Privacy Policy
Effective date: July 2026
TaxSync GmbH ("TaxSync", "we", "us") takes the protection of your personal data seriously. This privacy policy explains what data we collect when you visit our website taxsync.eu, use our platform, or contact us, and how we process it.
This policy complies with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the German Federal Data Protection Act (BDSG).
1. Controller
The controller responsible for data processing on this website is:
TaxSync GmbH
[Street Address]
[Postal Code] [City], Germany
Email: privacy@taxsync.eu
If you have questions about data protection, contact us at privacy@taxsync.eu.
2. Data We Collect
Account Data:
- Name (first name, last name)
- Business email address
- Phone number (optional)
- Job function and department
- Company affiliation and role
Company Data:
- Company name, registered address, and country of incorporation
- Industry classification and packaging role (producer, importer, brand owner, toll manufacturer)
- LUCID registration numbers and dual-system provider information (where applicable)
- GS1 Global Location Number (GLN) and GS1 Company Prefix
Packaging and Compliance Data:
- Product catalogue data: names, GTINs, packaging types, and hierarchies
- Material compositions: types, weights per component, recycled content percentages
- Transaction data: sales volumes, import/export quantities, toll manufacturing movements
- Recyclability assessment results and PPWR readiness scores
- Declaration of Conformity records, evidence files, and audit trails
GS1 and EDI Data:
- EANCOM and GS1 XML messages processed through the platform
- Trade item data received from or published to GDSN data pools
- Partner GLNs, interchange references, and message processing logs
Technical Data:
- IP address, browser type, and device information
- Session data, access logs, and usage analytics
- API access tokens and integration connection metadata
3. Purpose of Processing
We process your personal data for the following purposes:
Providing and maintaining the website and platform.
Responding to your enquiries and scheduling demos.
Fulfilling our contractual obligations towards customers.
Sending relevant product and regulatory updates (only with your consent).
Ensuring the security and integrity of our systems.
Complying with legal obligations (e.g., tax law, commercial law).
4. Data Sharing
We do not sell your personal data. We share data only in the following cases:
Service Providers
We use carefully selected processors who act on our instructions: hosting providers (data centre located in the EU), email service providers for transactional emails, and customer support tools. All processors are contractually bound by Data Processing Agreements (Art. 28 GDPR).
Legal Requirements
We may disclose data if required by law, regulation, legal process, or enforceable governmental request.
No Transfers Outside the EU/EEA
All data is stored and processed within the European Union. If a transfer to a third country becomes necessary, it will only take place with appropriate safeguards (Standard Contractual Clauses or adequacy decision) and we will update this policy accordingly.
5. Data Retention
We retain your personal data only for as long as necessary for the purposes described in this policy, or as required by law.
Account and company data: retained for the duration of your subscription plus 12 months after termination to allow for data export and any outstanding compliance queries.
Packaging and compliance data: retained for the duration of your subscription. Upon termination, you may export your data within 30 days. After 30 days, data is permanently deleted unless a longer retention period is required by law.
Declarations of Conformity and technical documentation: retained for 10 years from the date the packaging was placed on the market, as required by EU Regulation 2025/40 (PPWR). This retention obligation overrides the general deletion timeline.
Financial records: invoices and payment records are retained for 10 years in accordance with Section 257 HGB (German Commercial Code) and Section 147 AO (German Fiscal Code).
Technical logs: server and access logs are retained for 90 days for security monitoring, then anonymised or deleted.
6. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
Right of Access (Art. 15)
You can request confirmation of whether we process your data and receive a copy of that data.
Right to Rectification (Art. 16)
You can request correction of inaccurate or incomplete data.
Right to Erasure (Art. 17)
You can request deletion of your data, provided there is no legal obligation to retain it.
Right to Restriction (Art. 18)
You can request that we restrict the processing of your data under certain conditions.
Right to Data Portability (Art. 20)
You can request to receive your data in a structured, commonly used, machine-readable format.
Right to Object (Art. 21)
You can object to the processing of your data based on legitimate interests at any time. We will cease processing unless we can demonstrate compelling legitimate grounds.
Right to Withdraw Consent (Art. 7(3))
Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, contact us at privacy@taxsync.eu. We will respond within 30 days.
7. Security Measures
We implement appropriate technical and organisational measures to protect your data against unauthorised access, alteration, disclosure, or destruction. These include: encryption of data in transit (TLS 1.2+) and at rest, access controls and role-based permissions, regular security audits, and employee training on data protection obligations.
8. Supervisory Authority
If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, your place of work, or the place of the alleged infringement.
The competent supervisory authority for TaxSync GmbH is:
[Landesbeauftragte/r fur Datenschutz und Informationsfreiheit]
[State Data Protection Authority for the applicable German federal state]
9. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we do, we will update the effective date at the top of this page. We encourage you to review this page periodically. For material changes, we will notify registered users by email.