Information on the Processing of Personal Data on perfunctio.eu
This Privacy Policy informs you about what personal data PPS Perfunctio Payment Services GmbH processes when you use this website and its contact options, for what purposes this is done, and what rights you have.
As of September 10, 2026
PPS Perfunctio Payment Services GmbH
Astra Tower, Zirkusweg 2
20359 Hamburg, Germany
Email: info@perfunctio.eu
Phone: +49 40 637 93 018
Attorney Kaspar-Ludwig Stolzenhain
24 Joachimsthaler Street
10719 Berlin, Germany
Questions regarding data protection may also be directed to info@perfunctio.eu.
Personal data is any information relating to an identified or identifiable natural person. We process personal data only if there is a legal basis for doing so and the processing is necessary for a specific purpose.
This statement applies to the website perfunctio.eu, the contact options offered there, and the data processing described below. Additional privacy notices may apply to specific services and technical payment processing if additional data is processed in connection with them.
When you visit the website, technically necessary connection data is processed. This may include your IP address, the date and time of access, the page or file accessed, the referrer URL, browser type and version, operating system, the amount of data transferred, and the HTTP status.
The purpose of this processing is to host the website, ensure stability and security, analyze errors, and detect and prevent unauthorized access. The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in the secure and reliable operation of our online services.
The website is hosted on Webflow. The provider is Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA. Webflow processes hosting, content, connection, and form data as a data processor in accordance with our instructions. Data from website visitors may be stored and processed in the United States.
Webflow is certified under the EU-U.S. Data Privacy Framework. To the extent that this adequacy decision does not apply, the agreement with Webflow specifically provides for the European Commission’s Standard Contractual Clauses. Further information and the applicable safeguards are available in Webflow’s Privacy Policy and Data Processing Agreement:
Webflow Privacy Policy · Webflow Data Processing Agreement
Server logs are stored only as long as necessary for operations, error analysis, and security. Data required to investigate a specific security incident or to safeguard legal claims may be stored for a longer period until the respective matter is resolved.
Our website uses cookies, local storage, scripts, and similar technologies. Technically necessary technologies are used to operate the website, ensure security, and save your privacy settings. Optional analytics technologies are used only with your consent.
For the storage of or access to information on your device that is not technically necessary, § 25(1) of the TDDDG applies; and, to the extent that personal data is processed, Article 6(1)(a) of the GDPR applies. For strictly necessary processes, § 25(2) of the TDDDG applies; the subsequent processing of personal data is based, depending on the purpose, in particular on Article 6(1)(c) or (f) of the GDPR.
Your consent is voluntary and may be revoked or modified at any time with future effect via the permanently accessible cookie settings. The lawfulness of the processing carried out prior to revocation remains unaffected. The specific cookies used, their providers, purposes, and durations are displayed in the consent tool.
We use CookieScript as our consent management platform. The provider is Objectis, UAB, Laisvės pr. 60, LT-05120 Vilnius, Lithuania. CookieScript may process a randomly generated key, your selection, a truncated IP address, the date and time, the page on which the selection was made or revoked, and browser information. The key and the consent status are stored in the required “CookieScriptConsent” cookie.
The processing is used to manage optional services, save your selections, and provide evidence of consent granted or denied. Access to the end device is required under Section 25(2)(2) of the TDDDG. Further processing is based on Article 6(1)(c) of the GDPR in conjunction with Article 7(1) of the GDPR, as well as, supplementarily, on Article 6(1)(f) of the GDPR. Our legitimate interest lies in reliable and user-friendly consent management.
The retention period is determined by the duration displayed in the consent tool. Records of consent are stored only as long as necessary to demonstrate compliance with the law and to defend against potential claims.
CookieScript transmits your selection to integrated Google services via Google Consent Mode. These signals determine, in particular, whether analytics or advertising cookies may be used. If consent is not granted or is denied, the corresponding cookie access remains disabled.
Under the expanded Google Consent Mode, Google tags can send so-called “cookieless pings” to Google even if consent has not been granted or has been denied. No analytics or advertising cookies are stored on or read from your device. However, technical information such as the time, user agent, referrer, consent status, and a temporarily processed IP address may be transmitted.
Among other things, these signals are used for technical measurement and modeling, without identifying you on our website through the use of analytics or advertising cookies. Analytics or advertising cookies will not be stored or accessed, nor will any further measurements be taken, until you have given your consent in accordance with Section 25(1) of the TDDDG and Article 6(1)(a) of the GDPR.
With your consent, we use Google Analytics 4 to analyze website usage statistics and to improve content and features. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google may use other companies within the Google Group as service providers.
Regardless of this, under the expanded Google Consent Mode described in section 6, cookieless pings may be sent to Google even if consent has not been granted or has been denied.
In particular, the following data may be processed: page views, interactions, the time and duration of use, referrers, device and browser information, approximate location data, and pseudonymous identifiers. For visitors from the EU, Google states that it uses the IP address to derive an approximate location and then discards it.
The legal basis is Section 25(1) of the TDDDG and Article 6(1)(a) of the GDPR. You may revoke your consent at any time via the cookie settings. The duration of the cookies used is displayed in the consent tool. User- and event-related data is stored in accordance with the retention period set in our Google Analytics property and subsequently deleted; aggregated reports may remain available for a longer period.
Data may be processed in the United States. Google LLC is certified under the EU-U.S. Data Privacy Framework. To the extent that the Adequacy Decision does not apply, appropriate safeguards—in particular, standard contractual clauses—will be implemented.
Our contact forms use Cloudflare Turnstile to detect and block automated submissions, spam, and malicious access. The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. During the check, the following data may be processed: IP address, device and browser information, time, referrer, technical interactions, and the result of the check. The check may take place as soon as the form is accessed or used.
This measure is intended to ensure the security of our website and contact channels. The access to the end device required for this purpose is governed by Section 25(2) of the TDDDG. The processing of personal data is based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in preventing automated and fraudulent form submissions.
Cloudflare may process data in the United States and other countries. Data transfers are carried out in accordance with Articles 44 et seq. of the GDPR, in particular on the basis of an adequacy decision or appropriate safeguards. The data will be processed only for as long as necessary for security checks and to prevent misuse.
If you contact us by email, phone, or through one of our contact forms, we will process the information you provide. This may include, in particular:
We process this data to review and respond to your inquiry and to communicate with you. If the inquiry relates to a contract or precontractual measures with us, the processing is based on Article 6(1)(b) of the GDPR. In other cases, it is based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in the proper handling and documentation of inquiries.
Please do not submit complete account, card, identification, or login information, or any special categories of personal data, via the contact forms. Information regarding a payment transaction should be limited to what is necessary for processing the transaction.
If you are unable to identify a debit transaction, we will use the reference and transaction details you have provided to determine the relevant client, merchant, or other contractual partner. To the extent necessary to process your inquiry, we may transmit the required information to the relevant company as well as to participating banks or payment service providers, or receive supplementary allocation information from them. In doing so, we limit the data to what is strictly necessary.
Processing is based, to the extent it is necessary for the performance of a contract or precontractual measures, on Article 6(1)(b) of the GDPR and, in all other cases, on Article 6(1)(f) of the GDPR. Our legitimate interests lie in resolving payment inquiries, preventing misuse, and assisting data subjects in identifying the appropriate contact person. If the company from which you ordered the service is solely responsible, you will find further information in its privacy policy.
Form submissions are transmitted via Webflow’s technical infrastructure and can be stored in the Webflow Forms section as well as forwarded as a notification to the communication systems we use. Recipients are limited to individuals and service providers who need the data to process the request.
We delete contact requests as soon as they have been fully processed and there are no legal retention requirements, security interests, or reasons to assert, exercise, or defend legal claims that prevent us from doing so. If a request is related to a business or payment relationship, the applicable statutory and contractual retention periods apply.
In connection with inquiries and business relationships, we process master data, contact information, contract details, billing information, payment information, and communication data. This processing is used to initiate, conduct, and manage business relationships; provide customer service; fulfill legal obligations; ensure security; and protect and enforce legal claims.
The legal bases are Article 6(1)(b) of the GDPR for contracts and precontractual measures, Article 6(1)(c) of the GDPR for legal obligations, and Article 6(1)(f) of the GDPR for proper business organization, security, prevention of misuse, and legal enforcement.
To the extent that we provide technical support for payments on behalf of a company, the allocation of roles under data protection law is determined by the specific order and the actual processing activities. The company from which you ordered the relevant service is generally responsible for the underlying customer relationship. Depending on the nature of the processing, Perfunctio may act as a data processor or, for certain purposes of its own, as a data controller. The privacy policy of the relevant company, as well as any supplementary information from Perfunctio, applies.
Business and payment records are retained in accordance with the statutory retention periods under commercial and tax law. Other data is deleted or anonymized as soon as it is no longer necessary for the respective purpose and there are no legal obligations or legitimate reasons for retaining it longer.
Within our company, only those individuals who need personal data to perform their duties are granted access to it. External recipients may include, in particular:
Data processors are contractually bound under Article 28 of the GDPR. Data will only be disclosed if it is necessary for the specific purpose and legally permissible.
Processing outside the European Union or the European Economic Area takes place only if the requirements of Articles 44 et seq. of the GDPR are met. We base such transfers, in particular, on an adequacy decision by the European Commission—including the EU-U.S. Data Privacy Framework for appropriately certified recipients—or on standard contractual clauses with the necessary supplementary safeguards.
Information about the guarantee applied to a specific recipient, as well as instructions on how to obtain or view a copy, can be found in the relevant section of this statement or is available upon request at info@perfunctio.eu.
We can use Google Search Console and Semrush as internal tools for technical monitoring, search engine optimization, and keyword and competitive analysis. These tools are not integrated into this website as standalone tracking scripts. Therefore, simply visiting our website does not result in any additional visitor data being transmitted directly to Semrush by us; Search Console provides reports within the scope of Google Search.
To the extent that we analyze summary reports on the discoverability and technical quality of our website, this is based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in the technical monitoring and improvement of our content. Account and usage data of our employees or service providers are processed by the respective providers in accordance with their own terms and conditions.
We store personal data only for as long as it is needed for the respective purpose. We then delete or anonymize it, unless longer retention is required by legal retention obligations, security interests, or reasons related to asserting, exercising, or defending legal claims.
The applicable criteria and, where available, specific time limits are listed in the relevant sections of this statement. The durations of cookies and similar technologies are also displayed in the consent tool.
Under the terms of the law, you have the following rights in particular:
To exercise your rights, you can contact info@perfunctio.eu or our Data Protection Officer.
In particular, you may file a complaint with the supervisory authority in your usual place of residence, your place of work, or the location of the alleged violation. The following authority generally has jurisdiction over our company:
The Hamburg Commissioner for Data Protection and Freedom of Information
22 Ludwig-Erhard-Straße
20459 Hamburg, Germany
Phone: +49 40 42854-4040
Email: mailbox@datenschutz.hamburg.de
If we process personal data pursuant to Article 6(1)(f) of the GDPR, you may object at any time on grounds relating to your particular situation. You may object at any time to processing for direct marketing purposes without having to provide specific reasons.
We take appropriate technical and organizational measures to protect personal data from loss, alteration, unauthorized access, and unauthorized disclosure. The website uses an encrypted HTTPS connection. Our security measures are reviewed and adjusted in accordance with the level of risk and the state of the art.
In connection with the website data processing described in this Privacy Policy, we do not make any decisions based solely on automated processing that have legal effects on you or similarly significantly affect you.
We will update this Privacy Policy if there are changes to the legal landscape, the website, the services we use, or our data processing procedures. The version currently published on the website is the one that applies.