Privacy Notice

for the Merkursoft backoffice system with XML import, AI functions, accounting and invoicing

Status: July 2026

This Privacy Notice provides information on the processing of personal data by Merkursoft when using the website, making contact, entering into a contract and using the Merkursoft backoffice system. It replaces older privacy texts dated 11 February 2019.

1. Controller

The controller within the meaning of Art. 4 No. 7 GDPR is: Merkursoft, Kernerweg 22, 89520 Heidenheim a. d. Brenz, Germany, email: info@merkursoft.de.

Where an authorised representative must be specified, the person named in the legal notice or offer shall apply. Privacy enquiries may be sent at any time to info@merkursoft.de.

2. Data protection role regarding customer data

For personal data that customers enter into the backoffice system, import into it or have processed there, the respective customer is generally the controller. This applies in particular to data of end customers, suppliers, employees, contacts, invoice, booking, travel, payment or communication data.

Merkursoft generally processes this data as processor under Art. 28 GDPR and only in accordance with the contract, the Data Processing Agreement, documented instructions of the Customer or statutory obligations.

The Customer is responsible for the lawfulness of data collection, the information of data subjects, required consents, erasure and retention periods and the handling of data subject rights vis-a-vis its end customers.

3. Processing categories

The following overview describes the most important processing activities. Depending on the booked scope of services, individual activities may not apply or additional activities may be added.

AreaData categoriesPurpose and legal basisRecipients / processorsRetention period
Website and server logsIP address, date and time, accessed page, browser, operating system, referrer, status codesProvision of the website, security and error analysis; Art. 6(1)(f) GDPR; technically necessary access under Section 25(2) TDDDGHosting via Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, GermanyUsually 7 to 30 days; longer only in the event of security incidents
Contact by email or formName, company, email address, telephone number, message, attachmentsHandling the request; Art. 6(1)(b) GDPR where contract-related, otherwise Art. 6(1)(f) GDPRMerkursoft; email/hosting service providersUntil final handling of the request; where business-related, in accordance with statutory retention periods
Customer account and contract managementMaster data, users, roles, login data, contract data, invoice data, payment statusProvision and administration of the customer account, billing and support; Art. 6(1)(b) and (c) GDPRMerkursoft; hosting; payment service providers/banks where requiredFor the contract term; tax and commercial-law documents usually 10 years
Use of the backoffice systemUser activities, settings, import logs, system messages, invoice/booking data, documents, XML import dataProvision of the SaaS functions, troubleshooting and security; Art. 6(1)(b) GDPR; for customer data usually processing on behalf of the controller under Art. 28 GDPRMerkursoft as processor; Hetzner Online GmbH as hosting subprocessorFor the contract term; deletion or return after contract end in accordance with the agreement/DPA
AI functionsInputs, document content, structured data, prompts, metadata, technical logsAutomated assistance for import, classification, summarisation, invoice/booking and backoffice processes; Art. 6(1)(b) GDPR or Art. 28 GDPR for customer dataMerkursoft; if external AI services are activated, AI service providers named in the subprocessor listOnly as long as required for the function and traceability; details per service in the product/subprocessor list
Support and error analysisContact data, ticket content, screenshots, system logs, affected data records insofar as provided by the CustomerHandling support cases, quality assurance and evidence; Art. 6(1)(b) and (f) GDPRMerkursoft; where applicable support and hosting service providersUsually up to 3 years after completion, unless longer statutory obligations apply
Newsletter / promotional communicationEmail address, name, company, consent and dispatch dataDispatch only with consent or statutory permission; Art. 6(1)(a) GDPR or Art. 6(1)(f) GDPRMerkursoft; mailing service provider if usedUntil withdrawal or objection; proof of consent up to 3 years

4. Cookies and comparable technologies

The website and the backoffice system use technically necessary cookies or comparable technologies to provide login, session, security, language settings and basic functions. These technologies are required so that the expressly requested digital service can be provided.

Non-essential cookies, tracking, analytics or marketing services are used only if the user has previously given valid consent. Consent that has been granted may be withdrawn at any time with effect for the future.

The earlier wording according to which consent to cookies is declared by merely using the website is replaced by this differentiated provision.

5. Google Maps / Places and other third-party functions

Where Google Maps, Google Places Autocomplete or comparable third-party functions are used in individual modules, this is done only for the respective purpose, for example address search or location support.

Technical data such as IP address, location/address data and usage data may be transmitted to the respective provider. Details of actively used third-party functions must be made available in the product description, cookie/consent management or a separate service list.

6. Google account & email sending (Gmail)

If you connect your Google account to send email from MerkurTravel, we request two permissions: the ability to send email on your behalf (the gmail.send scope) and access to your Google account's email address (the userinfo.email scope). We use these solely to deliver the invoices and payment reminders you send to your customers from your own mailbox, and to show you which account is connected.

MerkurTravel does not read, import, or store the contents of your inbox, and we never use this data for advertising or sell it to third parties. The OAuth access and refresh tokens required to send on your behalf are stored encrypted. You can disconnect the mailbox at any time in your agency settings, which deletes the tokens we hold, or fully revoke the grant from your Google Account's security page.

MerkurTravel's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

7. AI functions and transparency

When AI functions are used, inputs, documents, import data, metadata and system context may be processed automatically in order to generate suggestions, classifications, summaries, extractions or other assistant services.

AI functions are intended to provide support. They do not make independent legally binding decisions by Merkursoft in relation to the Customer's end customers. The Customer must check results before using them and decides on their use itself.

Where external AI service providers are used, they are engaged in accordance with the Data Processing Agreement and the subprocessor list. Personal data should only be transmitted to AI functions to the extent necessary for the specific purpose.

8. Recipients and subprocessors

Personal data is disclosed to recipients only insofar as this is necessary for contract performance, operation of the systems, billing, statutory obligations, security purposes or enforcement of legitimate claims.

Hosting is provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Other service providers may include email, support, payment, security, backup or AI services, provided they are required for the specific scope of services.

Where service providers process personal data on behalf of Merkursoft, Data Processing Agreements are concluded.

9. Transfers to third countries

Personal data is transferred to countries outside the European Union or the European Economic Area only if there is a suitable legal basis, for example an adequacy decision, EU Standard Contractual Clauses or explicit consent.

If third-party functions with a possible third-country connection are activated, the affected users or customers are informed about this in the product, privacy or consent information.

10. Retention period

Merkursoft stores personal data only for as long as this is required for the respective purposes or statutory retention obligations exist.

Contact and support data is regularly deleted once the request has been completed and no statutory retention or evidentiary obligations exist. Contract, invoice and booking documents are regularly stored in accordance with commercial and tax-law retention obligations.

Customer data in the backoffice system is returned or deleted after the end of the contract in accordance with the contract and the Data Processing Agreement, unless statutory obligations prevent this.

11. Data subject rights

Data subjects have the rights of access, rectification, erasure, restriction of processing, data portability and objection to certain processing activities in accordance with the GDPR.

Where processing is based on consent, consent may be withdrawn at any time with effect for the future. The lawfulness of processing until withdrawal remains unaffected.

Data subjects also have the right to lodge a complaint with a data protection supervisory authority. The competent authority may in particular be the authority of the habitual place of residence, workplace or registered office of Merkursoft.

For data that a Customer processes as controller in the backoffice system, data subject rights must generally be asserted against the respective Customer. Merkursoft supports the Customer within the framework of the Data Processing Agreement.

12. Security

Merkursoft uses appropriate technical and organisational measures to protect personal data against loss, destruction, unauthorised access, manipulation or disclosure.

These measures may include transport encryption, access controls, role and rights concepts, logging, backup procedures, authorisation concepts, security updates and organisational safeguards.

The Customer is obliged to appropriately protect its own user accounts, passwords, end devices and internal authorisations.

13. Updating this Privacy Notice

Merkursoft may update this Privacy Notice if the legal situation, technical processes, functions, service providers or business processes change. The current version is made available on the website or in the customer area.