Privacy Policy

back to home page

Privacy Policy

DTHgroupSystemic Transformation for People and Organizations
This policy applies to the website hsflow.dth-group.com and to the HSflow™ application provided through it.
Last updated: August 2026

1. Controller

Simone Unger
DTHgroup
An der Waage 4
97264 Helmstadt
Germany
E-mail: contact@dth-group.de
Phone: +49 160 4537323

No data protection officer has been appointed; the statutory requirements for such an appointment are not met.

2. General information

The protection of your personal data is important to us. We process data exclusively in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

This website can generally be used without providing personal data. Personal data is processed only where:

  • you provide it voluntarily (for example when contacting us), or
  • it is technically necessary for the operation of the website.

3. Hosting and server log files

This website is hosted by ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. The hosting provider processes data on our behalf under a data processing agreement pursuant to Article 28 GDPR. The servers are located in Germany.

When you visit this website, the following information is logged automatically:

  • browser type and version
  • operating system
  • referrer URL
  • IP address (truncated)
  • date and time of access
  • pages accessed

Purpose: secure and uninterrupted operation of the website.
Legal basis: Article 6 (1) (f) GDPR (legitimate interest in secure operation).
Retention period: log files are deleted after no more than 14 days, unless they are required to investigate a specific security incident.

4. Cookies and consent management

This website uses the consent tool Complianz to store your cookie settings. Complianz runs on our own server; no data is transmitted to third parties.

Technically necessary cookies (for example to store your selection and for the login process) are set without consent.
Legal basis: section 25 (2) no. 2 TDDDG in conjunction with Article 6 (1) (f) GDPR.

Optional cookies are set only with your consent.
Legal basis: section 25 (1) TDDDG in conjunction with Article 6 (1) (a) GDPR.
You may withdraw your consent at any time with effect for the future via the cookie settings.

5. No web analytics, no external fonts

This website performs no web analytics and no tracking. No analytics services, advertising networks or social media plugins are embedded.

All fonts used are served locally from our own server. No connection is made to external font providers (such as Google Fonts).

6. Contacting us

If you contact us by e-mail or telephone, we process the data you provide (for example name, company, e-mail address, telephone number and the content of your enquiry) in order to handle your request.

Legal basis: Article 6 (1) (b) GDPR (initiation or performance of a contract) or Article 6 (1) (f) GDPR (legitimate interest in responding to enquiries).
Retention period: until your enquiry has been dealt with conclusively; beyond that only where commercial or tax retention periods apply.

For sending e-mails from the system we use WP Mail SMTP via the mail server of our hosting provider ALL-INKL.COM.

7. Customer accounts and access management

We use Paid Memberships Pro to manage customer access to HSflow™. The plugin runs on our own server; no data is transmitted to third parties.

The following data is processed:

  • name and e-mail address of the contact person at the customer company
  • company name and billing address
  • access credentials and activation status
  • login times and technical log data

Legal basis: Article 6 (1) (b) GDPR (performance of the licence agreement).
Retention period: for the duration of the contractual relationship; thereafter until the expiry of commercial and tax retention periods.

8. Billing

HSflow™ is invoiced as an annual licence by invoice. No online payment service providers (such as Stripe or PayPal) are embedded in this website; no payment data is collected through the website.

For invoicing we process company name, address, contact person, VAT ID and payment status.
Legal basis: Article 6 (1) (b) GDPR and Article 6 (1) (c) GDPR (commercial and tax obligations).
Retention period: ten years pursuant to section 147 of the German Fiscal Code and section 257 of the German Commercial Code.

9. The HSflow™ application

HSflow™ is a web-based application for recording and analysing metrics on the psychosocial situation within organisations (ESRS S1 reporting). It is provided within this website in an embedded frame (iframe) and consists of three areas: the employee input page, the payroll input tool and the HR dashboard.

9.1 Controllership

The controller within the meaning of the GDPR is exclusively the company that uses HSflow™. We (DTHgroup) process data on behalf of and on the instructions of that company (Article 28 GDPR). A data processing agreement pursuant to Article 28 GDPR is available to companies on request.

9.2 Employee entries

Entries by employees are made anonymously. There is no login using personal credentials; access is granted via an organisation code. Only the following are processed:

  • anonymous functional data (colour proportions, scores)
  • time of measurement
  • organisation ID and, where applicable, site or department assignment
  • technical metadata, solely to ensure the application functions

No names, e-mail addresses, employee IDs, performance data, diagnoses, health data or psychological profiles of natural persons are processed. No tracking and no profiling takes place.

Attribution to individual persons is technically impossible. The system stores no personal identifiers. Nor can the company determine from the data who made which entry. Analyses at site or department level are displayed only above a minimum group size, so that no conclusions can be drawn about individual persons.

9.3 Access for HR and administration

Unlike the employee input page, the HR dashboard requires a personal login. For these accounts we process:

  • e-mail address and login credentials of the authorised person
  • organisational affiliation and permission level
  • login times and technical log data
  • where specially protected analyses are unlocked: a time-based confirmation code (two-factor authentication)

This data serves solely to secure access and to keep organisations separate from one another.
Legal basis: Article 6 (1) (b) GDPR (performance of the licence agreement) and Article 6 (1) (f) GDPR (legitimate interest in the security of the application).
The login session ends when the browser is closed.

9.4 Technical operation (Google Firebase)

The HSflow™ application is operated technically on the Google Firebase platform. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google processes the data as a processor on the basis of its data processing terms pursuant to Article 28 GDPR.

The following are used:

  • Cloud Firestore (database) – storage location: European multi-region eur3
  • Cloud Functions (server logic, calculation of metrics) – region europe-west1 (Belgium)
  • Firebase Authentication (login for HR accounts)

Measurement and metrics data is stored within the European Union. In connection with login and technical support, data may be transferred to Google LLC in the United States. For such cases, the Standard Contractual Clauses adopted by the European Commission are in place; Google LLC is additionally certified under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023).

Legal basis: Article 6 (1) (b) GDPR; for transfers to third countries Article 45 or Article 46 (2) (c) GDPR.
Google privacy policy: https://policies.google.com/privacy

9.5 Retention periods

  • anonymous measurement data: 36 months
  • HR metrics: in accordance with the statutory retention obligations of the company using the application
  • credentials for HR accounts: for the duration of the contractual relationship; accounts are deleted after the contract ends

9.6 No disclosure to third parties

No data is transmitted to third parties, to external research, to marketing or to analytics platforms. The Provider may use exclusively fully anonymised, aggregated data without any personal reference for product improvement and benchmarking.

9.7 Security

  • measurement and metrics data stored within the European Union
  • encrypted transmission (TLS/HTTPS)
  • access restricted to authorised persons
  • strict separation of organisations by server-side access rules
  • two-factor authentication for specially protected analyses

9.8 Information for employees

Note for companies using the application:
Please inform the works council and all employees before they use the application. Participation is voluntary; no disadvantage arises from not taking part. Co-determination rights of the works council or staff council (in particular section 87 (1) nos. 6 and 7 BetrVG) must be observed.

We provide an information sheet for employees together with the contract documents.

10. Your rights

You have the following rights:

  • access (Article 15 GDPR)
  • rectification (Article 16 GDPR)
  • erasure (Article 17 GDPR)
  • restriction of processing (Article 18 GDPR)
  • data portability (Article 20 GDPR)
  • objection to processing (Article 21 GDPR)
  • withdrawal of consent with effect for the future (Article 7 (3) GDPR)

Please address requests to: contact@dth-group.de

Note on employee entries: because this data is collected anonymously and no personal reference can be established, we can neither attribute individual entries nor disclose or delete them on request (Article 11 GDPR). For any questions concerning the use of HSflow™ within your own company, please contact your employer as the responsible controller.

11. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR). The authority responsible for us is:

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 27, 91522 Ansbach, Germany
https://www.lda.bayern.de

12. Encryption

This website and the HSflow™ application use TLS encryption (“https://”). Data is therefore protected against interception by third parties during transmission in accordance with the current state of the art.

13. Currency of this privacy policy

Last updated: August 2026
We reserve the right to amend this policy if the legal situation or our processing activities change.

This is a translation provided for convenience. In the event of any discrepancy, the German version of this privacy policy shall prevail.

Nach oben