Privacy Notice
for the Merkursoft backoffice system with XML import, AI functions, accounting and invoicing
Status: July 2026
This Privacy Notice provides information on the processing of personal data by Merkursoft when using the website, making contact, entering into a contract and using the Merkursoft backoffice system. It replaces older privacy texts dated 11 February 2019.
1. Controller
The controller within the meaning of Art. 4 No. 7 GDPR is: Merkursoft, Kernerweg 22, 89520 Heidenheim a. d. Brenz, Germany, email: info@merkursoft.de.
Where an authorised representative must be specified, the person named in the legal notice or offer shall apply. Privacy enquiries may be sent at any time to info@merkursoft.de.
2. Data protection role regarding customer data
For personal data that customers enter into the backoffice system, import into it or have processed there, the respective customer is generally the controller. This applies in particular to data of end customers, suppliers, employees, contacts, invoice, booking, travel, payment or communication data.
Merkursoft generally processes this data as processor under Art. 28 GDPR and only in accordance with the contract, the Data Processing Agreement, documented instructions of the Customer or statutory obligations.
The Customer is responsible for the lawfulness of data collection, the information of data subjects, required consents, erasure and retention periods and the handling of data subject rights vis-a-vis its end customers.
3. Processing categories
The following overview describes the most important processing activities. Depending on the booked scope of services, individual activities may not apply or additional activities may be added.
| Area | Data categories | Purpose and legal basis | Recipients / processors | Retention period |
|---|---|---|---|---|
| Website and server logs | IP address, date and time, accessed page, browser, operating system, referrer, status codes | Provision of the website, security and error analysis; Art. 6(1)(f) GDPR; technically necessary access under Section 25(2) TDDDG | Hosting via Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | Usually 7 to 30 days; longer only in the event of security incidents |
| Contact by email or form | Name, company, email address, telephone number, message, attachments | Handling the request; Art. 6(1)(b) GDPR where contract-related, otherwise Art. 6(1)(f) GDPR | Merkursoft; email/hosting service providers | Until final handling of the request; where business-related, in accordance with statutory retention periods |
| Customer account and contract management | Master data, users, roles, login data, contract data, invoice data, payment status | Provision and administration of the customer account, billing and support; Art. 6(1)(b) and (c) GDPR | Merkursoft; hosting; payment service providers/banks where required | For the contract term; tax and commercial-law documents usually 10 years |
| Use of the backoffice system | User activities, settings, import logs, system messages, invoice/booking data, documents, XML import data | Provision of the SaaS functions, troubleshooting and security; Art. 6(1)(b) GDPR; for customer data usually processing on behalf of the controller under Art. 28 GDPR | Merkursoft as processor; Hetzner Online GmbH as hosting subprocessor | For the contract term; deletion or return after contract end in accordance with the agreement/DPA |
| AI functions | Inputs, document content, structured data, prompts, metadata, technical logs | Automated assistance for import, classification, summarisation, invoice/booking and backoffice processes; Art. 6(1)(b) GDPR or Art. 28 GDPR for customer data | Merkursoft; if external AI services are activated, AI service providers named in the subprocessor list | Only as long as required for the function and traceability; details per service in the product/subprocessor list |
| Support and error analysis | Contact data, ticket content, screenshots, system logs, affected data records insofar as provided by the Customer | Handling support cases, quality assurance and evidence; Art. 6(1)(b) and (f) GDPR | Merkursoft; where applicable support and hosting service providers | Usually up to 3 years after completion, unless longer statutory obligations apply |
| Newsletter / promotional communication | Email address, name, company, consent and dispatch data | Dispatch only with consent or statutory permission; Art. 6(1)(a) GDPR or Art. 6(1)(f) GDPR | Merkursoft; mailing service provider if used | Until withdrawal or objection; proof of consent up to 3 years |
4. Cookies and comparable technologies
The website and the backoffice system use technically necessary cookies or comparable technologies to provide login, session, security, language settings and basic functions. These technologies are required so that the expressly requested digital service can be provided.
Non-essential cookies, tracking, analytics or marketing services are used only if the user has previously given valid consent. Consent that has been granted may be withdrawn at any time with effect for the future.
The earlier wording according to which consent to cookies is declared by merely using the website is replaced by this differentiated provision.
5. Google Maps / Places and other third-party functions
Where Google Maps, Google Places Autocomplete or comparable third-party functions are used in individual modules, this is done only for the respective purpose, for example address search or location support.
Technical data such as IP address, location/address data and usage data may be transmitted to the respective provider. Details of actively used third-party functions must be made available in the product description, cookie/consent management or a separate service list.
6. Google account & email sending (Gmail)
If you connect your Google account to send email from MerkurTravel, we request two permissions: the ability to send email on your behalf (the gmail.send scope) and access to your Google account's email address (the userinfo.email scope). We use these solely to deliver the invoices and payment reminders you send to your customers from your own mailbox, and to show you which account is connected.
MerkurTravel does not read, import, or store the contents of your inbox, and we never use this data for advertising or sell it to third parties. The OAuth access and refresh tokens required to send on your behalf are stored encrypted. You can disconnect the mailbox at any time in your agency settings, which deletes the tokens we hold, or fully revoke the grant from your Google Account's security page.
MerkurTravel's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
7. AI functions and transparency
When AI functions are used, inputs, documents, import data, metadata and system context may be processed automatically in order to generate suggestions, classifications, summaries, extractions or other assistant services.
AI functions are intended to provide support. They do not make independent legally binding decisions by Merkursoft in relation to the Customer's end customers. The Customer must check results before using them and decides on their use itself.
Where external AI service providers are used, they are engaged in accordance with the Data Processing Agreement and the subprocessor list. Personal data should only be transmitted to AI functions to the extent necessary for the specific purpose.
8. Recipients and subprocessors
Personal data is disclosed to recipients only insofar as this is necessary for contract performance, operation of the systems, billing, statutory obligations, security purposes or enforcement of legitimate claims.
Hosting is provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Other service providers may include email, support, payment, security, backup or AI services, provided they are required for the specific scope of services.
Where service providers process personal data on behalf of Merkursoft, Data Processing Agreements are concluded.
9. Transfers to third countries
Personal data is transferred to countries outside the European Union or the European Economic Area only if there is a suitable legal basis, for example an adequacy decision, EU Standard Contractual Clauses or explicit consent.
If third-party functions with a possible third-country connection are activated, the affected users or customers are informed about this in the product, privacy or consent information.
10. Retention period
Merkursoft stores personal data only for as long as this is required for the respective purposes or statutory retention obligations exist.
Contact and support data is regularly deleted once the request has been completed and no statutory retention or evidentiary obligations exist. Contract, invoice and booking documents are regularly stored in accordance with commercial and tax-law retention obligations.
Customer data in the backoffice system is returned or deleted after the end of the contract in accordance with the contract and the Data Processing Agreement, unless statutory obligations prevent this.
11. Data subject rights
Data subjects have the rights of access, rectification, erasure, restriction of processing, data portability and objection to certain processing activities in accordance with the GDPR.
Where processing is based on consent, consent may be withdrawn at any time with effect for the future. The lawfulness of processing until withdrawal remains unaffected.
Data subjects also have the right to lodge a complaint with a data protection supervisory authority. The competent authority may in particular be the authority of the habitual place of residence, workplace or registered office of Merkursoft.
For data that a Customer processes as controller in the backoffice system, data subject rights must generally be asserted against the respective Customer. Merkursoft supports the Customer within the framework of the Data Processing Agreement.
12. Security
Merkursoft uses appropriate technical and organisational measures to protect personal data against loss, destruction, unauthorised access, manipulation or disclosure.
These measures may include transport encryption, access controls, role and rights concepts, logging, backup procedures, authorisation concepts, security updates and organisational safeguards.
The Customer is obliged to appropriately protect its own user accounts, passwords, end devices and internal authorisations.
13. Updating this Privacy Notice
Merkursoft may update this Privacy Notice if the legal situation, technical processes, functions, service providers or business processes change. The current version is made available on the website or in the customer area.