011. Person responsible and contact
The person responsible for PartnerConnect is:
AEGIS SECURITAS
Udo Neidhart
Hansaring 7
63843 Niedernberg
Germany
Email: service@aegis-securitas.de
This declaration supplements the general data protection declaration of AEGIS-SECURITAS for the special processing in the partner program.
022. Applications and partner profiles
When you apply, we process in particular your name, business contact details, company, website, country, partner model, focus, regions, motivation as well as verification and status information. The processing serves to carry out pre-contractual measures, to decide on acceptance and then to carry out the partner contract. The legal basis is Article 6 Paragraph 1 Letter b GDPR. Security, misuse and compliance checks are also based on Art. 6 Para. 1 lit. f GDPR.
An application does not constitute a right to admission. We generally delete rejected application data no later than six months after completion of the examination, provided that there are no legal obligations, legal claims or permissible longer storage to the contrary.
033. Partner Account, Portal and Log Data
For the partner account, we process identity and account data, roles, partner status, level, commission conditions, portal access, security events, session and device information, support processes as well as evidence of the accepted version of the partner terms and data protection notices.
The purposes are contract execution, access protection, misuse prevention, proof of declarations, error analysis and protection of our systems. The legal basis is Article 6 Paragraph 1 Letter b and Letter f GDPR. Security and access logs are regularly deleted after twelve months, unless they are no longer needed to resolve an incident, legal claims or legal obligations.
044. Deal registrations and contact details
As part of a deal registration, partners can submit data of business contacts, in particular company, name, business email address, telephone number, interest, deal phase and notes. The transmitting partner is responsible for ensuring that the collection and transmission is carried out lawfully and that the data subject is properly informed.
If we do not receive the data directly from the person concerned, we process it to check the recommendation, initiate a contract, avoid double assignments, communicate and document the sales process. Depending on the case, the legal basis is Art. 6 Para. 1 lit. b GDPR if the data subject has initiated a contract themselves, or Art. 6 Para. 1 lit. f GDPR. Our legitimate interest lies in processing demonstrably qualified business inquiries, protecting existing sales relationships and preventing abusive multiple registrations.
The data subject can object to the processing based on legitimate interests at any time for reasons relating to their particular situation. Unchecked or rejected lead data will generally be deleted no later than six months after completion of the check, unless there is another legal basis or obligation for further storage.
055. Deals, Commissions and Billing
We process deal status, protection periods, contract and payment reference, commission rate, calculation basis, amounts, tax and payment data, invoices, credit notes and payout references. This serves the purpose of contract execution and billing in accordance with Article 6 Paragraph 1 Letter b GDPR as well as the fulfillment of commercial and tax obligations in accordance with Article 6 Paragraph 1 Letter c GDPR.
Billing and booking documents are stored in accordance with the statutory retention periods. Portal values may represent preliminary calculations before they are released.
066. API keys, integrations and technical reviews
For API and integration usage, we process key prefixes and hashes, permissions, creation, use and revocation times, technical requests, errors, IP and security information as well as submitted integration descriptions, documentation and test results.
The purposes are to provide and secure the interfaces, detect misuse, quality and security checks and publish approved integrations. The legal basis is Article 6 Paragraph 1 Letter b and Letter f GDPR. Secret API keys are not stored in plain text and are only displayed once after they are created.
077. Communication, Support and Optional Information
We use contact information for contract-related messages, status changes, security information, billing and support. The legal basis is Article 6 Paragraph 1 Letter b GDPR. Legally required notifications are based on Article 6 Paragraph 1 Letter c GDPR.
We only send product news, events or sales information by electronic mail if there is a permissible legal basis for this. Consent given voluntarily can be revoked at any time with future effect without this affecting participation in the contract.
088. Recipients and service providers used
Data is only received internally by people who need it for partner verification, sales, billing, technology, security or support. We use processors and technical service providers, in particular for platform operation, hosting, databases, logging, email sending and, if necessary, payment processing.
The service provider groups currently relevant to our platform include, in particular, Base44 or Wix and their sub-processors, Resend for email sending and Stripe, insofar as payment functions are used. Data will also be transmitted to tax advisors, legal advisors, authorities or courts if this is necessary or required by law.
The necessary data protection agreements are concluded with processors.
099. Third country transfers
Individual service providers or their sub-processors may process data outside the European Economic Area, in particular in the USA, the United Kingdom or Israel. A transfer will only take place in compliance with the legal requirements, for example on the basis of an adequacy decision, the EU-US Data Privacy Framework, EU standard contractual clauses and additional protective measures.
We therefore do not claim that all processing takes place exclusively in Germany or the European Union. We provide specific information about the sub-processors used upon request or in the Trust Center.
1010. Storage period
We only store personal data for as long as it is necessary for the respective purpose. During an active partnership, partner, contract, deal and portal information is generally processed for the duration of the contract.
After the end of the contract, the following principles apply in particular:
• Application dates for rejected applicants: generally six months after completion of the examination.
• Unverified or rejected lead data: generally six months after completion of the verification.
• Contract, billing and tax-relevant documents: in accordance with the statutory retention periods.
• Security and access protocols: generally twelve months.
• Support and dispute data: until final processing and then according to possible statute of limitations.
Longer storage only takes place if legal obligations, consent or the assertion, exercise or defense of legal claims justify this.
1111. Mandatory information and automated decisions
Information marked as mandatory fields is required for application, contract, deal review or technical provision. Without this information, the respective function cannot be offered.
We do not make exclusively automated decisions with legal or similarly significant effects regarding inclusion, deal allocation or commission release. Automatic hints, duplicate checks and calculations support human checking, but do not replace it.
1212. Your Rights
In accordance with the legal requirements, you have the right to information, correction, deletion, restriction of processing, data portability and objection. Consent given can be revoked at any time with future effect.
In the case of processing based on Article 6 Paragraph 1 Letter f of the GDPR, you can object for reasons arising from your particular situation. You can object to direct advertising at any time without any particular justification.
Please send inquiries to service@aegis-securitas.de. You also have the right to complain to a data protection supervisory authority. The Bavarian State Office for Data Protection Supervision is particularly responsible for our headquarters.
1313. Security
We take appropriate technical and organizational measures to protect personal data. This includes, in particular, encrypted transmission, role-based access, server-side client and authorization checks, hashing of secret API keys, logging of security-relevant changes and options for revoking access.
No internet-based system can guarantee absolute security. Partners must adequately protect access data and devices and report security incidents immediately.
1414. Cookies, local storage and modifications
PartnerConnect uses technically required storage and access functions for login, security, language, presentation and portal operation. Unnecessary analysis or marketing technologies will only be used if there is effective consent or other legal permission.
We will update this statement if the legal situation, service providers or functions change significantly. The current version is available on PartnerConnect. Significant changes will be indicated appropriately.