices, invoices, changes to the contractual terms).
We store your account data for as long as your account is active. When your account is deleted, your personal data is erased unless statutory retention periods (e.g. under the German Commercial Code (HGB) and Fiscal Code (AO): 6 or 8 years for business and accounting records) require otherwise; in that case, processing is restricted.
8. Payment Processing (Stripe)
For paid plans we use the payment service provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland). Stripe processes the data required for payment (e.g. name, email address, billing address, payment method details, amount) partly as an independent controller and partly on our behalf. Full credit card details are processed exclusively by Stripe and never reach our servers.
The legal basis is Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(c) GDPR (retention obligations under commercial and tax law). Where Stripe transfers data to the USA, this takes place on the basis of the EU Standard Contractual Clauses and the EU-US Data Privacy Framework. Further information: Stripe Privacy Policy.
9. Email Delivery
Transactional emails (account confirmation, password reset, security notices, invoices) are sent via our mail provider netcup GmbH (Daimlerstraße 25, 76185 Karlsruhe, Germany); servers are located in Germany. The legal basis is Art. 6(1)(b) GDPR. We send marketing emails only with your separate consent (Art. 6(1)(a) GDPR), which you may withdraw at any time.
10. Data in the CRM Workspace (Processing on Behalf)
As a customer, you store personal data about your own contacts (e.g. names, contact details, communication and order history) in your KS CRM workspace. For this data, you are the controller within the meaning of the GDPR; we process it exclusively on your behalf and in accordance with your instructions as a processor pursuant to Art. 28 GDPR.
- The basis is the Data Processing Agreement (DPA), including the technical and organizational measures (Art. 32 GDPR), which forms part of the service contract.
- Each workspace is logically separated and has its own database.
- Data is stored in data centers within the European Union (Germany).
- After the end of the contract, you can export your data for 30 days; it is then deleted (see Section 9 of the Terms of Service).
Data subjects whose data a customer has stored in its workspace should contact the respective customer as controller to exercise their data subject rights; we support our customers in this within the scope of the DPA.
11. AI Assistant (Anthropic)
KS CRM includes optional AI-supported features (e.g. an AI assistant). To provide them, we use Anthropic (Anthropic, PBC, 500 Howard Street, San Francisco, CA 94105, USA) as a sub-processor.
- Content (e.g. your prompts to the assistant and the CRM data required for them) is transmitted to Anthropic only when you actively use an AI feature.
- Under Anthropic's API terms, content submitted via the API is not used to train AI models.
- Transfers to the USA take place on the basis of the EU Standard Contractual Clauses and the EU-US Data Privacy Framework.
The legal basis is Art. 6(1)(b) GDPR (provision of the contractually agreed feature); to the extent customer data from the workspace is affected, processing takes place as processing on behalf pursuant to section 10. Further information: Anthropic Privacy Policy.
12. Storage Periods
Unless stated otherwise in this policy, we store personal data only for as long as necessary for the purposes stated. Data is then deleted or — where statutory retention obligations apply (in particular under the HGB and AO) — restricted until those periods expire and deleted afterwards.
13. Data Security
Data transmitted between your browser and our servers is encrypted using TLS (HTTPS). We implement technical and organizational measures pursuant to Art. 32 GDPR to protect your data against loss, misuse and unauthorized access, and we adapt these measures to the state of the art on an ongoing basis. Passwords are stored exclusively as salted hashes.
14. Your Rights
You have the following rights with regard to your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to withdraw consent with effect for the future (Art. 7(3) GDPR)
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de. You may, however, also contact the supervisory authority of your habitual residence.
15. Contact for Data Protection Enquiries
For all questions concerning the processing of your personal data or the exercise of your rights, please contact: [email protected]
16. Changes to this Privacy Policy
We update this privacy policy when the legal situation, our services or the service providers we use change. The current version published on this page applies.